发明名称 Distributed threat management
摘要 A method and system are provided for managing a security threat in a distributed system. A distributed element of the system detects and reports suspicious activity to a threat management agent. The threat management agent determines whether an attack is taking place and deploys a countermeasure to the attack when the attack is determined to be taking place. Another method and system are also provided for managing a security threat in a distributed system. A threat management agent reviews reported suspicious activity including suspicious activity reported from at least one distributed element of the system, determines, based on the reports, whether a pattern characteristic of an attack occurred, and predicts when a next attack is likely to occur. Deployment of a countermeasure to the predicted next attack is directed in a time window based on when the next attack is predicted to occur.
申请公布号 US7373666(B2) 申请公布日期 2008.05.13
申请号 US20020185008 申请日期 2002.07.01
申请人 MICROSOFT CORPORATION 发明人 KALER CHRISTOPHER G.;DELLA-LIBERA GIOVANNI MOISES;SHEWCHUK JOHN P.
分类号 G06F12/00;G06F7/04;G06F11/30;G06F21/00;H04L9/32 主分类号 G06F12/00
代理机构 代理人
主权项
地址