On-Device Adaptive Security Using Threat Intelligence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security solutions for client computing devices, such as mobile and wireless devices, are inadequate in protecting against new and emerging threats due to their reliance on periodic software updates and patches, which are often delayed and can introduce new vulnerabilities, leaving devices vulnerable to hackers and malware.
Innovation Solution
A method where client computing devices collaborate with server devices to quickly identify and respond to emerging threats by receiving threat profiles, analyzing device behavior, and implementing customized security measures before permanent solutions are available, using on-device security systems to devise and implement responses based on threat scores and vulnerability assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security solutions rely on periodic software updates and patches, then security maintenance is simplified, but response time to new threats increases and devices remain vulnerable longer
Solution Approach 1:
The system performs preliminary security actions by deploying emergency security responses before permanent patches are available. When a vulnerability is detected, the system immediately implements temporary mitigations (such as disabling vulnerable components or applying workarounds) to protect against exploitation, rather than waiting for the official vendor patch. This preliminary protective action bridges the critical time gap between vulnerability discovery and permanent resolution.
Solution Approach 2:
The system introduces an intermediary layer between the vulnerability and the device's security response. The emergency security response acts as a mediator that translates the raw vulnerability information into actionable protective measures. This intermediary component enables rapid response by pre-processing vulnerability data and generating appropriate countermeasures before the full security update is ready.
2Adaptability or versatility
If client devices implement customized security responses based on threat profiles, then security adaptability improves, but device complexity increases
Solution Approach 1:
The security system is segmented into distinct functional modules: threat intelligence collection, vulnerability assessment, emergency response generation, and security patch management. Each module operates independently and handles a specific aspect of security. This segmentation allows the system to achieve high adaptability through modular customization without overwhelming complexity, as each module can be optimized and managed separately.
Solution Approach 2:
The system changes parameters of existing security components rather than creating entirely new systems. By adjusting parameters such as detection thresholds, response timing, and mitigation strategies based on threat profiles, the system achieves customized security responses. This parameter-based approach maintains simplicity while enabling adaptability, as modifications are made to existing structures rather than building complex new architectures.
3Reliability
If emergency security responses are deployed before patches are available, then threat protection improves, but potential for introducing new vulnerabilities increases
Solution Approach 1:
The system implements feedback mechanisms that continuously monitor the effectiveness of emergency security responses and the device's overall security state. After deploying a temporary mitigation, the system observes whether the vulnerability is successfully closed off and whether the response introduces any unintended consequences. This feedback loop allows the system to adjust or revoke emergency responses if they prove harmful, thereby reducing the risk of introducing new vulnerabilities while maintaining protection.
Solution Approach 2:
The system applies beforehand cushioning by implementing conservative emergency responses that prioritize safety over functionality. When deploying temporary mitigations, the system uses precautionary measures that may limit device functionality but ensure protection against known threats. This cushioning approach creates a safety buffer that prevents over-aggressive responses from introducing new vulnerabilities, while still providing adequate protection during the transition period before permanent patches are applied.
Data Source
AI summary
Methods, and computing devices implementing the methods, that enable client computing devises to work in conjunction with a server device to identify and temporarily defend against non-benign applications (e.g., malware, etc.) and other threats before a more permanent solution or defense (e.g., a patch or software upgrade) becomes available and installed on the client computing device. The server device may be configured to receive reports from the client computing devices, receive threat feeds from third-party servers (e.g., threat intelligence servers, etc.), and use information included in the received threat feed and information included in the received reports to analyze, in the server computing device, a software application that is operating on a client device in multiple passes. The server may generate threat scores (e.g., one for each pass, etc.), and the threat scores to the client computing device for use in devising a customized security response.


