发明名称 System, method, and computer program for preventing infections from spreading in a network environment using dynamic application of a firewall policy
摘要 A method for containing a threat in network environment using dynamic firewall policies is provided. In one example embodiment, the method can include detecting a threat originating from a first node having a source address in a network, applying a local firewall policy to block connections with the source address, and broadcasting an alert to a second node in the network. In more particular embodiments, an alert may be sent to a network administrator identifying the source address and providing remedial information. In yet other particular embodiments, the method may also include applying a remote firewall policy to the first node blocking outgoing connections from the first node.
申请公布号 US8881258(B2) 申请公布日期 2014.11.04
申请号 US201113216516 申请日期 2011.08.24
申请人 McAfee, Inc. 发明人 Paul Manabendra;Sudharma Praveen Ravichandran
分类号 G06F17/00;G06F11/00;H04L29/06 主分类号 G06F17/00
代理机构 Patent Capital Group 代理人 Patent Capital Group
主权项 1. A method, comprising: detecting, at a first node having a security-as-a-service (SaaS) agent, a threat originating from a source node having a source address in a network, wherein the network includes at least the first node and a plurality of nodes each having a respective SaaS agent; applying a local firewall policy on the first node to block incoming connections associated with the source address; broadcasting, from the first node, an alert to the respective SaaS agents of the plurality of nodes in the network, wherein the broadcast alert comprises the source address of the source node from which the threat originated, wherein broadcasting the alert comprises broadcasting the local firewall policy; identifying, by the first node, a presence of an SaaS firewall module of the source node; and responsive to identifying the presence of the SaaS firewall module on the source node, communicating to the source node to apply a remote firewall policy to block outgoing connections from the source node to the plurality of nodes in the network.
地址 Santa Clara CA US