IP Library Granted Patent US 7,409,714
Granted Patent B2
US 7,409,714 · App. 10/171,805 · Granted Aug 5, 2008

Virtual intrusion detection system and method of using same

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,409,714
App. No.
10/171,805
Granted
Aug 5, 2008
Kind
B2
Abstract

A method of forming a virtual intrusion detection system includes the step of positioning a set of sensors in a network environment, each sensor supporting multiple logical traffic paths. The method also includes the step of providing a set of sensor management systems corresponding to the set of sensors. This set of sensor management systems enforces a set of virtual intrusion detection systems, wherein each virtual intrusion detection system corresponds to a predetermined logical traffic path through the set of sensors, each virtual detection system providing sensor traffic information solely to authorized parties.

Claims (26)

1. A method of forming a virtual intrusion detection system, comprising:

positioning a set of sensors in a network environment, each sensor supporting multiple logical traffic paths; and

providing a set of sensor management systems corresponding to said set of sensors, said set of sensor management systems enforcing a set of virtual intrusion detection systems, wherein each virtual intrusion detection system corresponds to a predetermined logical traffic path through said set of sensors, each virtual intrusion detection system providing sensor traffic information solely to authorized parties;

wherein each of the logical traffic paths is associated with a subscriber;

wherein virtual intrusion detection services are provided differently for each of the subscribers based on subscriber input;

wherein resources of the virtual intrusion detection systems are each allocated based on an IP address range that is associated with one of the subscribers;

wherein each of the sensor management systems includes a virtual intrusion detection system provisioning module to perform local virtual intrusion detection system operations as coordinated by the virtual intrusion detection system provisioning module, the local virtual intrusion detection system operations providing intrusion protection for multiple subscribers utilizing one integrated platform.

2. The method of claim 1 , wherein the resources of the virtual intrusion detection systems are each allocated based on a sensor identifier.

3. The method of claim 1 , wherein the resources of the virtual intrusion detection systems are each allocated based on a port number.

4. The method of claim 1 , wherein the resources of the virtual intrusion detection systems are each allocated based on an identifier for traffic belonging to one of the subscribers.

5. The method of claim 1 , wherein user roles are defined each with a unique corresponding capability with respect to the virtual intrusion detection systems.

6. The method of claim 5 , wherein the user roles are selected from the group consisting of a system administrator, an analyzer/operator, a user manager, an intrusion expert, and a monitor.

7. The method of claim 5 , wherein the user roles include a system administrator, an analyzer/operator, a user manager, an intrusion expert, and a monitor.

8. The method of claim 1 , wherein the virtual intrusion detection systems each include said set of sensors in the network environment.

9. The method of claim 8 , wherein the virtual intrusion detection systems each include the set of sensor management systems corresponding to said set of sensors.

10. The method of claim 1 , wherein the virtual intrusion detection services are provided differently by supporting different security policies.

11. The method of claim 1 , wherein the virtual intrusion detection services are provided differently by supporting different protection objectives.

12. The method of claim 1 , wherein the virtual intrusion detection services are provided differently by supporting different security management preferences.

13. The method of claim 1 , wherein the virtual intrusion detection system provisioning module facilitates protection for multiple traffic streams for different subscribers using a single sensor platform while maintaining security separation.

14. A system for forming a virtual intrusion detection system, comprising:

a set of sensors positioned in a network environment, each sensor supporting multiple logical traffic paths; and

a set of sensor management systems corresponding to said set of sensors, said set of sensor management systems enforcing a set of virtual intrusion detection systems, wherein each virtual intrusion detection system corresponds to a predetermined logical traffic path through said set of sensors, each virtual intrusion detection system providing sensor traffic information solely to authorized parties;

wherein each of the logical traffic paths is associated with a subscriber;

wherein virtual intrusion detection services are provided differently for each of the subscribers based on subscriber input;

wherein resources of the virtual intrusion detection systems are each allocated based on an IP address range that is associated with one of the subscribers;

wherein each of the sensor management systems includes a virtual intrusion detection system provisioning module to perform local virtual intrusion detection system operations as coordinated by the virtual intrusion detection system provisioning module, the local virtual intrusion detection system operations providing intrusion protection for multiple subscribers utilizing one integrated platform.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →