IPS Filter Confidence Scoring for Deployment Mode Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion Prevention/Detection systems (IPS) face challenges in determining the performance of IPS filters before and during deployment, leading to uncertainties in their effectiveness and potential risks, as they are not thoroughly examined in all potential usage scenarios.

Innovation Solution

A method and system that provide quantitative measurements to assess the performance of IPS filters based on confidence attributes, including accuracy, false negatives, false positives, traffic processing, and environmental factors, to determine the likelihood of successful attack prevention without blocking legitimate traffic, and adjust scoring based on organizational experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If an IPS filter is deployed without thorough examination in all potential usage scenarios, then deployment speed is improved, but performance reliability deteriorates

Engineering Contradiction:
Improvedeployment speedVSAvoidfilter performance reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by conducting comprehensive testing of IPS filters in multiple usage scenarios before deployment. The system pre-evaluates filter performance across different network conditions, traffic types, and attack vectors to establish confidence scores that predict real-world effectiveness, thereby enabling faster deployment decisions without sacrificing reliability

Inventive Principle:
Principle #10Preliminary action

2Reliability

If an IPS filter is used in protection mode, then attack prevention capability is improved, but false positive rate increases

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies dynamics by enabling flexible mode configuration where the IPS filter can operate in either detection mode or protection mode based on organizational risk tolerance and traffic characteristics. The system dynamically adjusts the filter's operational behavior to balance between aggressive attack prevention and false alarm reduction, allowing administrators to optimize performance for their specific environment

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If more confidence attributes are collected and measured, then measurement precision of filter performance is improved, but system complexity increases

Engineering Contradiction:
Improvefilter performance measurement precisionVSAvoidmeasurement system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the complex performance measurement process into distinct, manageable confidence attributes (such as false positive rate, false negative rate, throughput impact, and detection accuracy). Each attribute is measured independently through specific test scenarios, and the results are aggregated into an overall confidence score, making the measurement system more organized and easier to implement

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8893276B2Methods and system for determining performance of filters in a computer intrusion prevention detection system
Publication Date: 2014.11.18 TREND MICRO INC
  • US8893276B2 patent drawing
  • US8893276B2 patent drawing
  • US8893276B2 patent drawing

AI summary

An intrusion prevention/detection system filter (IPS filter) performance evaluation is provided. The performance evaluation is performed at both the security center and at the customer sites to derive a base confidence score and local confidence scores. Existence of new vulnerability is disclosed and its attributes are used in the generation of new IPS filter or updates. The generated IPS filter is first tested to determine its base confidence score from test confidence attributes prior to deploying it to a customer site. A deep security manager and deep security agent, at the customer site, collect local confidence attributes that are used for determining the local confidence score. The local confidence score and the base confidence score are aggregated to form a global confidence score. The local and global confidence scores are then compared to deployment thresholds to determine whether the IPS filter should be deployed in prevention or detection mode or sent back to the security center for improvement.