Intent-Based Intrusion Detection Scripts for SDDC Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems (IDSs) are not intuitive, making it difficult for administrators to define fine-grained policies, as they require sifting through thousands of signatures, thus failing to capture the administrator's intent effectively, especially in preventing specific threats like all logins from a group after hours.
Innovation Solution
An intent-based intrusion detection and prevention system that uses contextual attributes to convert defined intent into intrusion detection scripts, which are then enforced on host computers, allowing for intuitive definition of policies through an API command and user interface, enabling detection and prevention of both anomalous user behavior and data message traffic anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators use traditional signature-based IDS with thousands of signatures, then detection coverage is improved, but system complexity and ease of operation deteriorate
Solution Approach 1:
The patent introduces an intermediary layer (the system described in the patent) that sits between the administrator and the thousands of IDS signatures. This intermediary automatically translates high-level intent statements into specific signature configurations, eliminating the need for administrators to directly manage complex signature sets while maintaining comprehensive detection coverage
Solution Approach 2:
The system enables self-service by allowing administrators to define intrusion detection policies through simple intent statements rather than manually configuring individual signatures. The system automatically performs the complex task of mapping intents to appropriate signatures and configurations, making the process self-serve and eliminating manual complexity
2Adaptability or versatility
If administrators manually configure individual intrusion detection signatures, then fine-grained control is improved, but ease of operation deteriorates
Solution Approach 1:
The patent uses copying by creating reusable intent templates that can be defined once and automatically applied to multiple similar scenarios. Instead of manually configuring each individual signature, administrators create high-level intent copies that replicate across different contexts, maintaining fine-grained control while dramatically simplifying operation
Solution Approach 2:
The system implements universality by designing intent statements that can serve multiple functions simultaneously - a single intent definition can cover multiple signatures, multiple workloads, and various detection scenarios. This multi-functional approach allows administrators to maintain precise control over detection policies while operating at a high level
3Measurement precision
If the system processes thousands of intrusion detection signatures, then detection accuracy is improved, but processing time and productivity deteriorate
Solution Approach 1:
The patent applies segmentation by dividing the large set of thousands of IDS signatures into smaller, manageable groups based on workload types, application categories, and threat scenarios. This segmentation allows the system to process only relevant signature subsets for each specific workload, maintaining high detection accuracy while significantly reducing processing time and improving overall productivity
Data Source
AI summary
Some embodiments of the invention provide a method of implementing an intent-based intrusion detection and prevention system in a datacenter, the datacenter including at least one host computer executing multiple machines. The method receives a filtered set of intrusion detection signatures to be enforced on the at least one host computer. The method uses a set of contextual attributes associated with a particular data message to generate an intrusion detection signature for the particular data message, the generated intrusion detection signature including a bit pattern, each bit associated with a contextual attribute in the set. The method compares the generated intrusion detection signature with the received set of intrusion detection signatures to identify a matching intrusion detection signature in the received filtered set.


