Unified Intrusion Detection System for End-to-End Attack Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion detection systems (IDSs) are inadequate in detecting sophisticated end-to-end targeted attacks that span beyond business and IT boundaries, as they are designed to detect intrusions within isolated zones and lack the capability to analyze events from multiple boundary sources simultaneously.
Innovation Solution
The implementation of an application-level intrusion detection system (appIDS) using an attack pattern framework (APF) that analyzes logs from various IT boundaries, providing a reference attack pattern execution engine and a specification language for managing attack patterns, enabling detection of end-to-end intrusions by comparing log data to predefined attack patterns and generating alerts based on configuration data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple isolated IDSs are deployed in different IT boundaries, then each IDS can detect intrusions within its own zone, but the system cannot detect end-to-end targeted attacks that span multiple boundaries
Solution Approach 1:
The patent combines multiple isolated IDSs into a unified end-to-end intrusion detection system that aggregates logs and events from multiple IT boundaries (network, host, application levels) to detect complex targeted attacks that span across boundaries, while maintaining modular architecture for manageable complexity
Solution Approach 2:
The unified IDS is designed to perform multiple detection functions across different IT boundaries simultaneously, analyzing logs from network devices, host systems, and application layers with a single system that can detect both simple and complex attack patterns
2Reliability
If a unified end-to-end IDS is implemented to detect attacks across multiple boundaries, then detection of complex intrusions is enabled, but system complexity and integration challenges increase
Solution Approach 1:
The system segments the end-to-end detection capability into modular components that can independently analyze logs from different IT boundaries (network level, host level, application level) while maintaining coordinated detection across all boundaries through a unified framework
Solution Approach 2:
The patent introduces an intermediary layer that aggregates and correlates logs and events from multiple sources, translating diverse data formats into a unified analysis framework that simplifies integration while enabling comprehensive end-to-end detection
Data Source
AI summary
Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for receiving parameters defining a detection technique, an attack scenario, and detection logic, receiving configuration data that is specific to a target system that is to be monitored, providing an attack pattern based on the parameters and the configuration data, monitoring the target system based on the attack pattern and data provided by one or more logs of the target system, and selectively generating, based on monitoring, an alert indicating a potential end-to-end intrusion into the target system.


