Intrusion Detection System Using Session Switching to Cloned Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

One-size-fits-all security solutions for computer systems are inadequate as they can be easily compromised by attackers, and once access is gained, there are no additional measures to detect or repel internal threats.

Innovation Solution

An intrusion detection and response system that monitors user actions, compares them to specific intrusion parameters, and responds by switching access to a cloned system designed to deceive attackers, allowing monitoring of their actions without risking the original system, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If one-size-fits-all security solutions like firewalls are deployed across multiple computing systems, then deployment simplicity and ease of operation are improved, but security reliability deteriorates as attackers can gain familiarity and defeat these generic solutions

Engineering Contradiction:
Improvedeployment simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements custom-tailored security measures for each computing system based on its specific characteristics, vulnerabilities, and threat profile. Instead of applying uniform firewall rules across all systems, the invention creates system-specific security configurations that address local security needs, making it harder for attackers to use generic exploitation techniques against diverse systems.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security system is divided into multiple components including vulnerability assessment modules, threat detection modules, and response modules that operate independently but coordinate together. This segmentation allows each component to specialize in specific security functions, improving overall reliability while maintaining manageable complexity through modular deployment.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If basic firewall protection is used without additional security measures, then device complexity is reduced and ease of operation is improved, but the ability to detect and repel internal threats after attacker access deteriorates

Engineering Contradiction:
Improvesecurity measure complexityVSAvoidintrusion detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary vulnerability assessments and threat modeling before attackers can exploit weaknesses. Security configurations, intrusion detection rules, and response protocols are pre-established based on system-specific risk analyses, enabling the system to detect and respond to intrusions more effectively without adding significant operational complexity during actual security events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system continuously monitors system activity, compares it against baseline behavior and known threat patterns, and automatically adjusts detection sensitivity and response actions. This feedback mechanism enables the system to detect subtle internal threats that basic firewalls would miss, while maintaining automated operation to avoid increasing operational complexity for security personnel.

Inventive Principle:
Principle #23Feedback

3Ease of manufacture

If generic security configurations are applied to all systems, then ease of manufacture and deployment are improved, but adaptability to specific system complexities and features deteriorates

Engineering Contradiction:
Improvedeployment easeVSAvoidsystem-specific adaptation
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The security system dynamically adjusts security parameters such as detection thresholds, monitoring intensity, and response protocols based on system-specific characteristics like hardware configuration, software stack, data sensitivity, and threat landscape. This parameter customization enables the system to adapt to diverse computing environments while maintaining a unified deployment framework that preserves ease of initial configuration.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The security configuration transitions from static generic rules to dynamic adaptive policies that automatically adjust based on real-time system state, threat intelligence, and observed behavior patterns. This dynamics allows the system to respond appropriately to varying security contexts without requiring manual reconfiguration for each system, balancing adaptability with deployment simplicity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10476895B2Intrusion detection and response system
Publication Date: 2019.11.12 SAP SE
  • US10476895B2 patent drawing
  • US10476895B2 patent drawing
  • US10476895B2 patent drawing

AI summary

Disclosed herein are system, method, and computer program product embodiments for intrusion detection and response. An embodiment operates by receiving one or more events corresponding to one or more user actions performed during a connectivity session to a computer system. The received one or more events are compared to one or more intrusion parameters associated with the computer system. It is determined that the received one or more events correspond to the intrusion event and that the user actions are performed on a first version of the computer system. The connectivity session is switched from the first version of the computer system to a second version of the computer system responsive to the determination of the intrusion event.