Invention Application
- Patent Title: HYBRID HARDWARE-SOFTWARE DISTRIBUTED THREAT ANALYSIS
-
Application No.: US15054671Application Date: 2016-02-26
-
Publication No.: US20170250953A1Publication Date: 2017-08-31
- Inventor: Navendu Jain , Ang Chen
- Applicant: Microsoft Technology Licensing, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Embodiments relate to detecting and mitigating network intrusions. Packets are inspected at their source/destination hosts to identify packet trends local to the hosts. The local packet trends are combined to identify network-wide packet trends. The network-wide packet trends are used to detect anomalies or attacks, which in turn informs mitigation actions. The local inspection may be performed by reconfigurable/reprogrammable “smart” network interfaces (NICs) at each of the hosts. Local inspection involves identifying potentially suspect packet features based on statistical prevalence of recurring commonalities among the packets; pre-defined threat patterns are not required. For network-wide coherence, each host/NIC uses the same packet-identifying and occurrence-measuring algorithms. An overlay or control server collects and combines the local occurrence-measures to derive the network-wide occurrence-measures. The network-wide occurrences can be used to automatically detect and mitigate completely new types of attack packets.
Public/Granted literature
- US10608992B2 Hybrid hardware-software distributed threat analysis Public/Granted day:2020-03-31
Information query