VMware, Inc.
REMEDIATING FALSE POSITIVES OF INTRUSION DETECTION SYSTEMS WITH GUEST INTROSPECTION

Last updated:

Abstract:

The disclosure provides an approach for remediating false positives for a network security monitoring component. Embodiments include receiving an alert related to network security for a virtual computing instance (VCI). Embodiments include collecting, in response to receiving the alert, context information from the VCI. Embodiments include providing a notification to a management plane based on the alert and the context information. Embodiments include receiving, from the management plane, in response to the notification, an indication of whether the alert is a false positive. Embodiments include training a model based on the alert, the context information, and the indication to determine whether a given alert is a false positive.

Status:
Application
Type:

Utility

Filling date:

13 Jul 2020

Issue date:

13 Jan 2022