IPS Filter Confidence Scoring for Deployment Mode Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion Prevention/Detection systems (IPS) face challenges in determining the performance of IPS filters before and during deployment, leading to uncertainties in their effectiveness and potential risks, as they are not thoroughly examined in all potential usage scenarios.
Innovation Solution
A method and system that provide quantitative measurements to assess the performance of IPS filters based on confidence attributes, including accuracy, false negatives, false positives, traffic processing, and environmental factors, to determine the likelihood of successful attack prevention without blocking legitimate traffic, and adjust scoring based on organizational experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If an IPS filter is deployed without thorough examination in all potential usage scenarios, then deployment speed is improved, but performance reliability deteriorates
Solution Approach 1:
The patent applies preliminary action by conducting comprehensive testing of IPS filters in multiple usage scenarios before deployment. The system pre-evaluates filter performance across different network conditions, traffic types, and attack vectors to establish confidence scores that predict real-world effectiveness, thereby enabling faster deployment decisions without sacrificing reliability
2Reliability
If an IPS filter is used in protection mode, then attack prevention capability is improved, but false positive rate increases
Solution Approach 1:
The patent applies dynamics by enabling flexible mode configuration where the IPS filter can operate in either detection mode or protection mode based on organizational risk tolerance and traffic characteristics. The system dynamically adjusts the filter's operational behavior to balance between aggressive attack prevention and false alarm reduction, allowing administrators to optimize performance for their specific environment
3Measurement precision
If more confidence attributes are collected and measured, then measurement precision of filter performance is improved, but system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the complex performance measurement process into distinct, manageable confidence attributes (such as false positive rate, false negative rate, throughput impact, and detection accuracy). Each attribute is measured independently through specific test scenarios, and the results are aggregated into an overall confidence score, making the measurement system more organized and easier to implement
Data Source
AI summary
An intrusion prevention/detection system filter (IPS filter) performance evaluation is provided. The performance evaluation is performed at both the security center and at the customer sites to derive a base confidence score and local confidence scores. Existence of new vulnerability is disclosed and its attributes are used in the generation of new IPS filter or updates. The generated IPS filter is first tested to determine its base confidence score from test confidence attributes prior to deploying it to a customer site. A deep security manager and deep security agent, at the customer site, collect local confidence attributes that are used for determining the local confidence score. The local confidence score and the base confidence score are aggregated to form a global confidence score. The local and global confidence scores are then compared to deployment thresholds to determine whether the IPS filter should be deployed in prevention or detection mode or sent back to the security center for improvement.


