ABSTRACT

Network elements that are configured to perform deep packet inspection may be dynamically updated with patterns associated with malicious code, so that malicious code may be detected and blocked at the network level.

As new threats are identified by a security service, new patterns may be created for those threats, and the new patterns may then be passed out onto the network in real time. The real time availability of patterns enables filter rules derived from the patterns to be applied by the network elements so that malicious code may be filtered on the network before it reaches the end users. The filter rules may be derived by security software resident in the network elements or may be generated by a filter generation service configured to generate network element specific filter rules for those network elements that are to be implemented as detection points on the network.

Method and apparatus for network immunization
Method and apparatus for network immunization

Method and apparatus for network immunization

An Inventor: Dr. Tal Lavian

BACKGROUND OF THE INVENTION

1. Field of the Invention

2. Description of the Related Art

SUMMARY OF THE INVENTION