A cooperative processing and escalation method and system for use in
multi-node application-layer security management is disclosed. The method
includes the steps of identifying individual application security nodes,
grouping and configuring nodes for cooperative processing, assigning the
default operational mode at each node, assignment of logging and alert
event tasks at each node, and defining escalation and de-escalation rules
and triggers at each node. Both loosely-coupled and tightly-coupled
configurations, each with its cooperative processing model, are
disclosed. The method includes provision for central console
configuration and control, near real-time central console dashboard
operations interface, alert notification, and operator override of
operational modes and event tasks.