Host Intrusion Prevention Server Dynamic Filter Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Host intrusion prevention systems (HIPS) face challenges in optimally provisioning filters and minimizing processing effort while ensuring appropriate protection, as each filter added increases system load, leading to performance degradation.
Innovation Solution
A dynamic mechanism involving a central server, local servers acting as deep security managers (DSM), and software agents on hosts, which use detection rules and expressions to determine required filters and remove redundant ones based on host configuration and events, optimizing filter provisioning and reducing processing effort.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If filters are added to HIPS to improve protection coverage, then security reliability is improved, but system processing performance deteriorates due to increased system load
Solution Approach 1:
The patent implements dynamic filter management where the HIPS system automatically adds or removes filters based on real-time host state changes. The system monitors host events and dynamically adjusts the filter set to maintain only those filters necessary for current security requirements, preventing static accumulation of unnecessary filters that would degrade performance
Solution Approach 2:
The system changes the operational parameters of the filter set by adding or removing specific filters based on host state transitions. When host state changes occur (such as service starts, stops, or configuration changes), the system evaluates which filters remain relevant and modifies the active filter configuration accordingly, optimizing the balance between security coverage and processing performance
2Reliability
If comprehensive filters are deployed to all hosts to ensure adequate protection, then security coverage is improved, but processing effort increases across the system
Solution Approach 1:
The patent applies local quality by customizing the filter configuration for each individual host based on its specific state and requirements. Rather than deploying a uniform comprehensive filter set to all hosts, the system evaluates each host's services, applications, and security needs, then provisions only the locally necessary filters, reducing overall processing effort while maintaining adequate protection
Solution Approach 2:
The system segments the filter provisioning process by dividing the comprehensive filter set into host-specific subsets. Each host receives a segmented, tailored collection of filters relevant to its specific configuration and risk profile, rather than the complete filter inventory, thereby reducing processing effort across the system while maintaining security coverage where needed
3Productivity
If manual filter provisioning is used to optimize performance, then processing effort is reduced, but system adaptability to host changes deteriorates
Solution Approach 1:
The system implements feedback mechanisms by continuously monitoring host state changes and automatically responding to them. When events occur on hosts (such as service installations, configuration changes, or security incidents), the HIPS system receives feedback about these changes and automatically adjusts the filter configuration, maintaining both processing efficiency and adaptability without manual intervention
Solution Approach 2:
The HIPS system performs self-service by automatically managing its own filter provisioning based on monitored host conditions. The system autonomously evaluates host state changes, determines which filters should be added or removed, and executes the configuration changes without requiring manual administrator input, thereby maintaining both efficiency and adaptability
Data Source
AI summary
An intrusion-prevention server supporting a set of hosts comprises data filters and an engine which uses a set of encoded rules for assigning data filters to hosts according to metadata characterizing the hosts. Each data filter corresponds to at least one intrusion pattern from among a set of intrusion patterns and the data filters are continuously updated as intrusion patterns change. Metadata acquired from a host varies with a changing state of the host. Acquisition of metadata from each host is streamlined to reduce communications between the server and the hosts and to minimize processing effort for both the server and the hosts.


