Event monitoring and management
Described are techniques used in monitoring the performance, security and health of a system used in an industrial application. Agents included in the industrial network report data to an appliance or server. The appliance stores the data and determines when an alarm condition has occurred. Notifications are sent upon detecting an alarm condition. The alarm thresholds may be user defined. A threat thermostat controller determines a threat level used to control the connectivity of a network used in the industrial application.
1 . A method for controlling connectivity in a network comprising:
receiving one or more inputs;
determining a threat level indicator in accordance with said one or more inputs; and
selecting, for use in said network, a firewall configuration in accordance with said threat level indicator.
2 . The method of claim 1 , wherein said firewall configuration is selected from a plurality of firewall configurations each associated with a different threat level indicator.
3 . The method of claim 2 , wherein a first firewall configuration associated with a first threat level indicator provides for more restrictive connectivity of said network than a second firewall configuration associated with a second threat level indicator when said first threat level indicator is a higher threat level than said second threat level indicator.
4 . The method of claim 3 , wherein, a firewall configuration associated with a highest threat level indicator provides for disconnecting said network from all other less-trusted networks.
5 . The method of claim 4 , wherein said disconnecting includes physically disconnecting said network from other networks.
6 . The method of claim 4 , wherein said network is reconnected to said less trusted networks when a current threat level is a level other than said highest threat level indicator.
7 . The method of claim 1 , further comprising:
automatically loading said firewall configuration as a current firewall configuration in use in said network.
8 . The method of claim 1 , wherein said one or more inputs includes at least one of: a manual input, a metric about a system in said network, a metric about said network, a derived value determined using a plurality of weighted metrics including one metric about said network, a derived value determined using a plurality of metrics, and an external source from said network.
9 . The method of claim 8 , wherein, if said manual input is specified, said manual input determines the threat level indicator overriding all other indicators.
10 . The method of claim 8 , wherein said plurality of weighted metrics includes a metric about at least one of: a network intrusion detection, a network intrusion prevention, a number of failed login attempts, a number of users with a high level of privileges.
11 . The method of claim 10 , wherein said high level of privileges corresponds to one of: administrator privileges and root user privileges.
12 . The method of claim 1 , wherein said selecting additionally selects one or more of the following: an antivirus configuration, an intrusion prevention configuration, and an intrusion detection configuration.
13 . A computer program product for controlling connectivity in a network comprising code that:
receives one or more inputs;
determines a threat level indicator in accordance with said one or more inputs; and
selects, for use in said network, a firewall configuration in accordance with said threat level indicator.
14 . The computer program product of claim 13 , wherein said firewall configuration is selected from a plurality of firewall configurations each associated with a different threat level indicator.
15 . The computer program product of claim 14 , wherein a first firewall configuration associated with a first threat level indicator provides for more restrictive connectivity of said network than a second firewall configuration associated with a second threat level indicator when said first threat level indicator is a higher threat level than said second threat level indicator.
16 . The computer program product of claim 15 , wherein, a firewall configuration associated with a highest threat level indicator provides for disconnecting said network from all other less-trusted networks.
17 . The computer program product of claim 16 , wherein said code that disconnects includes physically disconnecting said network from other networks.
18 . The computer program product of claim 16 , wherein said network is reconnected to said less trusted networks when a current threat level is a level other than said highest threat level indicator.
19 . The computer program product of claim 13 , further comprising code that:
automatically loads said firewall configuration as a current firewall configuration in use in said network.
20 . The computer program product of claim 13 , wherein said one or more inputs includes at least one of: a manual input, a metric about a system in said network, a metric about said network, a derived value determined using a plurality of weighted metrics including one metric about said network, a derived value determined using a plurality of metrics, and an external source from said network.
21 . The computer program product of claim 20 , wherein, if said manual input is specified, said manual input determines the threat level indicator overriding all other indicators.
22 . The computer program product of claim 20 , wherein said plurality of weighted metrics includes a metric about at least one of: a network intrusion detection, a network intrusion prevention, a number of failed login attempts, a number of users with a high level of privileges.
23 . The computer program product of claim 22 , wherein said high level of privileges corresponds to one of: administrator privileges and root user privileges.
24 . The computer program product of claim 13 , wherein said code that selects additionally selects one or more of the following: an antivirus configuration, an intrusion prevention configuration, and an intrusion detection configuration.
25 - 174 . (canceled)