IP Library Granted Patent US 8,015,604
Granted Patent B1
US 8,015,604 · App. 10/683,221 · Granted Sep 6, 2011

Hierarchical architecture in a network security system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,015,604
App. No.
10/683,221
Granted
Sep 6, 2011
Kind
B1
Abstract

A network security system having a hierarchical configuration is provided. In one embodiment the present invention includes a plurality of subsystems, where each subsystem includes a plurality of distributed software agents configured to collect security events from monitor devices, and a local manager module coupled to the plurality of distributed software agents to generate correlated events by correlating the security events. Each of the subsystems can report the correlated events to a global manager module coupled to the plurality of subsystems, and the global manager module can correlate the correlated events from each manager module.

Claims (46)

1. A network security system comprising:

a plurality of subsystems, each subsystem comprising:

a plurality of distributed software agents, each agent configured:

to collect a security event from a monitor device; and

to transmit the security event;

a local manager module coupled to the plurality of distributed software agents, configured:

to receive, from each agent, the security event;

to generate one or more correlated events by correlating the received security events, wherein a correlated event comprises a conclusion drawn from the received security events; and

to transmit the one or more correlated events; and

a local manager agent coupled to the local manager module, configured:

to receive, from the local manager module, the one or more correlated events;

to process the one or more correlated events; and

to transmit the processed correlated events; and

a global manager module coupled to the plurality of subsystems, each subsystem comprising a local network security system, the global manager module configured:

to receive, from each subsystem, the processed correlated events; and

to correlate the received processed correlated events.

2. The network security system of claim 1 , wherein each subsystem further comprises a filter coupled to the local manager module, configured:

to receive, from the local manager module, the one or more correlated events;

to select correlated events; and

to transmit the selected correlated events.

3. The network security system of claim 2 , wherein the filter can be automatically programmed by the global manager module.

4. The network security system of claim 1 , further comprising a back-channel between the global manager module and the local manager module configured to request a security event related to a specific correlated event received by the global manager module.

5. The network security system of claim 4 , wherein the back-channel is further configured to transmit the requested security event to the global manager module.

6. The network security system of claim 1 , wherein the local network security system monitors a network associated with a site.

7. A method for monitoring a plurality of local networks, the method comprising:

for each local network:

collecting security events;

generating local correlated events by correlating the collected security events at a local network security system monitoring the local network, wherein a local correlated event comprises a conclusion drawn from the collected security events; and

processing the local correlated events;

collecting, from each local network, the processed local correlated events; and

generating global correlated events by correlating the collected processed local correlated events.

8. The method of claim 7 , further comprising filtering the processed local correlated events generated by each local network to determine which processed local correlated events to collect.

9. The method of claim 7 , wherein the security events are collected by a plurality of distributed software agents.

10. The method of claim 7 , wherein the processed local correlated events are collected by a distributed software agent associated with the local network security system.

11. The method of claim 7 , wherein the global correlated events are generated by a global manager module.

12. A machine-readable medium having stored thereon data representing instructions that, when executed by a processor, causes the processor to perform operations comprising:

for each local network of a plurality of local networks:

collecting security events;

generating local correlated events by correlating the collected security events at a local network security system monitoring the local network, wherein a local correlated event comprises a conclusion drawn from the collected security events; and

processing the local correlated events;

collecting, from each local network, the processed local correlated events; and

generating global correlated events by correlating the collected processed local correlated events.

13. The machine-readable medium of claim 12 , wherein the instructions further cause the processor to perform operations comprising filtering the processed local correlated events generated by each local network to determine which processed local correlated events to collect.

14. The machine-readable medium of claim 12 , wherein the security events are collected by a plurality of distributed software agents.

15. The machine-readable medium of claim 12 , wherein the processed local correlated events are collected by a distributed software agent associated with the local network security system.

16. The machine-readable medium of claim 12 , wherein the global correlated events are generated by a global manager module.

Assignments (9)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
CERTIFICATE OF CONVERSION Recorded Nov 16, 2012
From: ARCSIGHT, INC.
To: ARCSIGHT, LLC.
Reel/Frame 029308/0908 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: ARCSIGHT, LLC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029308/0929 →