Intent-Based Intrusion Detection Scripts for SDDC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems (IDSs) are not intuitive, making it difficult for administrators to define fine-grained policies, as they require sifting through thousands of signatures, thus failing to capture the administrator's intent effectively, especially in preventing specific threats like all logins from a group after hours.

Innovation Solution

An intent-based intrusion detection and prevention system that uses contextual attributes to convert defined intent into intrusion detection scripts, which are then enforced on host computers, allowing for intuitive definition of policies through an API command and user interface, enabling detection and prevention of both anomalous user behavior and data message traffic anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators use traditional signature-based IDS with thousands of signatures, then detection coverage is improved, but system complexity and ease of operation deteriorate

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer (the system described in the patent) that sits between the administrator and the thousands of IDS signatures. This intermediary automatically translates high-level intent statements into specific signature configurations, eliminating the need for administrators to directly manage complex signature sets while maintaining comprehensive detection coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing administrators to define intrusion detection policies through simple intent statements rather than manually configuring individual signatures. The system automatically performs the complex task of mapping intents to appropriate signatures and configurations, making the process self-serve and eliminating manual complexity

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If administrators manually configure individual intrusion detection signatures, then fine-grained control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvefine-grained controlVSAvoidease of operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent uses copying by creating reusable intent templates that can be defined once and automatically applied to multiple similar scenarios. Instead of manually configuring each individual signature, administrators create high-level intent copies that replicate across different contexts, maintaining fine-grained control while dramatically simplifying operation

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system implements universality by designing intent statements that can serve multiple functions simultaneously - a single intent definition can cover multiple signatures, multiple workloads, and various detection scenarios. This multi-functional approach allows administrators to maintain precise control over detection policies while operating at a high level

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If the system processes thousands of intrusion detection signatures, then detection accuracy is improved, but processing time and productivity deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies segmentation by dividing the large set of thousands of IDS signatures into smaller, manageable groups based on workload types, application categories, and threat scenarios. This segmentation allows the system to process only relevant signature subsets for each specific workload, maintaining high detection accuracy while significantly reducing processing time and improving overall productivity

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12095780B2Method and system for enforcing intrusion detection signatures curated for workloads based on contextual attributes in an SDDC
Publication Date: 2024.09.17 VMWARE INC
  • US12095780B2 patent drawing
  • US12095780B2 patent drawing
  • US12095780B2 patent drawing

AI summary

Some embodiments of the invention provide a method of implementing an intent-based intrusion detection and prevention system in a datacenter, the datacenter including at least one host computer executing multiple machines. The method receives a filtered set of intrusion detection signatures to be enforced on the at least one host computer. The method uses a set of contextual attributes associated with a particular data message to generate an intrusion detection signature for the particular data message, the generated intrusion detection signature including a bit pattern, each bit associated with a contextual attribute in the set. The method compares the generated intrusion detection signature with the received set of intrusion detection signatures to identify a matching intrusion detection signature in the received filtered set.