US 7,373,666 B2
Distributed threat management
Christopher G. Kaler, Sammamish, Wash. (US); Giovanni Moises Della-Libera, Seattle, Wash. (US); and John P. Shewchuk, Redmond, Wash. (US)
Assigned to Microsoft Corporation, Redmond, Wash. (US)
Filed on Jul. 01, 2002, as Appl. No. 10/185,008.
Prior Publication US 2004/0003286 A1, Jan. 01, 2004
Int. Cl. G06F 12/00 (2006.01); G06F 7/04 (2006.01); G06F 11/30 (2006.01); H04L 9/32 (2006.01)
U.S. Cl. 726—23  [726/2; 726/3; 726/4; 726/5; 726/6; 726/7; 726/8; 726/25; 726/26; 726/27; 713/187; 713/188; 709/223; 709/224; 709/225] 51 Claims
OG exemplary drawing
 
1. A method for managing a security threat in a distributed system, comprising:
detecting data correlated to suspicious activity in a distributed element of the system; and
reporting data correlated to the suspicious activity from a distributed element to a threat management agent configured to achieve a coordinated response to the threat;
determining, by the threat management agent based on an aggregate of data correlated to the suspicious activity in the distributed system, whether an attack is taking place at least at one distributed element identified by the data correlated to the suspicious activity;
deploying a coordinated countermeasure to the attack including a preventive deployment of a countermeasure to at least one distributed element not initially reporting data correlated to suspicious activity, as directed by the threat management agent, based on the attack determination by the threat management agent;
reviewing, by a threat management agent, of reports of data correlated to suspicious activity from at least one distributed element of the system;
determining by the threat management agent, based on the reports, whether a pattern characteristic of an attack occurred and predicting when a next attack is likely to occur; and
directing deployment of a coordinated countermeasure to the predicted next attack, in a time window based on when the next attack is predicted to occur, wherein the coordinated countermeasure comprises adjustment of at least one distributed element of the system where the data correlated to suspicious activity was not detected.