Unified Intrusion Detection System for End-to-End Attack Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems (IDSs) are inadequate in detecting sophisticated end-to-end targeted attacks that span beyond business and IT boundaries, as they are designed to detect intrusions within isolated zones and lack the capability to analyze events from multiple boundary sources simultaneously.

Innovation Solution

The implementation of an application-level intrusion detection system (appIDS) using an attack pattern framework (APF) that analyzes logs from various IT boundaries, providing a reference attack pattern execution engine and a specification language for managing attack patterns, enabling detection of end-to-end intrusions by comparing log data to predefined attack patterns and generating alerts based on configuration data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple isolated IDSs are deployed in different IT boundaries, then each IDS can detect intrusions within its own zone, but the system cannot detect end-to-end targeted attacks that span multiple boundaries

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple isolated IDSs into a unified end-to-end intrusion detection system that aggregates logs and events from multiple IT boundaries (network, host, application levels) to detect complex targeted attacks that span across boundaries, while maintaining modular architecture for manageable complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified IDS is designed to perform multiple detection functions across different IT boundaries simultaneously, analyzing logs from network devices, host systems, and application layers with a single system that can detect both simple and complex attack patterns

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a unified end-to-end IDS is implemented to detect attacks across multiple boundaries, then detection of complex intrusions is enabled, but system complexity and integration challenges increase

Engineering Contradiction:
Improveend-to-end detection capabilityVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the end-to-end detection capability into modular components that can independently analyze logs from different IT boundaries (network level, host level, application level) while maintaining coordinated detection across all boundaries through a unified framework

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer that aggregates and correlates logs and events from multiple sources, translating diverse data formats into a unified analysis framework that simplifies integration while enabling comprehensive end-to-end detection

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10140447B2Attack pattern framework for monitoring enterprise information systems
Publication Date: 2018.11.27 SAP SE
  • US10140447B2 patent drawing
  • US10140447B2 patent drawing
  • US10140447B2 patent drawing

AI summary

Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for receiving parameters defining a detection technique, an attack scenario, and detection logic, receiving configuration data that is specific to a target system that is to be monitored, providing an attack pattern based on the parameters and the configuration data, monitoring the target system based on the attack pattern and data provided by one or more logs of the target system, and selectively generating, based on monitoring, an alert indicating a potential end-to-end intrusion into the target system.