IP Library Patent Application 14094961
Patent Application
App. No. 14/094,961

Security Event Routing In a Distributed Hash Table

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/094,961
Abstract

Embodiments include components of a computer defense network (CND) architecture, e.g. a content addressable network (CAN) gateway, a CAN peer or a CND controller. The gateway is configured to receive from a host a security event log that includes a protocol tag, and to securely forward the log to a selected one of a plurality of CAN peers based on the protocol tag. The CAN peer is configured to configured to filter the events based on an assigned communication protocol, and to produce a security report from the filtered events. The CND controller is configured to receive the filtered report from the peer and to defend the network against a threat based on the report.

Claims (53)

1 . An apparatus, comprising:

a processor;

a memory coupled to said processor and containing instructions that when executed configure the processor to:

receive from a host a security event log including a protocol tag; and

securely forward the security event log, to a selected one of a plurality of peers in a distributed hash table (DHT), based on the protocol tag.

2 . The apparatus of claim 1 , wherein said DHT is a content addressable network (CAN).

3 . The apparatus of claim 1 , wherein said processor is configured to accept said security event log only on the condition that the security event log includes a valid security certificate.

4 . The apparatus of claim 1 , wherein said processor is configured to forward said security event log only on the condition that said selected one is authenticated.

5 . The apparatus of claim 1 , wherein said protocol tag is selected from the group consisting of hypertext transfer protocol (HTTP), secure hypertext transfer protocol (HTTPs), session initiation protocol (SIP), secure shell protocol (SSH), file transfer protocol (FTP), and secure file transfer protocol (sFTP) and Microsoft NetBIOS.

6 . An apparatus, comprising:

a processor;

a memory coupled to said processor and containing instructions that when executed by the processor configure the processor to:

receive one of a plurality of security event reports from corresponding ones of a plurality of peers in a computer network, each one of the security event reports being associated with a particular communication protocol; and

defend, in response to the received security event reports, against a threat to the network based on the received security event reports.

7 . The apparatus of claim 6 , wherein said peers are members of a distributed hash table (DHT).

8 . The apparatus of claim 7 , wherein said DHT includes a content addressable network (CAN).

9 . The apparatus of claim 6 , wherein said processor is configured to accept the security event reports only on the condition that identities of each of the peers are authenticated.

10 . The apparatus of claim 6 , wherein said processor is configured to block traffic from an IP address associated with said threat.

11 . The apparatus of claim 6 , wherein said communication protocol is selected from the group consisting of hypertext transfer protocol (HTTP), secure hypertext transfer protocol (HTTPs), session initiation protocol (SIP), secure shell protocol (SSH), file transfer protocol (FTP), and secure file transfer protocol (sFTP) and Microsoft NetBIOS.

12 . An apparatus, comprising:

a processor;

a memory coupled to said processor and containing instructions that when executed configure the processor to:

receive security events from an event generator;

filter said events based on an assigned communication protocol;

produce a security report from said filtered events; and

send said report to a security controller.

13 . The apparatus of claim 12 , wherein said processor is further configured to filter events by rejecting events associated with non-assigned communication protocols.

14 . The apparatus of claim 12 , wherein the processor is configured to receive said events from a single gateway computer.

15 . The apparatus of claim 12 , wherein said assigned communication protocol is selected from the group consisting of hypertext transfer protocol (HTTP), secure hypertext transfer protocol (HTTPs), session initiation protocol (SIP), secure shell protocol (SSH), file transfer protocol (FTP), and secure file transfer protocol (sFTP) and Microsoft NetBIOS.

16 . The apparatus of claim 12 , wherein said processor is one of a plurality of processors configured to filter said events based on said assigned communication protocol, but only said processor is configured to send said report to a security controller.

17 . An method, comprising:

receiving from a host a security event log including a protocol tag; and

securely forwarding the security event log, to a selected one of a plurality of peers in a distributed hash table (DHT), based on the protocol tag.

18 . The method of claim 17 , wherein said DHT is a content addressable network (CAN).

19 . The method of claim 17 , further comprising accepting said security event log only on the condition that the security event log includes a valid security certificate.

20 . The method of claim 17 , further comprising forwarding said security event log only on the condition that said selected one is authenticated.

21 . The method of claim 17 , wherein said protocol tag is selected from the group consisting of hypertext transfer protocol (HTTP), secure hypertext transfer protocol (HTTPs), session initiation protocol (SIP), secure shell protocol (SSH), file transfer protocol (FTP), and secure file transfer protocol (sFTP) and Microsoft NetBIOS.

22 . An method, comprising:

receiving one of a plurality of security event reports from corresponding ones of a plurality of peers in a computer network, each one of the security event reports being associated with a particular communication protocol; and

defending, in response to the received security event reports, against a threat to the network based on the received security event reports, the defending comprising at least one of 1) electronically generating an visual or aural notification, and 2) directing instructions to a router via a physical data path to block internet traffic originating from an IP address associated with the threat.

23 . The method of claim 22 , wherein said peers are members of a distributed hash table (DHT).

24 . The method of claim 23 , wherein said DHT includes a content addressable network (CAN).

25 . The method of claim 22 , further comprising accepting said security event reports only from ones of the peers that have an authenticated identity.

26 . The method of claim 22 , wherein said instructions direct said router to block IP packets from said IP address to a controller of the network.

27 . The method of claim 22 , wherein said communication protocol is selected from the group consisting of hypertext transfer protocol (HTTP), secure hypertext transfer protocol (HTTPs), session initiation protocol (SIP), secure shell protocol (SSH), file transfer protocol (FTP), and secure file transfer protocol (sFTP) and Microsoft NetBIOS.

28 . An method, comprising:

receiving logs of security events from an event generator;

filtering said events based on an assigned communication protocol;

producing a security event report from said filtered events; and

sending said event report to a security controller.

29 . The method of claim 28 , further comprising filtering said events by rejecting events associated with non-assigned communication protocols.

30 . The method of claim 28 , wherein said filtering may include determining a statistical measure of the filtered events.

31 . The method of claim 28 , wherein said assigned communication protocol is selected from the group consisting of hypertext transfer protocol (HTTP), secure hypertext transfer protocol (HTTPs), session initiation protocol (SIP), secure shell protocol (SSH), file transfer protocol (FTP), and secure file transfer protocol (sFTP) and Microsoft NetBIOS.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2015
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 034737/0399 →
RELEASE OF SECURITY INTEREST Recorded Aug 28, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033654/0480 →
SECURITY AGREEMENT Recorded Feb 7, 2014
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 032176/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2013
From: GURBANI, VIJAY
To: ALCATEL LUCENT USA INC.
Reel/Frame 031703/0882 →