Inventors:
Edouard Granstedt - Great Falls VA, US
Troy C. Nolan - Bristow VA, US
Brian D. Womack - Leesburg VA, US
Joseph S. Klein - Reston VA, US
Assignee:
Qinetiq North America, Inc. - McLean VA
International Classification:
G06F 11/00, G06F 15/173
Abstract:
A computer system for providing security in a computer network includes: a global sensor device configured to determine potential threats to the computer network; a global threat manager device configured to determine identification information associated with the potential threats; and a local security device configured to detect the existence of the potential threats based on the identification information and to take remedial action in response to the potential threats. The system also provides for responding to network attacks in a sufficiently granular method that is optimized according to the current state of the network by maintaining a virtual model of the network; detecting a network attack; generating a plurality of alternative candidate remedial responses to the network attack; and determining a potential network impact of each candidate remedial response using the virtual model of the network.