| US 7,373,666 B2 | ||
| Distributed threat management | ||
| Christopher G. Kaler, Sammamish, Wash. (US); Giovanni Moises Della-Libera, Seattle, Wash. (US); and John P. Shewchuk, Redmond, Wash. (US) | ||
| Assigned to Microsoft Corporation, Redmond, Wash. (US) | ||
| Filed on Jul. 01, 2002, as Appl. No. 10/185,008. | ||
| Prior Publication US 2004/0003286 A1, Jan. 01, 2004 | ||
| Int. Cl. G06F 12/00 (2006.01); G06F 7/04 (2006.01); G06F 11/30 (2006.01); H04L 9/32 (2006.01) | ||
| U.S. Cl. 726—23 [726/2; 726/3; 726/4; 726/5; 726/6; 726/7; 726/8; 726/25; 726/26; 726/27; 713/187; 713/188; 709/223; 709/224; 709/225] | 51 Claims |

| 1. A method for managing a security threat in a distributed system, comprising:
detecting data correlated to suspicious activity in a distributed element of the system; and
reporting data correlated to the suspicious activity from a distributed element to a threat management agent configured to
achieve a coordinated response to the threat;
determining, by the threat management agent based on an aggregate of data correlated to the suspicious activity in the distributed
system, whether an attack is taking place at least at one distributed element identified by the data correlated to the suspicious
activity;
deploying a coordinated countermeasure to the attack including a preventive deployment of a countermeasure to at least one
distributed element not initially reporting data correlated to suspicious activity, as directed by the threat management agent,
based on the attack determination by the threat management agent;
reviewing, by a threat management agent, of reports of data correlated to suspicious activity from at least one distributed
element of the system;
determining by the threat management agent, based on the reports, whether a pattern characteristic of an attack occurred and
predicting when a next attack is likely to occur; and
directing deployment of a coordinated countermeasure to the predicted next attack, in a time window based on when the next
attack is predicted to occur, wherein the coordinated countermeasure comprises adjustment of at least one distributed element
of the system where the data correlated to suspicious activity was not detected.
|