Agentless Host Computer Security Investigation System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems for investigating computer systems for intrusion, malware, or other threats often require software agents on the host computer, leading to high performance loads, resource consumption, and potential detection by intruders. Additionally, these systems typically rely on contiguous scanning, making them predictable and vulnerable to evasion by malicious actors.
Innovation Solution
An agentless investigation system that uses a computer system with a processor and memory programmed with instructions to establish a connection with a host computer and send investigative modules configured to run independently on the host computer. These modules perform investigative functions without requiring a software agent, minimizing performance and data loads, and can operate non-contiguously to evade detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software agents are installed on host computers to conduct security scans, then security investigation capability is improved, but system performance load and resource consumption increase
Solution Approach 1:
The patent extracts the security investigation functionality from the host system by using a remote investigation system that connects to the host computer without installing software agents. The investigative modules are executed remotely on the host computer's operating system, allowing security scans to be performed without permanently installing software that consumes system resources. This resolves the contradiction by maintaining security investigation capability while eliminating the continuous resource consumption associated with installed agents.
2Reliability
If software agents are installed on host computers to conduct security scans, then security investigation capability is improved, but the system becomes more complex and difficult to maintain
Solution Approach 1:
The patent removes the complexity of managing software agents by extracting the investigation functionality to a remote system. Instead of installing and maintaining software on each host computer, the system uses remote connections to execute investigative modules, eliminating the need for agent installation, updates, and conflict resolution with other system software.
Solution Approach 2:
The remote investigation system serves multiple host computers through a single centralized platform, providing universal security investigation capability. The system can connect to and investigate multiple different host computers without requiring separate software installations, thereby reducing overall system complexity while maintaining comprehensive security coverage.
3Measurement precision
If contiguous scanning is used to investigate host computers, then thoroughness of investigation is improved, but predictability increases making the system vulnerable to evasion
Solution Approach 1:
The patent implements dynamic scanning intervals and timing that are not fixed or predictable. The investigation system can adjust when and how it scans different host computers, making it difficult for malicious actors to predict when investigations will occur. This maintains thorough investigation capability while reducing vulnerability to evasion through unpredictable timing and adaptive scanning schedules.
4Reliability
If software agents are continuously running on host computers, then security monitoring is improved, but resource consumption and potential detection by intruders increase
Solution Approach 1:
The patent extracts the monitoring functionality from continuously running host-based agents to a remote investigation system that connects on-demand. This allows security monitoring capability to be maintained through remote investigative modules that are executed only when needed, rather than continuously running software on host computers that could be detected by intruders.
Data Source
AI summary
A method of investigating a host computer uses an investigation system remote to the host computer. The investigation system includes at least one computer system. The method includes establishing a connection with the remote host computer, and sending at least one investigative module to the host computer. The at least one investigative module is configured to run on the host computer to perform at least one investigative function on the host computer. The at least one investigative module includes an agentless computer program configured to run on the host computer to perform at least one investigative function on the host computer to investigate the host computer to ascertain if the host computer has any data or process (hereinafter collectively referred to as data forms) with suspicious attributes.


