Crowd-Sourced Intrusion Detection Rule Recommendation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems rely heavily on the experience and knowledge of administrators to define responses to malicious activities, leading to vulnerabilities when less experienced administrators operate them, and require continuous updates to adapt to emerging threats, often resulting in false alerts due to non-personalized rule definitions.

Innovation Solution

An improved method where electronic circuitry receives numerical ratings from one intrusion detection system to predict the effectiveness of rules in another, transmitting recommendations based on collective administrator experiences, reducing the burden on individual administrator expertise and relying on crowd-sourced wisdom.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an administrator manually defines intrusion detection rules based on personal experience and knowledge, then the system can respond to malicious activities, but the effectiveness varies significantly with administrator skill level and creates vulnerability when less experienced administrators operate the system

Engineering Contradiction:
Improvedetection effectivenessVSAvoidadministrator skill dependency
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a rule recommendation system that acts as an intermediary between experienced administrators and less experienced ones. The system collects performance data from multiple administrators, analyzes it centrally, and generates personalized rule recommendations. This intermediary mechanism transfers detection expertise from experienced to less experienced administrators without requiring direct human-to-human knowledge transfer, thereby reducing skill dependency while maintaining detection effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback loop where detection rules are continuously evaluated based on their performance in identifying malicious versus benign traffic. This feedback information is collected, analyzed, and used to refine and update rule recommendations. The feedback mechanism ensures that rules evolve based on actual performance data, maintaining high detection effectiveness across different administrator skill levels.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If an administrator continuously maintains up-to-date threat awareness and manually researches intelligence sources, then the system can adapt to emerging threats, but this places a heavy burden on the administrator and is difficult to sustain

Engineering Contradiction:
Improvethreat response adaptabilityVSAvoidadministrator burden
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system enables self-service by automatically collecting intelligence from multiple sources, analyzing threat patterns, and generating updated rule recommendations without requiring continuous administrator intervention. The automated rule recommendation engine performs the burden-intensive tasks of research and analysis, while administrators simply receive and apply recommendations, dramatically reducing operational burden while maintaining adaptability to emerging threats.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively collecting intelligence data, analyzing threat patterns, and preparing rule recommendations in advance before administrators need them. This preliminary processing of threat intelligence and rule generation occurs automatically in the background, so when administrators need to respond to threats, ready-to-use recommendations are already available, reducing their workload and response time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If intrusion detection rules are defined through administrator interpretation of intelligence sources, then the system can respond to threats, but the rules are not personalized to the specific administrator's system and result in frequent false alerts

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem personalization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by tailoring rule recommendations to each specific administrator's system characteristics, traffic patterns, and historical performance data. Instead of providing generic rules, the system analyzes local system attributes and generates customized recommendations that fit each environment uniquely. This personalization reduces false alerts by ensuring rules are appropriate for each system's specific context while maintaining high detection accuracy.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10148673B1Automatic selection of malicious activity detection rules using crowd-sourcing techniques
Publication Date: 2018.12.04 EMC IP HLDG CO LLC
  • US10148673B1 patent drawing
  • US10148673B1 patent drawing
  • US10148673B1 patent drawing

AI summary

Techniques of operating intrusion detection systems provide a recommendation of an intrusion detection rule to an administrator of an intrusion detection system based on the experience of another administrator that has used the rule in another intrusion detection system. For example, suppose that electronic circuitry receives a numerical rating from a first intrusion detection system that indicates whether an intrusion detection rule was effective in identifying malicious activity when used in the first intrusion detection system. Based on the received rating and attributes of the first intrusion detection system, the electronic circuitry generates a predicted numerical rating that indicates whether the intrusion detection rule is likely to be effective in identifying malicious communications when used in a second intrusion detection system. If the predicted numerical rating is sufficiently high, then the electronic circuitry transmits a message to the second intrusion detection system recommending the intrusion detection rule for use in the second intrusion detection system.