IP Library Patent Application 18536356
Patent Application
App. No. 18/536,356

SECURE VERIFICATION OF DETECTION RULES ON TEST SENSORS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/536,356
Abstract

New intrusion detection system (IDS) rules to be deployed on an IDS that generates alerts based on an applied ruleset are accessed. A trial window that includes incorporating the new IDS rules into a candidate list to enable summarization and filtering of the alerts is started and the applied ruleset that includes existing IDS rules is supplemented with the candidate list that includes the new IDS rules. The applied ruleset is transmitted to a network sensor associated with the IDS upon the supplementation and alerts generated based on network events implicated by both the existing IDS rules and the new IDS rules in the applied ruleset are received from the IDS. Upon completion of the trial window, a set of alerts generated only by the new IDS rules in the applied ruleset are designated as suppressed alerts and a set of new IDS rules is eliminated from the applied ruleset upon determining that the set of new IDS rules generate a subset of alerts that exceed an alert threshold. The update and modified applied ruleset is then transmitted to the network sensor associated with the IDS.

Claims (51)

1 .- 18 . (canceled)

19 . A computer-implemented method, comprising:

executing an intrusion decision system (IDS) that generates intrusion detection alerts based on an applied ruleset of existing IDS rules;

supplementing the applied ruleset with a list of new IDS rules;

receiving a plurality of alerts generated based on the applied ruleset including both the existing IDS rules and the new IDS rules;

designating, as suppressed alerts, a set of new alerts of the plurality of alerts that were generated based on only the new IDS rules in the applied ruleset; and

eliminating, from the applied ruleset, a first rule of the new IDS rules that caused generation of an excessive number of suppressed alerts exceeding a threshold.

20 . The computer-implemented method of claim 19 , wherein

the eliminating of the first rule is performed by a rule control server located remotely from a monitored network.

21 . The computer-implemented method of claim 19 , wherein

the applied ruleset is sent to one or more network sensors deployed in a monitored network.

22 . The computer-implemented method of claim 19 , wherein

the list of new IDS rules is a candidate list used during a trial window, and the eliminating of the first rule is performed after the trial window.

23 . The computer-implemented method of claim 19 , further comprising:

designating a second rule of the new IDS rules as a suppressed rule, wherein alerts generated based on the suppressed rule are filtered by the IDS.

24 . The computer-implemented method of claim 19 , further comprising:

designating a second rule of the new IDS rules as a suppressed rule, wherein alerts generated based on the suppressed rule are summarized by the IDS.

25 . The computer-implemented method of claim 24 , further comprising:

providing a summary of the suppressed rule for review by a user; and

adding or eliminating the suppressed rule to or from the applied ruleset based on user input from the user.

26 . The computer-implemented method of claim 19 , further comprising:

maintaining statistical metadata on each suppressed alert associated with the new IDS rules.

27 . The computer-implemented method of claim 19 , further comprising:

storing a packet sample generated by the IDS for each suppressed alert.

28 . The computer-implemented method of claim 19 , wherein

the threshold is determined based on a configuration version of the applied ruleset of an organization identifier associated with the applied ruleset.

29 . A system comprising:

one or more computer system that implement an intrusion decision system (IDS), configured to:

generate intrusion detection alerts based on an applied ruleset of existing IDS rules;

supplement the applied ruleset with a list of new IDS rules;

receive a plurality of alerts generated based on the applied ruleset including both the existing IDS rules and the new IDS rules;

designate, as suppressed alerts, a set of new alerts of the plurality of alerts that were generated based on only the new IDS rules in the applied ruleset; and

eliminate, from the applied ruleset, a first rule of the new IDS rules that caused generation of an excessive number of suppressed alerts exceeding a threshold.

30 . The system of claim 29 , wherein

the elimination of the first rule is performed by a rule control server located remotely from a monitored network.

31 . The system of claim 29 , wherein

the applied ruleset is sent to one or more network sensors deployed in a monitored network.

32 . The system of claim 29 , wherein

the list of new IDS rules is a candidate list used during a trial window, and the elimination of the first rule is performed after the trial window.

33 . The system of claim 29 , wherein the IDS is configured to:

designate a second rule of the new IDS rules as a suppressed rule; and

filter alerts generated based on the suppressed rule.

34 . The system of claim 29 , wherein the IDS is configured to:

designate a second rule of the new IDS rules as a suppressed rule; and

summarize alerts generated based on the suppressed rule.

35 . The system of claim 34 , wherein the IDS is configured to:

provide a summary of the suppressed rule for review by a user; and

add or eliminate the suppressed rule to or from the applied ruleset based on user input from the user.

36 . The system of claim 29 , wherein the IDS is configured to maintain statistical metadata on each suppressed alert associated with the new IDS rules.

37 . The system of claim 29 , wherein the IDS is configured to store a packet sample generated by the IDS for each suppressed alert.

38 . The system of claim 29 , wherein the threshold is determined based on a configuration version of the applied ruleset of an organization identifier associated with the applied ruleset.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2024
From: LOPES, LUIS; ADDIS, SARAH; HUTCHINGS, MARTIN; MCTEGGART, RALPH; COCHRANE, NIALL
To: RAPID7, INC.
Reel/Frame 068623/0273 →