Agent Message Bus With Local Event Correlation for Ransomware Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity threats evade modern security tools by delivering or executing malicious code within computing environments, necessitating sophisticated and frequent messaging capabilities to monitor and respond to security breaches.

Innovation Solution

An agent-based messaging bus that selectively transmits messages indicative of system health to a cloud-connected monitoring platform, utilizing a router with a routing policy and an aggregation, correlation, and detection core (AC+DC) to process and route messages efficiently, reducing resource consumption and enabling dynamic responses to security events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all messages are transmitted to the monitoring platform, then complete security monitoring is achieved, but bandwidth consumption and processing costs increase

Engineering Contradiction:
Improvesecurity monitoring completenessVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by implementing different processing strategies for different messages based on their characteristics. The AC+DC component analyzes message attributes and routes high-value messages to the monitoring platform while filtering or aggregating low-value messages locally, optimizing bandwidth usage while maintaining monitoring effectiveness

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts only the essential and high-value messages from the complete message stream for transmission to the monitoring platform. The AC+DC component identifies and extracts critical security events while filtering out redundant information, reducing bandwidth consumption without compromising security monitoring completeness

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of energy

If message filtering and aggregation are implemented, then resource consumption is reduced, but message processing complexity increases

Engineering Contradiction:
Improveprocessing costVSAvoidmessage processing complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent segments the message processing function into distinct components: the router for initial message distribution, the AC+DC for aggregation and correlation, and the monitoring platform for analysis. This segmentation allows each component to specialize in specific processing tasks, reducing overall system complexity while maintaining effective filtering and aggregation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The AC+DC component serves as an intermediary between the router and the monitoring platform. It performs message aggregation, correlation, and filtering operations, simplifying the message stream before transmission and reducing the processing burden on the monitoring platform while managing complexity through a dedicated intermediate layer

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If sophisticated routing policies are implemented, then message routing efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvemessage routing efficiencyVSAvoidrouting policy complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic routing policies that adapt based on message characteristics, system state, and security priorities. The router and AC+DC component adjust routing decisions in real-time based on message attributes and suspiciousness levels, improving routing efficiency while managing complexity through dynamic adaptation rather than static complex rules

Inventive Principle:
Principle #15Dynamics

4Reliability

If all messages are stored and processed, then complete security analysis is achieved, but storage costs and processing time increase

Engineering Contradiction:
Improvesecurity analysis completenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary filtering, aggregation, and correlation of messages at the AC+DC component before transmission to the monitoring platform. This preliminary action reduces the volume of messages requiring comprehensive storage and analysis, decreasing processing time while maintaining the ability to perform complete security analysis on high-value messages

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250384128A1Agent Message Bus
Publication Date: 2025.12.18 HALCYON TECH
  • US20250384128A1 patent drawing
  • US20250384128A1 patent drawing
  • US20250384128A1 patent drawing

AI summary

Applications and processes executing on an endpoint are monitored to identify behavior indicative of malicious activity such as a ransomware attack. Messages generated from this monitoring as well as messages derived from external sources are stored in a queue for routing. A router selects some messages from the queue based on a routing policy and sends them to a cloud-based platform that can initiate various actions based on received messages. The router also sends some messages from the queue to a module that analyzes the messages and reduces their size by aggregating, correlating, and detecting relevant information. The module puts the modified messages back into the queue for further routing by the router according to the policy. Related apparatus, systems, techniques and articles are also described.