Invention Grant
- Patent Title: Hybrid hardware-software distributed threat analysis
-
Application No.: US15054671Application Date: 2016-02-26
-
Publication No.: US10608992B2Publication Date: 2020-03-31
- Inventor: Navendu Jain , Ang Chen
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56 ; G06F21/57 ; G06F21/55

Abstract:
Embodiments relate to detecting and mitigating network intrusions. Packets are inspected at their source/destination hosts to identify packet trends local to the hosts. The local packet trends are combined to identify network-wide packet trends. The network-wide packet trends are used to detect anomalies or attacks, which in turn informs mitigation actions. The local inspection may be performed by reconfigurable/reprogrammable “smart” network interfaces (NICs) at each of the hosts. Local inspection involves identifying potentially suspect packet features based on statistical prevalence of recurring commonalities among the packets; pre-defined threat patterns are not required. For network-wide coherence, each host/NIC uses the same packet-identifying and occurrence-measuring algorithms. An overlay or control server collects and combines the local occurrence-measures to derive the network-wide occurrence-measures. The network-wide occurrences can be used to automatically detect and mitigate completely new types of attack packets.
Public/Granted literature
- US20170250953A1 HYBRID HARDWARE-SOFTWARE DISTRIBUTED THREAT ANALYSIS Public/Granted day:2017-08-31
Information query