Agent-Less Enterprise Threat Analysis System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in effectively protecting enterprise computer systems from malicious threats, identifying sensitive data, and monitoring vulnerabilities across diverse operating systems.

Innovation Solution

A remote threat analysis system that deploys a threat analysis software tool across enterprise computing systems, collecting and analyzing system information for potential threats, sensitive data, and vulnerabilities, while being operable on multiple operating systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security tools are deployed across enterprise computing systems, then threat detection capability is improved, but system performance and resource consumption worsen

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security analysis functionality is segmented into a centralized cloud-based platform rather than being distributed across all enterprise computing systems. Local agents only perform minimal data collection and transmission, while heavy analysis operations are performed remotely, reducing local resource consumption while maintaining comprehensive threat detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized security platform acts as an intermediary between enterprise computing systems and threat analysis resources. The platform receives data from multiple systems, performs centralized analysis using sophisticated algorithms and threat intelligence, then returns results to individual systems, enabling advanced threat detection without burdening individual system resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security monitoring is implemented across all enterprise systems, then vulnerability identification is improved, but operational complexity and false positives worsen

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements feedback loops where analysis results, threat intelligence, and system responses are continuously fed back into the security platform. This enables the system to learn from previous analyses, refine detection algorithms, reduce false positives over time, and adapt to emerging threats, thereby improving vulnerability identification accuracy while managing complexity through automated learning.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security platform performs self-diagnosis and self-configuration by automatically analyzing collected data, identifying vulnerabilities, and adjusting monitoring parameters without requiring manual intervention for each system. This self-service capability reduces operational complexity while maintaining high detection precision through automated analysis.

Inventive Principle:
Principle #25Self-service

3Reliability

If security analysis tools are deployed on each computing system, then local threat detection is improved, but enterprise-wide coordination and data sharing worsen

Engineering Contradiction:
Improvelocal threat detectionVSAvoidenterprise-wide coordination
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system merges local threat detection capabilities with enterprise-wide coordination by combining distributed data collection agents with a centralized analysis platform. Local agents maintain proximity to system data for immediate detection, while the centralized platform aggregates data from across the enterprise, enabling both local responsiveness and enterprise-wide coordination through unified analysis.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The architecture transitions from a single-dimension local analysis model to a multi-dimensional approach by adding the centralized cloud platform dimension. This enables simultaneous local threat detection at the system level and enterprise-wide pattern recognition at the platform level, coordinating security efforts across multiple dimensions of the enterprise infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12244632B2Systems and methods for identifying and mapping sensitive data on an enterprise
Publication Date: 2025.03.04 KIVU CONSULTING INC
  • US12244632B2 patent drawing
  • US12244632B2 patent drawing
  • US12244632B2 patent drawing

AI summary

Embodiments of the present invention provide techniques, systems, and methods for remote, agent-less enterprise computer threat data collection, malicious threat analysis, and identification and reporting of potential and real threats present on an enterprise computer system. Specifically, embodiments are directed to a system that securely identifies and maps sensitive information from computers across the enterprise. Secure and sensitive information may be internally encrypted and analyzed for indicators of compromise, threatening behavior, and known vulnerabilities. The remote, agent-less collection, analysis, and identification process can be repeated periodically to detect and map additional sensitive information over time, and may delete itself after completion to avoid detection.