Dynamic Host Intrusion Prevention Filter Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing host intrusion prevention systems (HIPS) face challenges in optimally provisioning and managing filters, leading to increased processing load and reduced performance due to the incremental addition of filters, necessitating a method for dynamic filter management and minimization of processing effort.

Innovation Solution

A system comprising a central server, local servers acting as deep security managers (DSM), and software agents on hosts, which dynamically determine and apply necessary filters based on host-specific metadata, using detection rules and expressions to add or remove filters as needed, thereby optimizing the host's security configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If filters are added to the HIPS to improve intrusion detection capability, then security coverage is improved, but system processing load increases and performance deteriorates

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem processing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by customizing filter sets for different host types based on their specific security needs and characteristics. Instead of applying a uniform filter set to all hosts, the system determines host type from metadata and selectively applies only the necessary filters to each host, thereby improving security coverage where needed while reducing processing load on hosts that don't require certain filters.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the filter configuration parameter based on host type. The central server receives host metadata, determines the appropriate host type, and returns a customized filter set. This parameter change approach allows the system to adapt the security configuration to match the specific requirements of different host types, optimizing the balance between security coverage and processing performance.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a comprehensive filter set is applied to all hosts to ensure maximum security coverage, then security capability is improved, but processing effort and resource utilization increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing effort
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the necessary filters from the comprehensive filter set and applies them selectively to specific host types. The central server processes host metadata to identify the appropriate host type and returns only the relevant subset of filters, thereby extracting and removing unnecessary filters that would otherwise increase processing effort without providing additional security benefit.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements local quality by tailoring the filter configuration to the specific characteristics and security needs of each host type. Different host types receive different filter sets based on their metadata, ensuring that processing resources are allocated efficiently and only necessary security measures are applied to each host.

Inventive Principle:
Principle #3Local quality

3Productivity

If filters are dynamically added and removed based on host configuration to optimize performance, then processing effort is reduced, but system complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidfilter management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a central server as an intermediary between the filter management system and individual hosts. The central server receives host metadata, determines the appropriate filter set, and distributes it to the respective hosts. This intermediary approach centralizes the complexity of filter management decisions while keeping individual host implementations simple, thereby reducing overall system complexity despite dynamic filter provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The central server performs multiple functions: collecting host metadata, determining host types, selecting appropriate filters, and distributing configurations. This multi-functional design consolidates complexity into a single universal component rather than distributing it across multiple hosts, making the system more manageable while achieving dynamic optimization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9813377B2Dynamic provisioning of protection software in a host intrusion prevention system
Publication Date: 2017.11.07 TREND MICRO INC
  • US9813377B2 patent drawing
  • US9813377B2 patent drawing
  • US9813377B2 patent drawing

AI summary

Methods and apparatus for optimizing security configurations of a set of computers are disclosed. A set of local servers, each functioning as a deep-security manager supporting a respective subset of the computers, maintains protection software containing filters and rules for deploying each filter. A local server receives updated protection software from a central server. Each local server interrogates each computer of its subset of computers to acquire computer-characterizing data and applies relevant rules to determine an optimal set of filters for each computer. Each rule adaptively determines required characterizing data elements from each computer for determining an optimal security configuration. A local server updates the security configuration of a computer to suit changes in the operational environment of the computer.