Adaptive Security Workload Distribution for Network Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer network security methods often implement a uniform security policy across all user devices without considering their individual performance capabilities, leading to potentially less secure configurations.
Innovation Solution
The implementation of adaptive security workloads, where user devices transmit their resource status to a server, which adjusts the workload distribution between the device and a cloud service to optimize security tasks based on available resources, allowing devices with sufficient resources to perform more extensive security analyses while delegating less resource-intensive tasks to the cloud service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a uniform security policy is implemented across all user devices, then security management is simplified, but security effectiveness deteriorates because devices with different performance capabilities cannot execute appropriately optimized security tasks
Solution Approach 1:
The patent implements dynamic workload distribution that adjusts security task allocation based on real-time device resource status. The system transitions from a static uniform security policy to a dynamic adaptive policy where devices with sufficient resources execute more comprehensive security analyses while resource-constrained devices receive simplified security tasks, resolving the contradiction between policy simplicity and security effectiveness
Solution Approach 2:
The patent applies local quality by customizing security workload characteristics to match individual device capabilities. Each device receives a tailored security policy configuration based on its specific resource status (CPU, memory, battery), allowing high-performance devices to execute intensive security scans while low-performance devices execute lighter security tasks, thereby improving overall security effectiveness without excessive complexity
2Reliability
If comprehensive security analyses are performed on all devices, then security effectiveness is improved, but device performance deteriorates due to resource constraints on less capable devices
Solution Approach 1:
The patent changes the parameter of security workload intensity based on device resource status. The system monitors device parameters (CPU availability, memory capacity, battery level) and dynamically adjusts the security task parameters accordingly. Devices with high resource availability receive comprehensive security analysis workloads, while resource-constrained devices receive reduced workloads, optimizing the balance between security effectiveness and device performance
Solution Approach 2:
The patent implements partial action by having devices perform only the portion of security analysis work that their resources can handle. Rather than requiring all devices to perform complete security scans, the system allows resource-constrained devices to perform partial security checks while more capable devices perform comprehensive analyses, achieving acceptable security coverage without overwhelming any single device
3Productivity
If security workloads are distributed based on device resources, then device performance is optimized, but system complexity increases due to the need for resource monitoring and dynamic adjustment
Solution Approach 1:
The patent implements self-service by having devices automatically report their own resource status to the server without requiring complex external monitoring infrastructure. Each device autonomously assesses its own CPU, memory, and battery status and communicates this information to the workload distribution server, which then autonomously determines appropriate task allocation. This self-reporting mechanism reduces system complexity compared to centralized monitoring approaches
Data Source
AI summary
Methods, systems, and media for protecting computer networks using adaptive workloads are provided. In some embodiments, the method comprises: transmitting, to a first server, an indication of a status of resources available to a user device; receiving a workload distribution that indicates an amount of work to be performed by the user device, wherein the amount of work is determined based on the status of resources; determining that a site is to be accessed by the user device; generating an analysis that includes one or more values indicating the safety of the site; transmitting the analysis to a second server at which a remaining amount of work is to be performed; based on the remaining amount of work, determining that the site is to be blocked from being accessed by the user device; and blocking the site from being accessed by the user device.


