IP Library Patent Application 17374623
Patent Application
App. No. 17/374,623

METHOD AND SYSTEM FOR IMPLEMENTING INTRUSION DETECTION SIGNATURES CURATED FOR WORKLOADS BASED ON CONTEXTUAL ATTRIBUTES IN AN SDDC

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/374,623
Abstract

Some embodiments of the invention provide a method of implementing an intent-based intrusion detection and prevention system in a datacenter, the datacenter including at least one host computer executing multiple machines. The method forwards multiple contextual attributes to a set of servers that distribute intrusion detection scripts. The method receives a filtered set of intrusion detection signatures for enforcement on the at least one host computer, the filtered set of intrusion detection signatures identified based on the multiple contextual attributes. The method uses the filtered set of intrusion detection signatures to detect at least one potential intrusion associated with a particular data message processed on the at least one host computer.

Claims (37)

1 . A method of implementing an intent-based intrusion detection and prevention system in a datacenter, the datacenter comprising at least one host computer executing a plurality of machines, the method comprising:

forwarding a plurality of contextual attributes to a set of servers that distribute intrusion detection scripts;

receiving a filtered set of intrusion detection signatures for enforcement on the at least one host computer, the filtered set of intrusion detection signatures identified based on the plurality of contextual attributes; and

using the filtered set of intrusion detection signatures to detect at least one potential intrusion associated with a particular data message processed on the at least one host computer.

2 . The method of claim 1 , wherein the set of servers use the forwarded plurality of attributes to perform a filtering operation to identify the filtered set of intrusion detection signatures from a plurality of intrusion detection signatures, the filtering operation comprising comparing contextual attribute patterns identified in the plurality of contextual attributes with contextual attribute patterns specified by a plurality of intrusion detection signatures.

3 . The method of claim 2 , wherein the plurality of intrusion detection signatures comprises (i) a first plurality of intrusion detection signatures collected from the at least one host computer and (ii) a second plurality of intrusion detection signatures collected from third-party sources in the datacenter, the third-party sources comprising sources external to the at least one host computer in the datacenter.

4 . The method of claim 3 , wherein only a first subset of the identified set of intrusion detection signatures comprises intrusion detection signatures identified during the filtering operation, wherein a second subset of the filtered set of intrusion detection signatures comprise intrusion detection signatures selected by a user and specified for workloads performed by the plurality of machines executing on the at least one host computer.

5 . The method of claim 4 , wherein the workloads are identified based on the forwarded plurality of contextual attributes.

6 . The method of claim 1 , wherein using the identified set of intrusion detection signatures to detect at least one threat associated with the particular data message comprises:

using a set of contextual attributes associated with the particular data message to generate an intrusion detection signature for the particular data message; and

comparing the generated intrusion detection signature with the received filtered set of intrusion detection signatures, wherein identifying a match between the generated intrusion detection signature and an intrusion detection signature in the received filtered set of intrusion detection signatures indicates a potential intrusion has been detected.

7 . The method of claim 6 further comprising sending an alert to the set of servers based on the identified match, the alert identifying the detected potential intrusion.

8 . The method of claim 6 , wherein

using the set of contextual attributes associated with the particular data message to generate the intrusion detection signature comprises using the set of contextual attributes associated with the data message to generate a bit pattern, and

comparing the generated intrusion detection signature with the received filtered set of intrusion detection signatures comprises comparing the generated bit pattern with bit patterns of the received filtered set of intrusion detection signatures.

9 . The method of claim 1 , wherein the filtered set of intrusion detection signatures are further for managing resource access and resource usage on the at least one host computer.

10 . The method of claim 1 , wherein the plurality of contextual attributes comprises contextual attributes that are not layer 2 through layer 4 attributes and that define a compute environment.

11 . The method of claim 1 , wherein the identified set of intrusion detection signatures comprise signatures for detecting (i) anomalous user behavior and (ii) anomalous data message traffic behavior.

12 . A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for implementing an intent-based intrusion detection and prevention system in at least one host computer in a datacenter, the at least one host computer executing a plurality of machines, the program comprising sets of instructions for:

forwarding a plurality of contextual attributes to a set of servers that distribute intrusion detection scripts;

receiving a filtered set of intrusion detection signatures for enforcement on the at least one host computer, the filtered set of intrusion detection signatures identified based on the plurality of contextual attributes; and

using the filtered set of intrusion detection signatures to detect at least one potential intrusion associated with a particular data message processed on the at least one host computer.

13 . The non-transitory machine readable medium of claim 12 , wherein the set of servers use the forwarded plurality of attributes to perform a filtering operation to identify the filtered set of intrusion detection signatures from a plurality of intrusion detection signatures, the filtering operation comprising comparing contextual attribute patterns identified in the plurality of contextual attributes with contextual attribute patterns specified by a plurality of intrusion detection signatures.

14 . The non-transitory machine readable medium of claim 13 , wherein the plurality of intrusion detection signatures comprises (i) a first plurality of intrusion detection signatures collected from the at least one host computer and (ii) a second plurality of intrusion detection signatures collected from third-party sources in the datacenter, the third-party sources comprising sources external to the at least one host computer in the datacenter.

15 . The non-transitory machine readable medium of claim 14 , wherein:

only a first subset of the identified set of intrusion detection signatures comprises intrusion detection signatures identified during the filtering operation;

a second subset of the filtered set of intrusion detection signatures comprise intrusion detection signatures selected by a user and specified for workloads (i) performed by the plurality of machines executing on the at least one host computer, and (ii) identified based on the forwarded plurality of contextual attributes.

16 . The non-transitory machine readable medium of claim 12 , wherein the set of instructions for using the identified set of intrusion detection signatures to detect at least one threat associated with the particular data message further comprises sets of instructions for:

using a set of contextual attributes associated with the particular data message to generate an intrusion detection signature for the particular data message;

comparing the generated intrusion detection signature with the received filtered set of intrusion detection signatures, wherein identifying a match between the generated intrusion detection signature and an intrusion detection signature in the received filtered set of intrusion detection signatures indicates a potential intrusion has been detected; and

sending an alert to the set of servers based on the identified match, the alert identifying the detected potential intrusion.

17 . The non-transitory machine readable medium of claim 16 , wherein

the set of instructions for using the set of contextual attributes associated with the particular data message to generate the intrusion detection signature comprises a set of instructions for using the set of contextual attributes associated with the data message to generate a bit pattern, and

the set of instructions for comparing the generated intrusion detection signature with the received filtered set of intrusion detection signatures comprises a set of instructions for comparing the generated bit pattern with bit patterns of the received filtered set of intrusion detection signatures.

18 . The non-transitory machine readable medium of claim 12 , wherein the filtered set of intrusion detection signatures are further for managing resource access and resource usage on the at least one host computer.

19 . The non-transitory machine readable medium of claim 12 , wherein the plurality of contextual attributes comprises contextual attributes that are not layer 2 through layer 4 attributes and that define a compute environment.

20 . The non-transitory machine readable medium of claim 12 , wherein the identified set of intrusion detection signatures comprise signatures for detecting (i) anomalous user behavior and (ii) anomalous data message traffic behavior.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2021
From: MANDLIWALA, NAFISA; MYNENI, SIRISHA; MANUGURI, SUBRAHMANYAM
To: VMWARE, INC.
Reel/Frame 058187/0690 →