MULTI-ENGINE INTRUSION DETECTION SYSTEM
    1.
    发明公开

    公开(公告)号:US20240314141A1

    公开(公告)日:2024-09-19

    申请号:US18204352

    申请日:2023-05-31

    Applicant: VMware, Inc.

    CPC classification number: H04L63/1416 G06F9/45558 G06F2009/45587

    Abstract: Example methods and systems for multi-engine intrusion detection are described. In one example, a computer system may configure a set of multiple intrusion detection system (IDS) engines that include at least a first IDS engine and a second IDS engine. In response to detecting establishment of a first packet flow and a second packet flow, the computer system may assign the first packet flow to the first IDS engine and second packet flow to the second engine based on an assignment policy. This way, first packet flow inspection may be performed using the first IDS engine to determine whether first packet(s) associated with the first packet flow are potentially malicious. Second packet flow inspection may be performed using the second IDS engine to determine whether second packet(s) associated with the second packet flow are potentially malicious.

Patent Agency Ranking