IP Library Granted Patent US 10,104,104
Granted Patent B1
US 10,104,104 · App. 13/922,724 · Granted Oct 16, 2018

Security alerting system with network blockade policy based on alert transmission activity

Inventors: Ari Juels (Brookline, MA); Nikolaos Triandopoulos (Arlington, MA); Kevin D. Bowers (Melrose, MA)
Assignee: EMC IP Holding Company LLC
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,104,104
App. No.
13/922,724
Granted
Oct 16, 2018
Kind
B1
Abstract

A security alerting system is provided with a network blockage policy based on alert transmission activity. Alert messages from a Security Alerting System executing on a host indicating a potential compromise of a protected resource are processed by determining if a number of buffer contents received from the host within a predefined time interval satisfies a predefined criteria, the buffer content comprising one or more of the alert messages from the Security Alerting System; and blocking a network connection of the host if the number of buffer contents received from the host within the predefined time interval does not satisfy the predefined criteria. The blocked network connection of the host can optionally be restored when a valid buffer content is received from the host. The predefined criteria is based on the alerting activity of the host.

Claims (34)

1. A method performed by a server that is part of a network for processing alert messages from a Security Alerting System executing on a host indicating a potential compromise of a protected resource, comprising:

determining if a number of buffer contents comprising said alert messages received from said host within a predefined time interval satisfies a predefined criteria, wherein said alert messages are generated by said Security Alerting System, wherein said number comprises only valid buffer contents received from said host;

determining whether said received buffer content comprises a replayed buffer content;

triggering, by said server, in response to said number of buffer contents comprising said alert messages received from said host within said predefined time interval failing to satisfy said predefined criteria, a blocking of access of said host to services of said network except for communications of said Security Alerting System executing on said host with said server; and

restoring said blocked access of said host to said network when a valid buffer content is received from said host.

2. The method of claim 1 , further comprising the step of issuing a heartbeat gap alert if a valid buffer content is not received from said host within a predefined time interval.

3. The method of claim 1 , wherein said predefined criteria comprises receiving one or more valid buffer contents from said host within said predefined time interval.

4. The method of claim 1 , wherein said blocking of said access of said host to said network is triggered when more than β time intervals have elapsed without receiving a valid buffer content, for parameter setting β>|B|/τ, where |B| is a buffer size and τ denotes an estimate of a maximum number of alerts written by said host per time interval under non-adversarial conditions.

5. The method of claim 1 , wherein said predefined criteria is based on alerting activity of said host.

6. A non-transitory machine-readable recordable storage medium for storing one or more software programs implemented by a server that is part of a network for processing alert messages from a Security Alerting System executing on a host indicating a potential compromise of a protected resource, wherein the one or more software programs when executed by one or more processing devices implement the following steps:

determining if a number of buffer contents comprising said alert messages received from said host within a predefined time interval satisfies a predefined criteria, wherein said alert messages are generated by said Security Alerting System, wherein said number comprises only valid buffer contents received from said host;

determining whether said received buffer content comprises a replayed buffer content;

triggering, by said server, in response to said number of buffer contents comprising said alert messages received from said host within said predefined time interval failing to satisfy said predefined criteria, a blocking of access of said host to services of said network except for communications of said Security Alerting System executing on said host with said server; and

restoring said blocked access of said host to said network when a valid buffer content is received from said host.

7. A server apparatus that is part of a network for processing an alert message from a Security Alerting System executing on a host indicating a potential compromise of a protected resource, the server apparatus comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to implement the following steps:

determine if a number of buffer contents comprising said alert messages received from said host within a predefined time interval satisfies a predefined criteria, wherein said alert messages are generated by said Security Alerting System, wherein said number comprises only valid buffer contents received from said host;

determining whether said received buffer content comprises a replayed buffer content;

trigger, by said server, in response to said number of buffer contents comprising said alert messages received from said host within said predefined time interval failing to satisfy said predefined criteria, a blocking of access of said host to services of said network except for communications of said Security Alerting System executing on said host with said server; and

restore said blocked access of said host to said network when a valid buffer content is received from said host.

8. The server apparatus of claim 7 , wherein said at least one hardware device is further configured to issue a heartbeat gap alert if a valid buffer content is not received from said host within a predefined time interval.

9. The server apparatus of claim 7 , wherein said predefined criteria comprises receiving one or more valid buffer contents from said host within said predefined time interval.

10. The server apparatus of claim 7 , wherein said blocking of said access of said host to said network is triggered when more than β time intervals have elapsed without receiving a valid buffer content, for parameter setting β>|B|/τ, where |B| is a buffer size and τ denotes an estimate of a maximum number of alerts written by said host per time interval under non-adversarial conditions.

11. The server apparatus of claim 7 , wherein said predefined criteria is based on alerting activity of said host.

12. The non-transitory machine-readable recordable storage medium of claim 6 , further comprising the step of issuing a heartbeat gap alert if a valid buffer content is not received from said host within a predefined time interval.

13. The non-transitory machine-readable recordable storage medium of claim 6 , wherein said predefined criteria comprises receiving one or more valid buffer contents from said host within said predefined time interval.

14. The non-transitory machine-readable recordable storage medium of claim 6 , wherein said predefined criteria is based on alerting activity of said host.

15. The non-transitory machine-readable recordable storage medium of claim 6 , wherein said blocking of said access of said host to said network is triggered when more than β time intervals have elapsed without receiving a valid buffer content, for parameter setting β>|B|/τ, where |B| is a buffer size and τ denotes an estimate of a maximum number of alerts written by said host per time interval under non-adversarial conditions.

16. The method of claim 1 , wherein said blocking of said access of said host to said network is triggered when more than a predefined number of time intervals have elapsed without receiving a valid buffer content, where said predefined number of time intervals is based on a buffer size and an estimate of a maximum number of alerts written by said host per time interval under non-adversarial conditions.

17. The server apparatus of claim 7 , wherein said blocking of said access of said host to said network is triggered when more than a predefined number of time intervals have elapsed without receiving a valid buffer content, where said predefined number of time intervals is based on a buffer size and an estimate of a maximum number of alerts written by said host per time interval under non-adversarial conditions.

18. The method of claim 1 , further comprising the step of filtering one or more redundant messages.

19. The non-transitory machine-readable recordable storage medium of claim 6 , further comprising the step of filtering one or more redundant messages.

20. The server apparatus of claim 7 , wherein said at least one hardware device is further configured to filter one or more redundant messages.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 048825 FRAME 0489 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058000/0916 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Apr 8, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 048825/0489 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2018
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 047395/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2013
From: JUELS, ARI; TRIANDOPOULOS, NIKOLAOS; BOWERS, KEVIN D.
To: EMC CORPORATION
Reel/Frame 031475/0855 →
Continuity (1)
Continuation In Part 13537981 · Jun 29, 2012
Cited By (1)
US 12,676,898