Host Intrusion Prevention Server Dynamic Filter Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Host intrusion prevention systems (HIPS) face challenges in optimally provisioning filters and minimizing processing effort while ensuring appropriate protection, as each filter added increases system load, leading to performance degradation.

Innovation Solution

A dynamic mechanism involving a central server, local servers acting as deep security managers (DSM), and software agents on hosts, which use detection rules and expressions to determine required filters and remove redundant ones based on host configuration and events, optimizing filter provisioning and reducing processing effort.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If filters are added to HIPS to improve protection coverage, then security reliability is improved, but system processing performance deteriorates due to increased system load

Engineering Contradiction:
Improvesecurity protection coverageVSAvoidsystem processing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic filter management where the HIPS system automatically adds or removes filters based on real-time host state changes. The system monitors host events and dynamically adjusts the filter set to maintain only those filters necessary for current security requirements, preventing static accumulation of unnecessary filters that would degrade performance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameters of the filter set by adding or removing specific filters based on host state transitions. When host state changes occur (such as service starts, stops, or configuration changes), the system evaluates which filters remain relevant and modifies the active filter configuration accordingly, optimizing the balance between security coverage and processing performance

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive filters are deployed to all hosts to ensure adequate protection, then security coverage is improved, but processing effort increases across the system

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing effort
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by customizing the filter configuration for each individual host based on its specific state and requirements. Rather than deploying a uniform comprehensive filter set to all hosts, the system evaluates each host's services, applications, and security needs, then provisions only the locally necessary filters, reducing overall processing effort while maintaining adequate protection

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the filter provisioning process by dividing the comprehensive filter set into host-specific subsets. Each host receives a segmented, tailored collection of filters relevant to its specific configuration and risk profile, rather than the complete filter inventory, thereby reducing processing effort across the system while maintaining security coverage where needed

Inventive Principle:
Principle #1Segmentation

3Productivity

If manual filter provisioning is used to optimize performance, then processing effort is reduced, but system adaptability to host changes deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidresponse to host state changes
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring host state changes and automatically responding to them. When events occur on hosts (such as service installations, configuration changes, or security incidents), the HIPS system receives feedback about these changes and automatically adjusts the filter configuration, maintaining both processing efficiency and adaptability without manual intervention

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The HIPS system performs self-service by automatically managing its own filter provisioning based on monitored host conditions. The system autonomously evaluates host state changes, determines which filters should be added or removed, and executes the configuration changes without requiring manual administrator input, thereby maintaining both efficiency and adaptability

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8230508B2Host intrusion prevention server
Publication Date: 2012.07.24 TREND MICRO INC
  • US8230508B2 patent drawing
  • US8230508B2 patent drawing
  • US8230508B2 patent drawing

AI summary

An intrusion-prevention server supporting a set of hosts comprises data filters and an engine which uses a set of encoded rules for assigning data filters to hosts according to metadata characterizing the hosts. Each data filter corresponds to at least one intrusion pattern from among a set of intrusion patterns and the data filters are continuously updated as intrusion patterns change. Metadata acquired from a host varies with a changing state of the host. Acquisition of metadata from each host is streamlined to reduce communications between the server and the hosts and to minimize processing effort for both the server and the hosts.