IP Library Patent Application 17374611
Patent Application
App. No. 17/374,611

METHOD AND SYSTEM FOR ENFORCING USER-DEFINED CONTEXT-BASED INTRUSION DETECTION RULES IN AN SDDC

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/374,611
Abstract

Some embodiments of the invention provide a method of implementing an intent-based intrusion detection and prevention system in a datacenter that includes at least one host computer executing multiple machines. The method forwards multiple contextual attributes to a set of servers that distribute intrusion detection scripts. The method receives, from the set of servers, a set of one or more intrusion detection scripts to be enforced on the at least one host computer, the set of one or more intrusion detection scripts defined based on the multiple forwarded contextual attributes. The method uses the multiple contextual attributes to identify and resolve at least one intrusion detection script in the set of one or more intrusion detection scripts.

Claims (31)

1 . A method of implementing an intent-based intrusion detection and prevention system in a datacenter, the datacenter comprising at least one host computer executing a plurality of machines, the method comprising:

forwarding a plurality of contextual attributes to a set of servers that distribute intrusion detection scripts;

receiving, from the set of servers, a set of one or more intrusion detection scripts to be enforced on the at least one host computer, the set of one or more intrusion detection scripts defined based on the forwarded plurality of contextual attributes; and

using the plurality of contextual attributes to identify and resolve at least one intrusion detection script in the set of one or more intrusion detection scripts.

2 . The method of claim 1 , wherein the plurality of contextual attributes is collected from at least two sources on the at least one host computer.

3 . The method of claim 2 , wherein

the first source comprises a context engine that executes on the at least one host computer to collect contextual attributes from guest introspection (GI) agents executing on the plurality of machines that execute on the particular host computer and process data messages, and

the second source comprises a deep packet inspection (DPI) engine that executes on the at least one host computer and processes data messages.

4 . The method of claim 3 , wherein the method is performed by an intrusion detection system operating on the at least one host computer to detect and prevent potential intrusion events.

5 . The method of claim 4 further comprising performing, prior to forwarding the plurality of contextual attributes, a correlation operation to correlate contextual attributes received from the context engine with contextual attributes received from the DPI engine.

6 . The method of claim 3 , wherein the plurality of machines comprises virtual machines (VMs) and the GI agents are installed on the VMs.

7 . The method of claim 3 , wherein the plurality of machines comprise containers and the GI agents are modules executing within memory spaces of the containers.

8 . The method of claim 1 , wherein the set of one or more intrusion detection scripts comprises intrusion detection scripts converted by the set of servers from user-defined intent specified in an intent-based application programming interface (API) command.

9 . The method of claim 1 , wherein using the plurality of contextual attributes to identify and resolve at least one intrusion detection script comprises comparing contextual attributes from the plurality of contextual attributes to contextual attributes specified by the at least one intrusion detection script to identify data messages for which the at least one intrusion detection script is applicable.

10 . The method of claim 1 , wherein the plurality of contextual attributes comprises contextual attributes that are not layer 2 through layer 4 attributes and that define a compute environment.

11 . The method of claim 1 , wherein the set of one or more intrusion detection scripts are defined based on any two of (i) attempts to access a particular resource, (ii) type of resource attempting to be accessed, and (iii) time of day of access attempts.

12 . The method of claim 1 , wherein the set of context-based intrusion detection rules are defined based on at least one of user identifier and group identifier.

13 . The method of claim 1 , wherein resolving the at least one intrusion detection script causes an alert to be sent to the set of servers identifying a potential intrusion event.

14 . The method of claim 1 , wherein the at least one intrusion detection script specifies a preventative action to be performed to prevent a detected potential intrusion event.

15 . A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for implementing an intent-based intrusion detection and prevention system on at least one host computer in a datacenter, the at least one host computer executing a plurality of machines, the program comprising sets of instructions for:

forwarding a plurality of contextual attributes to a set of servers that distribute intrusion detection scripts;

receiving, from the set of servers, a set of one or more intrusion detection scripts to be enforced on the at least one host computer, the set of one or more intrusion detection scripts defined based on the forwarded plurality of contextual attributes; and

using the plurality of contextual attributes to identify and resolve at least one intrusion detection script in the set of one or more intrusion detection scripts.

16 . The non-transitory machine readable medium of claim 15 , wherein the set of instructions for using the plurality of contextual attributes to identify and resolve at least one intrusion detection script comprises a set of instructions for comparing contextual attributes from the plurality of contextual attributes to contextual attributes specified by the at least one intrusion detection script to identify data messages for which the at least one intrusion detection script is applicable.

17 . The non-transitory machine readable medium of claim 15 , wherein the plurality of contextual attributes comprises contextual attributes that are not layer 2 through layer 4 attributes and that define a compute environment.

18 . The non-transitory machine readable medium of claim 15 , wherein the set of one or more intrusion detection scripts comprises intrusion detection scripts converted by the set of servers from user-defined intent specified in an intent-based application programming interface (API) command.

19 . The non-transitory machine readable medium of claim 15 , wherein:

the plurality of contextual attributes is collected from at least two sources on the at least one host computer;

the first source comprises a context engine that executes on the at least one host computer to collect contextual attributes from guest introspection (GI) agents executing on the plurality of machines that execute on the particular host computer and process data messages, and

the second source comprises a deep packet inspection (DPI) engine that executes on the at least one host computer and processes data messages.

20 . The non-transitory machine readable medium of claim 15 , wherein the set of one or more intrusion detection scripts are defined based on any two of (i) attempts to access a particular resource, (ii) type of resource attempting to be accessed, and (iii) time of day of access attempts.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2021
From: MYNENI, SIRISHA; MANDLIWALA, NAFISA; MANHAS, ROBIN; RAMASWAMY, SRINIVAS
To: VMWARE, INC.
Reel/Frame 058187/0589 →