IP Library Granted Patent US 9,027,120
Granted Patent B1
US 9,027,120 · App. 10/683,191 · Granted May 5, 2015

Hierarchical architecture in a network security system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,027,120
App. No.
10/683,191
Granted
May 5, 2015
Kind
B1
Abstract

A network security system having a hierarchical configuration is provided. In one embodiment the present invention includes a plurality of subsystems, where each subsystem includes a plurality of distributed software agents configured to collect base security events from monitor devices, and a local manager module coupled to the plurality of distributed software agents to generate correlated events by correlating the base security events. Each subsystem can also include a filter coupled to the manager module to select which base security events are to be processed further. The selected base security events are passed to a global manager module coupled to the plurality of subsystems that generates global correlated events by correlating the base security events selected for further processing by each filter of each subsystem.

Claims (64)

1. A network security system comprising:

a plurality of subsystems, each subsystem comprising:

a plurality of distributed software agents, each agent configured:

to collect a base security event from a monitor device; and

to transmit the base security event;

a local manager module coupled to the plurality of distributed software agents, configured:

to receive, from each agent, the base security event;

to generate one or more local correlated events by correlating the received base security events, wherein a local correlated event comprises a conclusion drawn from the received base security events according to a rule based on at least a vulnerability of a target network node, the rule grouping security incidents associated with the base security events into a plurality of threat levels, and wherein the conclusion indicates that a plurality of the received base security events is associated with a same security incident; and

to transmit the one or more local correlated events; and

a filter coupled to the local manager module, configured:

to receive the one or more local correlated events;

to select local correlated events; and

to transmit the selected local correlated events; and

a global manager module coupled to the plurality of subsystems, comprising a processor configured:

to receive, from each subsystem, the selected local correlated events; and

to generate one or more global correlated events by correlating the received selected local correlated events, wherein a global correlated event comprises a second conclusion drawn from the received selected local correlated events according to a second rule, and wherein the second conclusion indicates that a plurality of the received selected local correlated events is associated with a second same security incident.

2. The network security system of claim 1 , wherein the filter can be automatically programmed by the global manager module.

3. The network security system of claim 1 , wherein each subsystem further comprises a local manager agent coupled to the filter to collect the selected local correlated events.

4. The network security system of claim 1 , wherein each subsystem comprises a local network security system.

5. The network security system of claim 4 , wherein each local network security system monitors a network associated with a site.

6. The network security system of claim 1 , wherein the plurality of threat levels comprises more than two threat levels.

7. The network security system of claim 1 , wherein the plurality of threat levels comprises:

a first threat level comprising one or more of reconnaissance zone transfer, port scan, protocol and scanning;

a second threat level comprising suspicious illegal outgoing traffic and unusual levels of alerts from the same host;

a third threat level comprising attack overflow, IDS evasion, virus, and denial of service; and

a fourth threat level comprising successful compromise of a backdoor, root compromise and covert channel exploit.

8. A method comprising:

collecting base security events at a plurality of sites;

generating local correlated events at each site by correlating the base security events collected at each site, wherein a local correlated event comprises a conclusion drawn from the collected base security events according to a rule based on at least a vulnerability of a target network node, the rule grouping security incidents associated with the base security events into a plurality of threat levels, and wherein the conclusion indicates that a plurality of the received base security events is associated with a same security incident;

selecting local correlated events from each site; and

a processor generating global correlated events by correlating the selected local correlated events, wherein a global correlated event comprises a second conclusion drawn from the selected local correlated events according to a second rule, and wherein the second conclusion indicates that a plurality of the selected local correlated events is associated with a second same security incident.

9. The method of claim 8 , further comprising filtering the local correlated events at each site to determine which local correlated events to collect.

10. The method of claim 8 , wherein the collecting the base security events at each site is performed by a plurality of distributed software agents at each site.

11. The method of claim 8 , wherein the local correlated events are generated by a local network security system monitoring each site.

12. The method of claim 11 , wherein the collecting of base security events from each site is performed by a distributed software agent associated with each site.

13. The method of claim 8 , wherein the global correlated events are generated by a global manager module.

14. A non-transitory machine-readable medium having stored thereon data representing instructions that, when executed by a processor, causes the processor to perform operations comprising:

collecting base security events at a plurality of sites;

generating local correlated events at each site by correlating the base security events collected at each site, wherein a local correlated event comprises a conclusion drawn from the collected base security events according to a rule based on at least a vulnerability of a target network node, the rule grouping security incidents associated with the base security events into a plurality of threat levels, and wherein the conclusion indicates that a plurality of the received base security events is associated with a same security incident;

selecting local correlated events from each site; and

generating global correlated events by correlating the selected local correlated events, wherein a global correlated event comprises a second conclusion drawn from the selected local correlated events according to a second rule, and wherein the second conclusion indicates that a plurality of the selected local correlated events is associated with a second same security incident.

15. The non-transitory machine-readable medium of claim 14 , wherein the instructions further cause the processor to perform operations comprising filtering the local correlated events at each site to determine which local correlated events to collect.

16. The non-transitory machine-readable medium of claim 14 , wherein the collecting the base security events at each site is performed by a plurality of distributed software agents at each site.

17. The non-transitory machine-readable medium of claim 14 , wherein the local correlated events are generated by a local network security system monitoring each site.

18. The non-transitory machine-readable medium of claim 17 , wherein the collecting of base security events from each site is performed by a distributed software agent associated with each site.

19. The non-transitory machine-readable medium of claim 14 , wherein the global correlated events are generated by a global manager module.

20. A network security system comprising:

a plurality of subsystems, each subsystem comprising:

a plurality of distributed software agents, each agent configured:

to collect a base security event from a monitor device; and

to transmit the base security event;

a local manager module coupled to the plurality of distributed software agents, configured:

to receive, from each agent, the base security event;

to transmit the base security events;

to generate one or more local correlated events by correlating the received base security events, wherein a local correlated event comprises a conclusion drawn from the received base security events according to a rule based on at least a vulnerability of a target network node, the rule grouping security incidents associated with the base security events into a plurality of threat levels, and wherein the conclusion indicates that a plurality of the received base security events is associated with a same security incident; and

to transmit the one or more local correlated events; and

a filter coupled to the local manager module, configured:

to receive the base security events;

to select base security events; and

to transmit the selected base security events; and

a global manager module coupled to the plurality of subsystems, comprising a processor configured:

to receive, from each subsystem, the one or more local correlated events;

to receive, from each subsystem, the selected base security events; and

to generate one or more global correlated events by correlating the one or more local correlated events and the received selected base security events.

Assignments (10)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
CERTIFICATE OF CONVERSION Recorded Nov 16, 2012
From: ARCSIGHT, INC.
To: ARCSIGHT, LLC.
Reel/Frame 029308/0908 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: ARCSIGHT, LLC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029308/0929 →
MERGER Recorded Dec 23, 2010
From: PRIAM ACQUISITION CORPORATION
To: ARCSIGHT, INC.
Reel/Frame 025525/0172 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2003
From: TIDWELL, KENNY; BEEDGEN, CHRISTIAN; NJEMANZE, HUGH S.; KOTHARI, PRAVIN S.
To: ARCSIGHT, INC.
Reel/Frame 014596/0491 →