Agent-Less Enterprise Threat Analysis System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in effectively protecting enterprise computer systems from malicious threats, identifying sensitive data, and monitoring vulnerabilities across diverse operating systems.
Innovation Solution
A remote threat analysis system that deploys a threat analysis software tool across enterprise computing systems, collecting and analyzing system information for potential threats, sensitive data, and vulnerabilities, while being operable on multiple operating systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security tools are deployed across enterprise computing systems, then threat detection capability is improved, but system performance and resource consumption worsen
Solution Approach 1:
The security analysis functionality is segmented into a centralized cloud-based platform rather than being distributed across all enterprise computing systems. Local agents only perform minimal data collection and transmission, while heavy analysis operations are performed remotely, reducing local resource consumption while maintaining comprehensive threat detection capability.
Solution Approach 2:
A centralized security platform acts as an intermediary between enterprise computing systems and threat analysis resources. The platform receives data from multiple systems, performs centralized analysis using sophisticated algorithms and threat intelligence, then returns results to individual systems, enabling advanced threat detection without burdening individual system resources.
2Measurement precision
If comprehensive security monitoring is implemented across all enterprise systems, then vulnerability identification is improved, but operational complexity and false positives worsen
Solution Approach 1:
The system implements feedback loops where analysis results, threat intelligence, and system responses are continuously fed back into the security platform. This enables the system to learn from previous analyses, refine detection algorithms, reduce false positives over time, and adapt to emerging threats, thereby improving vulnerability identification accuracy while managing complexity through automated learning.
Solution Approach 2:
The security platform performs self-diagnosis and self-configuration by automatically analyzing collected data, identifying vulnerabilities, and adjusting monitoring parameters without requiring manual intervention for each system. This self-service capability reduces operational complexity while maintaining high detection precision through automated analysis.
3Reliability
If security analysis tools are deployed on each computing system, then local threat detection is improved, but enterprise-wide coordination and data sharing worsen
Solution Approach 1:
The system merges local threat detection capabilities with enterprise-wide coordination by combining distributed data collection agents with a centralized analysis platform. Local agents maintain proximity to system data for immediate detection, while the centralized platform aggregates data from across the enterprise, enabling both local responsiveness and enterprise-wide coordination through unified analysis.
Solution Approach 2:
The architecture transitions from a single-dimension local analysis model to a multi-dimensional approach by adding the centralized cloud platform dimension. This enables simultaneous local threat detection at the system level and enterprise-wide pattern recognition at the platform level, coordinating security efforts across multiple dimensions of the enterprise infrastructure.
Data Source
AI summary
Embodiments of the present invention provide techniques, systems, and methods for remote, agent-less enterprise computer threat data collection, malicious threat analysis, and identification and reporting of potential and real threats present on an enterprise computer system. Specifically, embodiments are directed to a system that securely identifies and maps sensitive information from computers across the enterprise. Secure and sensitive information may be internally encrypted and analyzed for indicators of compromise, threatening behavior, and known vulnerabilities. The remote, agent-less collection, analysis, and identification process can be repeated periodically to detect and map additional sensitive information over time, and may delete itself after completion to avoid detection.


