Invention Grant
- Patent Title: On-box active reconnaissance
- Patent Title (中): 机上主动侦察
-
Application No.: US11030139Application Date: 2005-01-07
-
Publication No.: US07934257B1Publication Date: 2011-04-26
- Inventor: Darrell Kienzle , Paul Swinton
- Applicant: Darrell Kienzle , Paul Swinton
- Applicant Address: US CA Cupertino
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Cupertino
- Agency: Finnegan, Henderson, Farabow, Garrett & Dunner, LLP
- Main IPC: H04L29/14
- IPC: H04L29/14

Abstract:
A method of monitoring events in a network associated with a node. An agent collects event information associated with the monitored activities, based on a set of collection rules. A determination is made whether a portion of the collected event information complies or potentially complies with one of a set of patterns. An agent selects event information from the collection based on the determination, and makes the selected event information available to a manager associated with the node and other nodes in the network. The agent manager receives event information from a plurality of agents. A triggering event is identified, as a function of the set of patterns, based on the event information. The agent manager sends at least one request to a selected set of the agents for additional event information when a triggering event is identified.
Information query