Host-Based IPS Agent Signature Matching Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network intrusion prevention systems face challenges such as generating false positives, being ineffective in high-speed networks, and inability to prevent attacks without integration with firewall protection systems, particularly with network-based IPS appliances.

Innovation Solution

A hybrid host-based and node-based intrusion prevention system is implemented, where each node in the network includes a memory module and a network stack with a protocol driver, enabling real-time signature rule matching and optimization through text-file input defining network-exploit rules with ENABLED and SEVERITY fields, reducing the number of signatures processed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-based IPS appliances perform signature analysis on all network traffic, then intrusion detection capability is improved, but processing speed and performance deteriorate in high-speed networks

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the network traffic analysis by implementing host-based IPS agents at individual nodes that perform local signature matching, dividing the centralized processing burden into distributed node-level processing. This allows high-speed networks to maintain intrusion detection capability while avoiding the bottleneck of centralized signature analysis.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If intrusion prevention system processes all signature rules, then detection accuracy is improved, but false positives increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by allowing each host-based IPS agent to customize its signature rule processing according to local security policies and risk assessments. Different nodes can enable or disable specific signature rules based on their particular security needs, reducing false positives while maintaining detection accuracy for relevant threats.

Inventive Principle:
Principle #3Local quality

3Device complexity

If intrusion prevention system is implemented without firewall integration, then system complexity is reduced, but prevention effectiveness deteriorates

Engineering Contradiction:
Improvesystem integration complexityVSAvoidprevention effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements multi-functionality by designing the host-based IPS agent to perform both intrusion detection and prevention functions locally at each node. The agent can block malicious traffic, terminate suspicious connections, and enforce security policies directly without requiring constant firewall integration, making the system universally applicable across different network architectures while maintaining prevention effectiveness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If host-based IPS agent performs real-time signature matching, then detection speed is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection speedVSAvoidresource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing signature matching optimization where the host-based IPS agent processes only the portion of traffic relevant to its host, using techniques such as signature rule prioritization, caching of recent matches, and selective application of signature rules based on traffic patterns. This reduces resource consumption while maintaining real-time detection speed for critical threats.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7836503B2Node, method and computer readable medium for optimizing performance of signature rule matching in a network
Publication Date: 2010.11.16 TREND MICRO INC
  • US7836503B2 patent drawing
  • US7836503B2 patent drawing
  • US7836503B2 patent drawing

AI summary

A node of a network for managing an intrusion protection system, the node comprising a memory module for storing data in machine-readable format for retrieval and execution by a central processing unit and an operating system comprising a network stack comprising a protocol driver and a media access control driver and operable to execute an intrusion protection system management application, the management application operable to receive text-file input from an input device, the text-file defining a network-exploit rule and comprising at least one field is provided. A method of distributing command and security updates in a network having an intrusion protection system comprising generating a text-file defining a network-exploit rule and specifying at least one field selected from the group consisting of an ENABLED field value and a SEVERITY level field value during generation of the text-file is provided. A computer-readable medium having stored thereon a set of instructions to be executed, the set of instructions, when executed by a processor, cause the processor to perform a computer method of reading input from an input device of the computer, compiling the input into a machine-readable signature file comprising machine-readable logic representative of the network-exploit rule and a value of at least one field selected from the group consisting of an ENABLED field and a SEVERITY field, evaluating the machine-readable signature file, and determining the value of the at least one field of the machine-readable signature file is provided.