Adaptive Security Workload Distribution for Network Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network security methods often implement a uniform security policy across all user devices without considering their individual performance capabilities, leading to potentially less secure configurations.

Innovation Solution

The implementation of adaptive security workloads, where user devices transmit their resource status to a server, which adjusts the workload distribution between the device and a cloud service to optimize security tasks based on available resources, allowing devices with sufficient resources to perform more extensive security analyses while delegating less resource-intensive tasks to the cloud service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a uniform security policy is implemented across all user devices, then security management is simplified, but security effectiveness deteriorates because devices with different performance capabilities cannot execute appropriately optimized security tasks

Engineering Contradiction:
Improvesecurity policy management complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic workload distribution that adjusts security task allocation based on real-time device resource status. The system transitions from a static uniform security policy to a dynamic adaptive policy where devices with sufficient resources execute more comprehensive security analyses while resource-constrained devices receive simplified security tasks, resolving the contradiction between policy simplicity and security effectiveness

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by customizing security workload characteristics to match individual device capabilities. Each device receives a tailored security policy configuration based on its specific resource status (CPU, memory, battery), allowing high-performance devices to execute intensive security scans while low-performance devices execute lighter security tasks, thereby improving overall security effectiveness without excessive complexity

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive security analyses are performed on all devices, then security effectiveness is improved, but device performance deteriorates due to resource constraints on less capable devices

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the parameter of security workload intensity based on device resource status. The system monitors device parameters (CPU availability, memory capacity, battery level) and dynamically adjusts the security task parameters accordingly. Devices with high resource availability receive comprehensive security analysis workloads, while resource-constrained devices receive reduced workloads, optimizing the balance between security effectiveness and device performance

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements partial action by having devices perform only the portion of security analysis work that their resources can handle. Rather than requiring all devices to perform complete security scans, the system allows resource-constrained devices to perform partial security checks while more capable devices perform comprehensive analyses, achieving acceptable security coverage without overwhelming any single device

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If security workloads are distributed based on device resources, then device performance is optimized, but system complexity increases due to the need for resource monitoring and dynamic adjustment

Engineering Contradiction:
Improvedevice performanceVSAvoidworkload distribution system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having devices automatically report their own resource status to the server without requiring complex external monitoring infrastructure. Each device autonomously assesses its own CPU, memory, and battery status and communicates this information to the workload distribution server, which then autonomously determines appropriate task allocation. This self-reporting mechanism reduces system complexity compared to centralized monitoring approaches

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11233828B1Methods, systems, and media for protecting computer networks using adaptive security workloads
Publication Date: 2022.01.25 MCAFEE LLC
  • US11233828B1 patent drawing
  • US11233828B1 patent drawing
  • US11233828B1 patent drawing

AI summary

Methods, systems, and media for protecting computer networks using adaptive workloads are provided. In some embodiments, the method comprises: transmitting, to a first server, an indication of a status of resources available to a user device; receiving a workload distribution that indicates an amount of work to be performed by the user device, wherein the amount of work is determined based on the status of resources; determining that a site is to be accessed by the user device; generating an analysis that includes one or more values indicating the safety of the site; transmitting the analysis to a second server at which a remaining amount of work is to be performed; based on the remaining amount of work, determining that the site is to be blocked from being accessed by the user device; and blocking the site from being accessed by the user device.