US2015304333A1PendingUtilityA1

Network Zone Identification In A Network Security System

Assignee: HEWLETT PACKARD DEVELOPMENT COPriority: Oct 27, 2004Filed: Jun 29, 2015Published: Oct 22, 2015
Est. expiryOct 27, 2024(expired)· nominal 20-yr term from priority
H04L 63/10H04L 63/02H04L 63/1408H04L 63/20H04L 63/101
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Different network segments can have overlapping address spaces. In one embodiment, the present invention includes a distributed agent of a security system receiving a security event from a network device monitored by the agent. In one embodiment, the agent normalizes the security event into an event schema including one or more zone fields. In one embodiment, the agent also determines one or more zones associated with the received security event, the one or more zones each describing a part of a network, and populates the one or more zone fields using the determined one or more zones.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method performed by a distributed software agent of a network security system, the method comprising:
 receiving a security event from a network device monitored by the agent;   normalizing the security event into an event schema including one or more zone fields;   determining one or more zones associated with the received security event, the one or more zones each describing a part of a network; and   populating the one or more zone fields using the determined one or more zones.   
     
     
         2 . The method of  claim 1 , wherein determining one or more zones comprises determining a zone associated with a source of the received security event. 
     
     
         3 . The method of  claim 2 , wherein determining the zone associated with the source of the received security event comprises mapping a source Internet protocol (“IP”) address to the zone associated with the source of the received security event, the zone comprising a range of IP addresses. 
     
     
         4 . The method of  claim 3 , further comprising mapping the determined zone associated with the source of the received security event to a zone name, and populating a zone name field of the normalized security event. 
     
     
         5 . The method of  claim 1 , wherein determining one or more zones comprises determining a zone associated with the network device monitored by the agent. 
     
     
         6 . The method of  claim 5 , wherein determining the zone associated with the network device monitored by the agent comprises mapping a network device Internet protocol (“IP”) address to the zone associated with the network device responsible for generating the received security event, the zone comprising a range of IP addresses. 
     
     
         7 . The method of  claim 1 , wherein determining one or more zones comprises determining a zone associated with the agent. 
     
     
         8 . The method of  claim 7 , wherein determining the zone associated with agent comprises mapping an Internet protocol (“IP”) address of the agent to the zone associated with the agent, the zone comprising a range of IP addresses. 
     
     
         9 . The method of  claim 1 , wherein determining one or more zones comprises determining a zone associated with a destination of the received security event. 
     
     
         10 . The method of  claim 9 , wherein determining the zone associated with the destination of the received security event comprises mapping a destination Internet protocol (“IP”) address to the zone associated with the destination of the received security event, the zone comprising a range of IP addresses. 
     
     
         11 . The method of  claim 1 , wherein determining one or more zones associated with the received security event comprises mapping an Internet protocol (“IP”) address to a zone, wherein the zone comprises a range of IP addresses. 
     
     
         12 . The method of  claim 11 , wherein mapping the IP address to a zone comprises mapping the IP address to a zone and a sub-zone, wherein the sub-zone comprises a range of IP addresses within the range of the zone. 
     
     
         13 . A distributed agent of a network security system, the agent comprising:
 an input buffer to receive a security event from a network device monitored by the agent;   a zone table configured to provide a mapping between internet protocol (“IP”) addresses and zones;   a zone mapper to determine one or more zones associated with the received security event using the zone table; and   an agent normalize module to generate a normalized security event based on the received security event, the normalized security event including the determined one or more zones.   
     
     
         14 . The agent of  claim 13 , wherein the one or more zones include a zone associated with a source of the received security event. 
     
     
         15 . The agent  claim 13 , wherein the one or more zones include a zone associated with a destination of the received security event. 
     
     
         16 . The agent of  claim 13 , wherein the one or more zones include a zone associated with the network device that generated the received security event. 
     
     
         17 . The agent of  claim 13 , wherein the one or more zones include a zone associated with the agent. 
     
     
         18 . A method preformed by a manager of a network security system monitoring a network, the method comprising:
 receiving a first security event from a first distributed agent of the network security system, the first distributed agent configured to receive security events from a first network device monitoring a first portion of the network, the security event including an identifier of the first portion of the network; and   receiving a second security event from a second distributed agent of the network security system, the second distributed agent configured to receive security events from a second network device monitoring a second portion of the network, the second security event including an identifier of the second portion of the network.   
     
     
         19 . The method of  claim 18 , wherein the first portion of the network at least partially shares an address space with the second portion of the network. 
     
     
         20 . The method of  claim 19 , wherein the address space comprises a range of Internet protocol (“IP”) addresses. 
     
     
         21 . The method of  claim 18 , further comprising correlating the first and the second security events using a rules engine. 
     
     
         22 . The method of  claim 18 , wherein the identifier of the first portion of the network comprises an identifier of a portion of the network where a source of the first security event resides. 
     
     
         23 . The method of  claim 18 , wherein the identifier of the first portion of the network comprises an identifier of a portion of the network where the first distributed agent resides. 
     
     
         24 . The method of  claim 18 , wherein the identifier of the first portion of the network comprises an identifier of a portion of the network where the first network device resides. 
     
     
         25 . A manager of a network security system, the manager comprising:
 an agent manager to receive a first security event from a first distributed agent of the network security system, the first distributed agent configured to receive security events from a first network device monitoring a first portion of the network, the security event including an identifier of the first portion of the network, wherein the agent manager is also to receive a second security event from a second distributed agent of the network security system, the second distributed agent configured to receive security events from a second network device monitoring a second portion of the network, the second security event including an identifier of the second portion of the network; and   a rules engine to correlate the first and second security events using the identifier of the first portion of the network and the identifier of the second portion of the network.   
     
     
         26 . The manager of  claim 25 , wherein the first portion of the network at least partially shares an address space with the second portion of the network. 
     
     
         27 . The manager of  claim 26 , wherein the address space comprises a range of Internet protocol (“IP”) addresses. 
     
     
         28 . A normalized event schema for a security event comprising:
 an agent zone field to identify a zone to which a distributed agent of a network security system belongs.   
     
     
         29 . The event schema of  claim 28  further comprising:
 a device zone field to identify a zone to which a monitor device that generated the security event belongs; 
 a source zone field to identify a zone to which a source of the security event belongs; and 
 a destination zone field to identify a zone to which a destination of the security event belongs. 
 
     
     
         30 . A machine-readable medium having stored thereon data representing instructions that, when executed by a processor, cause the processor to perform operations comprising:
 receiving a security event from a network device monitored by the agent;   normalizing the security event into an event schema including one or more zone fields;   determining one or more zones associated with the received security event, the one or more zones each describing a part of a network; and   populating the one or more zone fields using the determined one or more zones.

Join the waitlist — get patent alerts

Track US2015304333A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.