Dynamic Intrusion Detection Rulesets for Network Threat Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Intrusion Detection and Prevention Systems (IDPS) face a trade-off between the scope of network threat detection and the number of false positives, as static rulesets do not adapt to the specific threat patterns of individual or groups of network sites, leading to suboptimal performance.

Innovation Solution

Dynamic rulesets are configured by clustering network sites based on operational features and threat patterns, using data clustering techniques and machine learning models to predict threat frequencies and adjust rule sets accordingly, balancing detection scope and false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If static rulesets are used for intrusion detection, then the system is simple to implement, but the detection accuracy and adaptability to specific network threats deteriorate

Engineering Contradiction:
Improvesystem implementation complexityVSAvoidthreat detection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent implements dynamic rulesets that automatically adapt to each network site's specific threat patterns through machine learning models. The system transitions from static, predefined rules to dynamic, site-specific rules that are continuously updated based on observed threat frequencies and patterns, resolving the contradiction between system simplicity and detection accuracy.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of the rulesets based on observed threat patterns at each network site. By adjusting rule priorities, thresholds, and specific detection parameters according to site-specific threat frequencies, the system achieves high detection accuracy without requiring complex manual configuration, thus resolving the contradiction between simplicity and precision.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If strict rulesets are applied to increase threat detection scope, then more threats are detected, but the number of false positives increases

Engineering Contradiction:
Improvethreat detection scopeVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies different ruleset configurations to different network sites based on their specific threat patterns. Each site receives a customized ruleset that is locally optimized for its threat landscape, allowing strict detection where needed while maintaining lower false positive rates overall. This local customization resolves the contradiction between detection scope and false positive reduction.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the strictness of rulesets based on observed threat patterns at each site. Rather than applying uniformly strict rules everywhere, the system adapts the detection threshold and rule severity to match actual threat frequencies, achieving comprehensive detection while minimizing false positives through dynamic parameter adjustment.

Inventive Principle:
Principle #15Dynamics

3Object-generated harmful factors

If lenient rulesets are used to reduce false positives, then false positive rate decreases, but the scope of threat detection is reduced

Engineering Contradiction:
Improvefalse positive rateVSAvoidthreat detection scope
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The system applies lenient or strict rules locally at each network site based on its specific threat patterns. Sites with low threat frequencies receive lenient rulesets that reduce false positives, while sites with high threat frequencies receive stricter rulesets that expand detection scope. This local differentiation resolves the contradiction between false positive reduction and detection scope.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If dynamic rulesets are implemented for each network site, then adaptability to specific threats improves, but system complexity increases

Engineering Contradiction:
Improveadaptability to network threatsVSAvoidsystem configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated machine learning models that analyze threat patterns and generate optimized rulesets for each network site without requiring manual configuration. The system automatically adapts to new threat patterns and updates rulesets dynamically, achieving high adaptability while keeping operational complexity low through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback from observed threat patterns to automatically adjust and optimize rulesets for each network site. By continuously monitoring threat frequencies and using this feedback to refine detection parameters, the system achieves high adaptability to specific threats while eliminating the need for complex manual tuning and configuration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12088633B2Dynamic intrusion detection and prevention in computer networks
Publication Date: 2024.09.10 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12088633B2 patent drawing
  • US12088633B2 patent drawing
  • US12088633B2 patent drawing

AI summary

The present disclosure describes dynamic intrusion detection and prevention in computer networks. The method includes generation of clusters of network sites based on a plurality of parameters related to operational features and network threats associated with the network sites. Data models are trained upon the clusters developed through the clustering. The data models are executed to predict a threat frequency of each network threat for each cluster. A difference between the predicted threat frequency of each network threat and corresponding baseline frequencies is determined. Dynamic rulesets are configured, based on the difference between the predicted threat frequency of each network threat and the corresponding baseline frequencies, for each cluster by integrating rules applicable to prevent each network threat.