Virtual Proxy Intrusion Prevention with Dynamic Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion prevention systems lack the ability to provide a smarter, customized response to network intrusions, as they cannot remove malicious content or adapt to new vulnerabilities without significant software or hardware upgrades, and proxy-based methods suffer from poor performance and fault tolerance issues.

Innovation Solution

The method involves using virtual proxies to intercept and analyze application data at the packet level, enhancing the transport layer to enable selective modification and loading/unloading of processing procedures for intrusion detection and prevention, allowing for unified and dynamic processing engines that can handle new vulnerabilities and protocols efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If application proxy is used to terminate TCP sessions and analyze application data for customized intrusion response, then the ability to customize response is improved, but system performance deteriorates

Engineering Contradiction:
Improvecustomized response capabilityVSAvoidsystem performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system segments the intrusion prevention functionality into modular processing procedures that can be independently loaded and executed. Instead of using a heavy application proxy that terminates all TCP sessions, the patent divides the processing into discrete, configurable modules that can be selectively applied to packet streams, reducing overall system overhead while maintaining customized response capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a transport layer intermediary that sits between the network layer and application layer, enabling customized intrusion response without fully terminating application sessions. This intermediary layer can inspect and modify packets selectively, providing the benefits of application-aware prevention while maintaining better performance than full proxy termination by allowing sessions to continue.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional intrusion detection systems use static processing engines with built-in policies, then system stability is improved, but adaptability to new vulnerabilities deteriorates

Engineering Contradiction:
Improvesystem stabilityVSAvoidadaptability to new vulnerabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic processing engine where processing procedures can be loaded, unloaded, and updated at runtime without requiring system restart or software upgrades. This dynamic architecture allows the system to adapt to new vulnerabilities by loading new processing procedures while maintaining the stability of the core system architecture.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The processing procedures are designed as universal, reusable modules that can handle multiple types of intrusion scenarios. These modular procedures can be combined and configured to address different vulnerabilities and attack vectors, making the system both stable (through proven reusable code) and adaptable (through flexible configuration and runtime loading).

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7657937B1Method for customizing processing and response for intrusion prevention
Publication Date: 2010.02.02 VMWARE INC
  • US7657937B1 patent drawing
  • US7657937B1 patent drawing
  • US7657937B1 patent drawing

AI summary

A method for customizing the response for network based intrusion prevention comprising of: 1) virtual proxying the application data to enable custom response 2) enhancing transport layer (TCP/IP) to enable selective processing and selective modification of the stream for intrusion prevention. The invention also discloses a method for customizing the processing for both network or host based intrusion prevention comprising of: 1) loading externally defined processing procedures for the detection and prevention of intrusions 2) combining multiple of these processing procedures to form a unified processing engine that can be used for intrusion detection and prevention 3) unloading processing procedures that are not needed any more 4) loading new processing procedures that improve the intrusion detection and prevention.