Invention Grant
- Patent Title: Applying blocking measures progressively to malicious network traffic
- Patent Title (中): 对恶意网络流量逐步应用阻塞措施
-
Application No.: US11871188Application Date: 2007-10-12
-
Publication No.: US07707633B2Publication Date: 2010-04-27
- Inventor: Robert William Danford , Kenneth M. Farmer , Clark Debs Jeffries , Robert B. Sisk , Michael A. Walter
- Applicant: Robert William Danford , Kenneth M. Farmer , Clark Debs Jeffries , Robert B. Sisk , Michael A. Walter
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Schmeiser, Olsen & Watts
- Agent David R. Irvine
- Main IPC: G06F11/30
- IPC: G06F11/30 ; G08B23/00 ; G06F11/18

Abstract:
A method of progressive response for invoking and suspending blocking measures that defend against network anomalies such as malicious network traffic so that false positives and false negatives are minimized. When an anomaly is detected, the detector notifies protective equipment such as a firewall or a router to invoke a blocking measure. The blocking measure is maintained for an initial duration, after which it is suspended while another test for the anomaly is made. If the anomaly is no longer evident, the method returns to the state of readiness. Otherwise, a loop is executed to re-apply the blocking measure for a specified duration, then suspend the blocking measure and test again for the anomaly. If the anomaly is detected, the blocking measure is re-applied, and its duration is adapted. If the anomaly is no longer detected, the method returns to the state of readiness.
Public/Granted literature
- US20080072326A1 APPLYING BLOCKING MEASURES PROGRESSIVELY TO MALICIOUS NETWORK TRAFFIC Public/Granted day:2008-03-20
Information query