IP Library Granted Patent US 12,489,783
Granted Patent B2
US 12,489,783 · App. 18/355,625 · Granted Dec 2, 2025

Intrusion detection and remediation based on type of intrusion

Inventors: Trupti Ghate (Pune, IN); Piyush Tibrewal (Pune, IN)
Assignee: Dell Products L.P.
H04L63/1441H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,783
App. No.
18/355,625
Granted
Dec 2, 2025
Kind
B2
Abstract

An example methodology includes, by a computing device, preparing remediation materials for use in remediating an intrusion on a resource of a computing system, monitoring the resource for intrusions, and detecting an intrusion on the resource based on the monitoring. The method also includes, responsive to a determination that the intrusion on the resource is an illegitimate intrusion, by the computing device, identifying at least one rule to execute to remediate the intrusion on the resource and running the identified at least one rule to remediate the intrusion on the resource, wherein the at least one rule defines one or more actions to sanitize the resource based on the remediation materials.

Claims (42)

1 . A method comprising:

detecting, by a computing device, installation of a resource of a computing system;

preparing, by the computing device in response to detecting the installation of the resource, remediation materials for use in remediating an intrusion on the resource;

monitoring, by the computing device, the resource for intrusions;

detecting, by the computing device, an intrusion on the resource based on the monitoring;

determining, by the computing device based on a first one or more rules, whether the intrusion is a legitimate intrusion or an illegitimate intrusion; and

responsive to determining that the intrusion on the resource is an illegitimate intrusion, by the computing device:

identifying a second one or more rules to execute to remediate the intrusion on the resource; and

running the identified second one or more rules to remediate the intrusion on the resource, wherein the second one or more rules define one or more actions to sanitize the resource based on the remediation materials.

2 . The method of claim 1 , wherein the remediation materials include an original copy of the resource necessary to sanitize the resource to its original state.

3 . The method of claim 1 , wherein the remediation materials include original copies of components of the resource necessary to sanitize a component of the resource to its original state.

4 . The method of claim 1 , wherein the preparing of the remediation materials is in a controlled environment.

5 . The method of claim 1 , wherein the second one or more rules define one or more actions to sanitize one or more additional resources.

6 . The method of claim 1 , wherein the resource is an operating system (OS)-level component, and wherein the second one or more rules define one or more actions to sanitize all or a subset of OS-level components of the computing system.

7 . The method of claim 1 , wherein the resource is an application-level component, and wherein the second one or more rules define one or more actions to sanitize all or a subset of application-level components of the computing system.

8 . The method of claim 1 , wherein the resource is a storage-level component, and wherein the second one or more rules define one or more actions to sanitize all or a subset of storage-level components of the computing system.

9 . The method of claim 1 , wherein the resource is a network-level component, and wherein the second one or more rules define one or more actions to sanitize all or a subset of network-level components of the computing system.

10 . The method of claim 1 , wherein the resource is a node in a cluster, and wherein the second one or more rules define one or more actions to sanitize all or a subset of nodes in the cluster.

11 . A computing device comprising:

one or more non-transitory machine-readable mediums configured to store instructions; and

one or more processors configured to execute the instructions stored on the one or more non-transitory machine-readable mediums, wherein execution of the instructions causes the one or more processors to carry out a process comprising:

detecting installation of a resource of a computing system;

preparing remediation materials for use in remediating an intrusion on resource in response to detecting the installation of the resource;

monitoring the resource for intrusions;

detecting an intrusion on the resource based on the monitoring;

determining, based on a first one or more rules, whether the intrusion is a legitimate intrusion or an illegitimate intrusion; and

responsive to determining that the intrusion on the resource is an illegitimate intrusion, running a second one or more rules to remediate the intrusion on the resource, wherein the second one or more rules define one or more actions to sanitize the resource based on the remediation materials.

12 . The computing device of claim 11 , wherein the remediation materials include an original copy of the resource necessary to sanitize the resource to its original state.

13 . The computing device of claim 11 , wherein the remediation materials include original copies of components of the resource necessary to sanitize a component of the resource to its original state.

14 . The computing device of claim 11 , wherein the preparing of the remediation materials is in a controlled environment.

15 . The computing device of claim 11 , wherein the second one or more rules define one or more actions to sanitize one or more additional resources.

16 . The computing device of claim 11 , wherein the resource is a configuration file of a service, and wherein the second one or more rules define one or more actions to sanitize the service.

17 . The computing device of claim 11 , wherein the second one or more rules define one or more actions to sanitize all or a subset of components of the computing system that are of a same type as the resource.

18 . A non-transitory machine-readable medium encoding instructions that when executed by one or more processors cause a process to be carried out, the process including:

detecting installation of a resource of a computing system;

preparing remediation materials for use in remediating an intrusion on the resource in response to detecting the installation of the resource;

monitoring the resource for intrusions;

detecting an intrusion on the resource based on the monitoring;

determining, based on a first one or more rules, whether the intrusion is a legitimate intrusion or an illegitimate intrusion; and

responsive to determining that the intrusion on the resource is an illegitimate intrusion, running a second one or more rules to remediate the intrusion on the resource, wherein the second one or more rules define one or more actions to sanitize the resource based on the remediation materials.

19 . The non-transitory machine-readable medium of claim 18 , wherein the remediation materials include one of an original copy of the resource necessary to sanitize the resource to its original state or original copies of components of the resource necessary to sanitize a component of the resource to its original state.

20 . The non-transitory machine-readable medium of claim 18 , wherein the preparing of the remediation materials is in a controlled environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2023
From: GHATE, TRUPTI; TIBREWAL, PIYUSH
To: DELL PRODUCTS L.P.
Reel/Frame 064325/0740 →
Continuity (1)
Related Publication 20250030728A1 · Jan 23, 2025
References Cited (10)
US 9100431B2 · Oliphant · 2015 [cited by examiner]
US 10609063B1 · Oliphant · 2020 [cited by examiner]
US 20170279844A1 · Bower, III · 2017 [cited by examiner]
US 20180121649A1 · Folco · 2018 [cited by examiner]
US 20180248893A1 · Israel · 2018 [cited by examiner]
US 20190347155A1 · Chevalier · 2019 [cited by examiner]
US 20200162503A1 · Shurtleff · 2020 [cited by examiner]
US 20210026947A1 · Korotaev · 2021 [cited by examiner]
US 20210216408A1 · Huskisson · 2021 [cited by examiner]
US 20220360594A1 · Cosgrove · 2022 [cited by examiner]