Aggregation Agent for Network Security Alert Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and number of agent-based security solutions in networked devices lead to duplicate information crowding network bandwidth, potential vulnerabilities due to multiple open ports, and complex security management, with no assurance of alert authenticity.

Innovation Solution

An aggregation agent is deployed on the host system to authenticate and correlate alert data from multiple agents, compressing and encrypting messages to reduce bandwidth usage and secure communication, while ensuring message authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple agents are deployed to monitor security conditions, then security coverage and detection capability are improved, but network bandwidth is crowded by duplicate information and device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple security agents are merged into a single aggregated security information message that consolidates alerts from antivirus, firewall, intrusion detection, and other security components. This merging reduces the number of separate communications while maintaining comprehensive security coverage, directly resolving the contradiction between improved security detection and reduced system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The aggregated security message serves multiple functions simultaneously: it provides comprehensive security monitoring across multiple agents, reduces network bandwidth consumption, simplifies message routing, and enables centralized management. This multi-functionality allows a single message structure to achieve what previously required multiple separate communication channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If each agent transmits alerts independently, then real-time security monitoring is improved, but network bandwidth is consumed by duplicate information

Engineering Contradiction:
Improvealert transmission speedVSAvoidnetwork bandwidth
Core Design Contradiction:
SpeedVSLoss of energy

Solution Approach 1:

Security alerts from multiple agents are combined into a single aggregated message that maintains real-time transmission capabilities. The aggregation process consolidates duplicate information while preserving the speed advantage of immediate alert delivery, resolving the contradiction between fast alert transmission and network bandwidth conservation.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple ports are opened for agent communications, then agent connectivity and reporting capability are improved, but system vulnerability increases

Engineering Contradiction:
Improveagent connectivityVSAvoidsystem vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Multiple communication ports used by individual agents are merged into a single aggregated security message channel. This consolidation maintains the ability of all security agents to report to the management server while reducing the number of open ports from many individual agent ports to a single aggregated communication interface, thereby maintaining connectivity while reducing vulnerability.

Inventive Principle:
Principle #5Merging (Combining)

4Ease of operation

If security alerts are transmitted without authentication, then transmission simplicity is improved, but alert authenticity cannot be ensured

Engineering Contradiction:
Improvetransmission simplicityVSAvoidalert authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

An authentication mechanism is introduced as an intermediary component within the aggregated security message framework. This intermediary validates the authenticity of alerts during the aggregation process without complicating the overall transmission simplicity, resolving the contradiction between easy transmission and reliable authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7631354B2System security agent authentication and alert distribution
Publication Date: 2009.12.08 TAASERA LICENSING LLC
  • US7631354B2 patent drawing
  • US7631354B2 patent drawing
  • US7631354B2 patent drawing

AI summary

An aggregation agent may combine and correlate information generated by multiple on-host agents and/or information generated in response to multiple security events. The aggregation agent may transmit the combined information to a security console. The security console may check the identity of the aggregation agent to determine whether to accept the information. The security console may map information to one or more consoles.