Intrusion Prevention Authorization Workflow
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion prevention systems lack effective methods for launching automated kill chains with countermeasures in response to specific threats, as system administrators are hesitant due to concerns about collateral damage, such as disrupting essential services.
Innovation Solution
Implementing a system that requires authorization from at least two authorized personnel across established trust channels before enacting countermeasures, allowing for stringent authorization protocols that can be scaled based on the severity of the threat, ensuring that countermeasures are only executed with proper approval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated countermeasures are implemented to respond to detected intrusions, then response speed and threat neutralization capability are improved, but the risk of collateral damage to essential services increases
Solution Approach 1:
The patent introduces authorized personnel as an intermediary between the intrusion detection system and the countermeasure execution system. When an intrusion is detected, the system sends notifications to authorized personnel who then manually approve or deny countermeasure execution. This human intermediary prevents automated systems from causing collateral damage while maintaining the capability for rapid response when approved.
Solution Approach 2:
The system implements a feedback loop where intrusion detection triggers notifications to authorized personnel, whose decisions (approve/deny) feed back into whether countermeasures are executed. This feedback mechanism allows the system to adapt to specific situations and prevent unintended consequences while maintaining security responsiveness.
2Object-affected harmful factors
If manual authorization protocols are implemented before executing countermeasures, then collateral damage is prevented, but response time increases
Solution Approach 1:
The system performs preliminary actions by immediately notifying authorized personnel upon intrusion detection, even before their authorization is received. The notification is sent in advance, and the system is ready to execute countermeasures as soon as approval is granted. This preliminary notification reduces the overall response time compared to waiting for authorization before initiating any process.
Solution Approach 2:
The system provides self-service by automatically managing the notification and authorization workflow without requiring manual intervention to start the process. Once an intrusion is detected, the system autonomously notifies authorized personnel and waits for their decision, reducing the administrative overhead and response time compared to fully manual processes.
3Reliability
If multiple authorization contacts are required for countermeasure approval, then decision accuracy and risk mitigation are improved, but system complexity increases
Solution Approach 1:
The authorization system is segmented into multiple independent authorization contacts, each capable of independently reviewing and approving or denying countermeasure execution. This segmentation distributes the decision-making authority and reduces the complexity of any single authorization point while improving overall reliability through multiple perspectives.
Solution Approach 2:
The system merges multiple authorization decisions into a single coordinated approval process. Rather than requiring separate independent actions, the system combines the authorization checks of multiple contacts into a unified workflow where all required authorizations must be obtained before countermeasure execution, simplifying the overall process while maintaining high decision accuracy.
Data Source
AI summary
System and methods are provided for implementing an intrusion prevention system in which data collected at one or more remote computing assets is analyzed against a plurality of workflow templates. Each template corresponding to a different threat vector and comprises: (i) a trigger definition, (ii) an authorization token, and (iii) an enumerated countermeasure responsive to the corresponding threat vector. When a match between the data collected at the one or more remote computing assets and a trigger definition of a corresponding workflow template is identified, an active threat is deemed to be identified. When this occurs the authorization token of the corresponding workflow template is enacted by obtaining authorization from at least two authorization contacts across established trust channels for the at least two authorization contacts. Responsive to obtaining this authorization, the enumerated countermeasure of the corresponding workflow template is executed.


