IP Library Granted Patent US 8,850,565
Granted Patent B2
US 8,850,565 · App. 10/905,537 · Granted Sep 30, 2014

System and method for coordinating network incident response activities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,850,565
App. No.
10/905,537
Granted
Sep 30, 2014
Kind
B2
Abstract

The present invention provides a system and method to process information regarding a network attack through an automated workflow that actively reconfigures a plurality of heterogeneous network-attached devices and applications to dynamically counter the attack using the network's own self-defense mechanisms. The present invention leverages the security capabilities present within existing and new network-attached devices and applications to effect a distributed defense that immediately quarantines and/or mitigates attacks from hostile sources at multiple points simultaneously throughout the network. In a preferred embodiment, deployed countermeasures are automatically lifted following remediation activities.

Claims (21)

1. A computer-implemented method for responding to an attack that occurred on a computer network, comprising:

receiving a description of the attack that occurred;

accessing a description of a topology of the network;

determining, based on the attack description and the topology description, one or more devices or applications that are relevant to the attack that occurred;

determining, based on the one or more relevant devices or applications, a first set of actions that can be executed to respond to the attack that occurred;

automatically determining, from the first set of actions, a subset of actions to execute to respond to the attack that occurred;

executing the subset of actions; and

determining that the attack that occurred no longer presents a threat.

2. The method of claim 1 , wherein the description of the attack that occurred comprises one element of a group containing a start time, a stop time, and a duration.

3. The method of claim 1 , wherein the description of the attack that occurred comprises one element of a group containing an indication of a source of the attack and an indication of a destination of the attack.

4. The method of claim 1 , wherein the description of the attack that occurred comprises one element of a group containing a packet count, an attribute of a packet header, a packet signature, an indication of a protocol, a regular expression, and a priority.

5. The method of claim 1 , wherein a device or application is relevant to the attack that occurred if the attack originated outside the network and if the device or application is located on a logical border of the network.

6. The method of claim 1 , wherein a device or application is relevant to the attack that occurred if the device or application is located on a logical path from a source of the attack to a destination of the attack.

7. The method of claim 1 , wherein a device or application is relevant to the attack that occurred if the device or application is vulnerable to the attack.

8. The method of claim 1 , wherein determining, based on the one or more relevant devices or applications, the first set of actions that can be executed to respond to the attack that occurred comprises determining one or more capabilities of the one or more relevant devices or applications.

9. The method of claim 1 , wherein determining, based on the one or more relevant devices or applications, the first set of actions that can be executed to respond to the attack that occurred comprises determining states of availability of the one or more relevant devices or applications.

10. The method of claim 1 , wherein determining, from the first set of actions, the subset of actions to execute to respond to the attack that occurred comprises determining a most effective action from the actions within the first set.

11. The method of claim 1 , wherein determining, from the first set of actions, the subset of actions to execute to respond to the attack that occurred comprises identifying, from the one or more relevant devices or applications, a device or application that is logically closest to a source of the attack.

12. The method of claim 1 , wherein executing the subset of actions comprises modifying a setting of a device or application.

13. The method of claim 1 , wherein executing the subset of actions comprises controlling operation of a device or application.

14. The method of claim 1 , further comprising responsive to determining that the attack that occurred no longer presents the threat, reversing the executed actions.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: ARCSIGHT, LLC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029308/0929 →
CERTIFICATE OF CONVERSION Recorded Nov 16, 2012
From: ARCSIGHT, INC.
To: ARCSIGHT, LLC.
Reel/Frame 029308/0908 →
MERGER Recorded Dec 23, 2010
From: PRIAM ACQUISITION CORPORATION
To: ARCSIGHT, INC.
Reel/Frame 025525/0172 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2006
From: ARCSIGHT ENIRA SUB, LLC
To: ARCSIGHT, INC.
Reel/Frame 018067/0712 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2006
From: ENIRA TECHNOLOGIES, LLC
To: ARCSIGHT ENIRA SUB, LLC
Reel/Frame 018067/0756 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2006
From: PATRICK, ROBERT; KEY, CHRISTOPHER; HOLZBERGER, PAUL
To: ENIRA TECHNOLOGIES, LLC
Reel/Frame 018067/0899 →