Invention Grant
- Patent Title: Hybrid hardware-software distributed threat analysis
-
Application No.: US15054692Application Date: 2016-02-26
-
Publication No.: US10084752B2Publication Date: 2018-09-25
- Inventor: Navendu Jain , Ang Chen
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Embodiments relate to detecting and mitigating network intrusions. Packets are inspected at their source/destination hosts to identify packet trends local to the hosts. The local packet trends are combined to identify network-wide packet trends. The network-wide packet trends are used to detect anomalies or attacks, which in turn informs mitigation actions. The local inspection may be performed by reconfigurable/reprogrammable “smart” network interfaces (NICs) at each of the hosts. Local inspection involves identifying potentially suspect packet features based on statistical prevalence of recurring commonalities among the packets; pre-defined threat patterns are not required. For network-wide coherence, each host/NIC uses the same packet-identifying and occurrence-measuring algorithms. An overlay or control server collects and combines the local occurrence-measures to derive the network-wide occurrence-measures. The network-wide occurrences can be used to automatically detect and mitigate completely new types of attack packets.
Public/Granted literature
- US20170250954A1 HYBRID HARDWARE-SOFTWARE DISTRIBUTED THREAT ANALYSIS Public/Granted day:2017-08-31
Information query