System and method for defending a network against cyber-threats

US11356471B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11356471-B2
Application numberUS-201916537013-A
CountryUS
Kind codeB2
Filing dateAug 9, 2019
Priority dateAug 9, 2019
Publication dateJun 7, 2022
Grant dateJun 7, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system for defending a network against one or more cyber-threats. The system can include a network bus that includes a first node and a second node, such that network traffic flows from the first node to the second node. The system can include an intrusion defense unit connected to the network bus, such that network traffic between the first node and the second node passes through the intrusion defense unit, wherein when a potential cyber-threat is detected in the network traffic, the intrusion defense unit is configured to engage an associated switch to filter the network traffic until the cyber-threat is neutralized.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for defending a network against one or more cyber-threats, the system comprising: a network bus that includes a first node and a second node, such that network traffic flows from the first node to the second node; and an intrusion defense unit connected to the network bus, such that network traffic between the first node and the second node passes through the intrusion defense unit, wherein: network traffic that passes through the intrusion defense unit is logged and cascaded to obtain searchable data; and when a potential cyber-threat is detected in the network traffic, the intrusion defense unit is configured to engage an associated switch to filter the network traffic until the cyber-threat is neutralized, wherein the switch is engaged by a hardware device comprising one or more MOSFETs. 2. The system of claim 1 , wherein the intrusion defense unit is configured to passively monitor the network traffic before the cyber-threat is detected. 3. The system of claim 1 , wherein the intrusion defense unit is configured to passively monitor the network traffic after the cyber-threat is neutralized. 4. The system of claim 1 , wherein the cyber-threat is detected based on an anomalous behavior of one or more nodes of the network. 5. The system of claim 1 , wherein the cyber-threat is detected based on an anomalous behavior of the network traffic. 6. The system of claim 5 , wherein the cyber-threat is detected based on a signature recognition of the anomalous behavior. 7. The system of claim 5 , wherein the anomalous behavior is detected by parsing one or more messages in the network traffic. 8. A method for defending a network against one or more cyber-threats, the method comprising: detecting a potential cyber-threat in network traffic flowing from a first node to a second node within a network bus, wherein the network traffic between the first node and second node passes through an intrusion defense unit; logging and cascading network traffic that passes through the intrusion defense unit to obtain searchable data; and filtering network traffic via the intrusion defense unit and an associated switch connected to the network bus, when the potential cyber-threat is detected, wherein the filtering is performed until the cyber-threat is neutralized, wherein the switch is engaged by a hardware device comprising one or more MOSFETs. 9. The method of claim 8 , wherein the intrusion defense unit is configured to passively monitor the network traffic before the cyber-threat is detected. 10. The method of claim 8 , wherein the intrusion defense unit is configured to passively monitor the network traffic after the cyber-threat is neutralized. 11. The method of claim 8 , wherein the cyber-threat is detected based on an anomalous behavior of one or more nodes of the network. 12. The method of claim 8 , wherein the cyber-threat is detected based on an anomalous behavior of the network traffic. 13. The method of claim 12 , wherein the cyber-threat is detected based on a signature recognition of the anomalous behavior. 14. The method of claim 12 , comprising: detecting the anomalous behavior by parsing one or more messages in the network traffic.

Assignees

Inventors

Classifications

  • H04L63/145Primary

    the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • Vulnerability analysis · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11356471B2 cover?
A system for defending a network against one or more cyber-threats. The system can include a network bus that includes a first node and a second node, such that network traffic flows from the first node to the second node. The system can include an intrusion defense unit connected to the network bus, such that network traffic between the first node and the second node passes through the intrusi…
Who is the assignee on this patent?
Booz Allen Hamilton Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/145. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 07 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).