Dynamic Rule Generation for Enterprise Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise intrusion detection systems lack scalability and effective communication across components, making it difficult to quickly update intrusion signatures and detect long-term attacks.

Innovation Solution

A vertically extensible intrusion detection system that dynamically generates rules by processing packet flows to detect attacks, automatically generating response messages and communicating them across multiple logical levels, enabling enterprise-wide deployment of dynamic signatures and reducing information volume between system levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional intrusion detection systems use multiple analysts to evaluate network data with various tool implementations, then detection capability is improved, but system complexity and operational cost increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates intrusion detection rules by processing packet flows and detecting attacks without requiring multiple human analysts. The rule generation is performed autonomously by the IDS itself, which processes network data, identifies attack patterns, and creates detection rules automatically, eliminating the need for complex manual analysis operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of multiple human analysts manually evaluating data with an automated computational system. The IDS uses algorithmic processing of packet flows and automatic pattern recognition to substitute human analytical operations, thereby reducing operational complexity while maintaining or improving detection capability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If traditional IDS lack ability to quickly update intrusion signatures at large number of nodes, then scalability is improved, but detection responsiveness deteriorates

Engineering Contradiction:
ImprovescalabilityVSAvoiddetection responsiveness
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The system implements dynamic rule generation where detection rules are continuously updated based on real-time analysis of packet flows. The IDS adapts its detection capabilities dynamically by processing incoming network data and automatically generating updated rules, allowing rapid response to new attack patterns across all nodes without requiring manual signature updates

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary analysis of packet flows to detect attack patterns and generate detection rules in advance. By continuously monitoring and analyzing network traffic, the IDS prepares detection rules proactively, enabling rapid deployment of new signatures across the enterprise network before attacks occur or as soon as they are detected

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If conventional IDS do not include capability to effectively detect long-term attacks, then detection scope is improved, but ability to detect slow attacks deteriorates

Engineering Contradiction:
Improvedetection scopeVSAvoidability to detect slow attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements continuous processing of packet flows to detect attacks over extended periods. The IDS maintains ongoing analysis of network traffic, accumulating data and patterns over time to reliably detect slow, low-level attacks that unfold across multiple time intervals, ensuring continuous detection coverage without gaps

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system uses feedback from continuous packet flow analysis to improve detection of long-term attacks. By monitoring network traffic over extended periods and using the accumulated information to refine detection rules, the IDS enhances its ability to identify gradual or persistent attack patterns that develop over time

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7895649B1Dynamic rule generation for an enterprise intrusion detection system
Publication Date: 2011.02.22 EVERFOX HOLDINGS LLC
  • US7895649B1 patent drawing
  • US7895649B1 patent drawing
  • US7895649B1 patent drawing

AI summary

A method for dynamically generating rules for an enterprise intrusion detection system comprises receiving a packet flow from a sensor. The packet flow is dynamically processed to detect if the packet flow represents an attack on the enterprise system. A response message is automatically generated in response to the attack, the response message comprising a signature to identify the attack. The response message is automatically communicated to a response message file, the response message file comprising at least one response message.