发明名称 Automated containment of network intruder
摘要 The invention in the preferred embodiment features a system ( 200 ) and method for automatically segregating harmful traffic from other traffic at a plurality of network nodes including switches and routers. In the preferred embodiment, the system ( 200 ) comprises an intrusion detection system ( 105 ) to determine the identity of an intruder and a server ( 130 ) adapted to automatically install an isolation rule on the one or more network nodes ( 114, 115, 116 ) to quarantine packets from the intruder. The isolation rule in the preferred embodiment is a virtual local area network (VLAN) rule or access control list (ACL) rule that causes the network node to route any packets from the intruder into a quarantine VLAN or otherwise isolate the traffic from other network traffic. In large networks, the isolation rule may be installed on a select plurality of network nodes under the gateway router ( 104 ) associated with the node at which the intruder first entered the network ( 100 ).
申请公布号 US2007192862(A1) 申请公布日期 2007.08.16
申请号 US20040568914 申请日期 2004.12.21
申请人 VERMEULEN VINCENT;MATTHEWS JOHN D 发明人 VERMEULEN VINCENT;MATTHEWS JOHN D.
分类号 G06F12/14;H04L29/06 主分类号 G06F12/14
代理机构 代理人
主权项
地址