IP Library Patent Application 13685784
Patent Application
App. No. 13/685,784

NETWORK INTRUSION DETECTION IN A NETWORK THAT INCLUDES A DISTRIBUTED VIRTUAL SWITCH FABRIC

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/685,784
Abstract

A network intrusion detection system (NIDS) works in conjunction with a distributed virtual switch fabric to provide enhanced network intrusion detection in a way that does not require as much human intervention, autonomically adjusts to hardware changes in the network, and responds much more quickly than known network intrusion detection systems. The NIDS accesses network information from the distributed virtual switch fabric, which gives the NIDS access to a virtual view that includes hardware information for all networking devices in the network. This allows the NIDS to automatically determine network topology, update itself as hardware in the network is added or changed, and promptly take automated service actions in response to detected network intrusions. The result is a NIDS that is easier to configure, maintain, and use, and that provides enhanced network security.

Claims (31)

1 . A computer-implemented method for detecting network intrusions in a networked computer system that includes a plurality of networks interconnecting a plurality of systems, the plurality of systems including a distributed virtual switch fabric that provides a virtual view of the plurality of networks and the plurality of systems, the method comprising the steps of:

querying the distributed virtual switch fabric to determine from the virtual view network topology and configuration of the networked computer system;

defining a plurality of attack signatures that specify characteristics of network intrusions;

defining a plurality of service actions that each may be performed automatically without input from a human system administrator when a network intrusion that matches at least one of the plurality of attack signatures is detected by the network intrusion detection system;

detecting a network intrusion in the networked computer system that matches at least one of the plurality of attack signatures; and

in response to detecting the network intrusion that matches the at least one of the plurality of attack signatures, autonomically performing at least one of the plurality of service actions without input from a human system administrator.

2 . The method of claim 1 wherein the plurality of service actions comprises monitoring a compromised host that originated network traffic detected as the network intrusion.

3 . The method of claim 1 wherein the plurality of service actions comprises quarantining a compromised host that originated network traffic detected as the network intrusion.

4 . The method of claim 1 wherein the plurality of service actions comprises moving to a different network a compromised host that originated network traffic detected as the network intrusion to a different network.

5 . The method of claim 1 wherein the plurality of service actions comprises shutting down a compromised host that originated network traffic detected as the network intrusion.

6 . The method of claim 1 further comprising the steps of:

detecting an addition to the plurality of systems;

querying the distributed virtual switch fabric to determine if the addition is reflected in the virtual view of the plurality of networks and the plurality of systems; and

when the addition is reflected in the virtual view, autonomically changing the network topology and configuration without input from a human system administrator.

7 . The method of claim 1 further comprising the steps of:

detecting a change to the plurality of systems;

querying the distributed virtual switch fabric to determine if the change is reflected in the virtual view of the plurality of networks and the plurality of systems; and

when the change is reflected in the virtual view, autonomically changing the network topology and configuration without input from a human system administrator.

8 . A computer-implemented method for detecting network intrusions in a networked computer system that includes a plurality of networks interconnecting a plurality of systems, the plurality of systems including a distributed virtual switch fabric that provides a virtual view of the plurality of networks and the plurality of systems, the method comprising the steps of:

(A) configuring a network intrusion detection system by performing the steps of:

querying the distributed virtual switch fabric to determine from the virtual view network topology and configuration of the networked computer system;

defining a plurality of attack signatures that specify characteristics of network intrusions;

defining a plurality of service actions that each may be performed automatically without input from a human system administrator when a network intrusion that matches at least one of the plurality of attack signatures is detected by the network intrusion detection system;

(B) running the network intrusion detection system, which performs the steps of:

monitoring network traffic in the networked computer system;

detecting a network intrusion in the networked computer system that matches at least one of the plurality of attack signatures; and

in response to detecting the network intrusion that matches the at least one of the plurality of attack signatures, when a corresponding action for the detected network intrusion is to notify a human system administrator, notifying the human system administrator of the network intrusion, and when the corresponding action for the detected network intrusion is to perform a specified service action, automatically performing the specified service action and notifying the system administrator, wherein the specified service action comprises performing at least one of the following steps:

monitoring a compromised host that originated network traffic detected as the network intrusion;

quarantining the compromised host;

moving to a different network the compromised host; and

shutting down the compromised host.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2014
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
Reel/Frame 034194/0111 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2013
From: LUKAS, JOSHUA; RICARD, GARY R.; THOMPSON, TIMOTHY L.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 030051/0377 →