-
公开(公告)号:US20230013808A1
公开(公告)日:2023-01-19
申请号:US17374608
申请日:2021-07-13
Applicant: VMware, Inc.
Inventor: Sirisha Myneni , Nafisa Mandliwala , Rajitha Arcot , Subrahmanyam Manuguri
Abstract: Some embodiments of the invention provide a method of implementing an intent-based intrusion detection and prevention system in a datacenter that includes at least one host computer executing multiple machines. The method receives an intent-based application programming interface (API) command that defines intent for a set of one or more context-based intrusion detection rules for detecting and preventing intrusions on the at least one host computer. The method uses multiple contextual attributes to convert the defined intent into a set of one or more intrusion detection scripts for enforcement on the at least one host computer. The method provides the set of one or more intrusion detection scripts to an intrusion detection system operating on the at least one host computer for enforcement.