IP Library Patent Application 17374617
Patent Application
App. No. 17/374,617

METHOD AND SYSTEM FOR USING USER-DEFINED INTENT TO IMPLEMENT AN INTENT-BASED INTRUSION DETECTION AND PREVENTION SYSTEM IN AN SDDC

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/374,617
Abstract

Some embodiments of the invention provide a method of implementing an intent-based intrusion detection and prevention system in a datacenter that includes a set of host computers that each execute multiple machines. The method receives, from the set of host computers, multiple contextual attributes that define one or more compute environments. Through a user interface, the method presents the multiple contextual attributes and a set of controls for use in generating intent-based API commands. The method receives, through the user interface, an intent-based API command that defines intent for a set of one or more intrusion detection rules to be enforced in the datacenter, the intent defined in terms of one or more of the multiple contextual attributes. The method processes the intent-based API command in order to distribute intrusion detection system configuration data to configure, for each host computer in the set of host computers, an intrusion detection system operating on the host computer.

Claims (32)

1 . A method of implementing an intent-based intrusion detection and prevention system in a datacenter, the datacenter comprising a set of host computers, each host computer executing a plurality of machines, the method comprising:

receiving, from the set of host computers, a plurality of contextual attributes that define one or more compute environments;

through a user interface, presenting (i) the plurality of contextual attributes, and (ii) a set of controls for use in generating intent-based API (application programming interface) commands;

receiving, through the user interface, an intent-based API command that defines intent for a set of one or more intrusion detection rules to be enforced in the datacenter, the intent defined in terms of one or more of the plurality of contextual attributes; and

processing the intent-based API command in order to distribute intrusion detection system configuration data to configure, for each host computer in the set of host computers, an intrusion detection system operating on the host computer.

2 . The method of claim 1 , wherein the intrusion detection system configuration data comprises intrusion detection scripts for detecting and preventing threats on host computers, wherein processing the intent-based API command comprises converting the intent-based API command into one or more intrusion detection scripts for enforcement on one or more host computers in the set of host computers in the datacenter.

3 . The method of claim 2 , wherein converting the intent-based API command into one or more intrusion detection scripts comprises using the plurality of contextual attributes to convert the defined intent into the one or more intrusion detection scripts.

4 . The method of claim 3 , wherein the defined intent specifies one or more contextual attributes from the plurality of contextual attributes as criteria for intrusion detection, wherein using the plurality of contextual attributes to convert the defined intent into the set of one or more intrusion detection scripts comprises using a subset of the plurality of contextual attributes to convert at least one contextual attribute specified by the defined intent into a context value identified from the subset of contextual attributes and associated with the at least one contextual attribute.

5 . The method of claim 1 , wherein processing the intent-based API command comprises converting the intent-based API command into a set of one or more intrusion detection rules for enforcement on one or more host computers in the set of host computers in the datacenter.

6 . The method of claim 1 , wherein processing the intent-based API command comprises converting the intent-based API command into one or more intrusion detection signatures for enforcement on one or more host computers in the set of host computers in the datacenter.

7 . The method of claim 1 , wherein the intent-based API command is a hierarchical API command comprising a set of API commands.

8 . The method of claim 1 , wherein the intent-based API command is a simple declaratory statement of intent for intrusion detection.

9 . The method of claim 1 , wherein a subset of the set of controls comprises a set of components to use to generate expressions for defining intent for the intent-based API command, each component in the set of components (i) is for populating using one or more contextual attributes from the provided plurality of contextual attributes presented through the user interface, and (ii) is associated with an intrusion detection script.

10 . The method of claim 9 , wherein the received intent-based API command comprises at least one expression defining intent, wherein processing the received intent-based API command comprises mapping each component used to generate the at least one expression to an associated intrusion detection script in order to convert the received intent-based API command into a set of one or more intrusion detection scripts to be enforced by one or more intrusion detection systems on one or more host computers in the set of host computers.

11 . The method of claim 1 , wherein the received intent-based API command defines intent for modifying at least one existing intrusion detection script.

12 . The method of claim 1 , wherein the presented set of controls comprise a subset of controls for selecting (i) a set of workloads identified based on the plurality of contextual attributes, and (ii) a set of intrusion detection signatures to apply to the selected set of workloads.

13 . The method of claim 1 , wherein the method is performed by a set of one or more servers.

14 . The method of claim 1 , wherein the intent-based API command is a hierarchical API command comprising a set of API commands.

15 . The method of claim 1 , wherein the plurality of contextual attributes comprises pre-defined contextual attributes.

16 . The method of claim 1 , wherein the plurality of contextual attributes is received from the at least one host computer and comprise contextual attributes that are not layer 2 through layer 4 attributes and that define a compute environment.

17 . The method of claim 1 , wherein the set of one or more intrusion detection scripts comprise rules for detecting (i) anomalous user behavior and (ii) anomalous data message traffic behavior.

18 . The method of claim 1 , wherein at least one intrusion detection script in the set of one or more intrusion detection scripts specifies a preventative action for preventing detected intrusion attempts.

19 . A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for implementing an intent-based intrusion detection and prevention system in a datacenter, the datacenter comprising a set of host computers, each host computer executing a plurality of machines, the method comprising:

receiving, from the set of host computers, a plurality of contextual attributes that define one or more compute environments;

through a user interface, presenting (i) the plurality of contextual attributes, and (ii) a set of controls for use in generating intent-based API (application programming interface) commands;

receiving, through the user interface, an intent-based API command that defines intent for a set of one or more intrusion detection rules to be enforced in the datacenter, the intent defined in terms of one or more of the plurality of contextual attributes; and

processing the intent-based API command in order to distribute intrusion detection system configuration data to configure, for each host computer in the set of host computers, an intrusion detection system operating on the host computer.

20 . The non-transitory machine readable medium of claim 19 , wherein the intrusion detection system configuration data comprises intrusion detection scripts for detecting and preventing threats on host computers, wherein the set of instructions for processing the intent-based API command comprises a set of instructions for converting the intent-based API command into one or more intrusion detection scripts for enforcement on one or more host computers in the set of host computers in the datacenter.

21 . The non-transitory machine readable medium of claim 20 , wherein:

the set of instructions for converting the intent-based API command into one or more intrusion detection scripts comprises a set of instructions for using the plurality of contextual attributes to convert the defined intent into the one or more intrusion detection scripts;

the defined intent specifies one or more contextual attributes from the plurality of contextual attributes as criteria for intrusion detection; and

the set of instructions for using the plurality of contextual attributes to convert the defined intent into the set of one or more intrusion detection scripts comprises a set of instructions for using a subset of the plurality of contextual attributes to convert at least one contextual attribute specified by the defined intent into a context value identified from the subset of contextual attributes and associated with the at least one contextual attribute.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2021
From: MYNENI, SIRISHA; MANDLIWALA, NAFISA; MANUGURI, SUBRAHMANYAM
To: VMWARE, INC.
Reel/Frame 058187/0638 →