Automatic Node Hardening for System Security Stability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administrators often delay software updates to avoid unintended consequences, leaving computers vulnerable to attacks, especially in large installations where compromising one node can affect the entire system, and existing protective measures may not adequately maintain system functionality.

Innovation Solution

Implementing an automatic hardening process for uncompromised nodes in a multi-node system by using a security manager to monitor for threats, isolate compromised nodes, apply updates, and transfer functionality to hardened nodes, thereby maintaining system stability and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software updates are installed to address security vulnerabilities, then system security is improved, but system stability may deteriorate due to potential update failures

Engineering Contradiction:
Improvesystem securityVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system performs preliminary actions by automatically installing security updates on uncompromised nodes upon detection of a compromise event. The security manager proactively hardens vulnerable nodes before they can be attacked, rather than waiting for update schedules or manual intervention. This preliminary security reinforcement resolves the contradiction by ensuring updates are applied when most needed (improving security) while maintaining stability through automated testing and gradual deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through automated update management where the security manager independently identifies vulnerabilities, selects appropriate updates, and deploys them to uncompromised nodes without human intervention. This self-service mechanism resolves the contradiction by eliminating the manual decision-making process that prioritizes stability over security, while automated testing ensures stability is maintained through controlled update deployment.

Inventive Principle:
Principle #25Self-service

2Reliability

If a compromised node is isolated to protect other nodes, then system security is improved, but system functionality deteriorates due to loss of operational capacity

Engineering Contradiction:
Improvesystem securityVSAvoidsystem functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts only the compromised node from the operational network while maintaining the functionality of uncompromised nodes. The security manager identifies and isolates specifically the infected node rather than taking down the entire system, thereby protecting security by removing the threat source while preserving overall system functionality through the remaining healthy nodes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates hardened copies of secure node configurations and applies them to uncompromised nodes. The security manager generates updated security configurations from clean nodes and propagates these hardened versions to other nodes, ensuring security improvements are distributed without requiring isolation of functional nodes. This copying mechanism maintains productivity while enhancing security.

Inventive Principle:
Principle #26Copying

3Stability of the object's composition

If manual monitoring and update management is performed, then system stability is maintained through controlled changes, but security response time deteriorates due to delayed update installation

Engineering Contradiction:
Improvesystem stabilityVSAvoidsecurity response time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The system implements feedback mechanisms where the security manager continuously monitors node status, detects compromise events in real-time, and automatically triggers update deployment to uncompromised nodes. This closed-loop feedback system resolves the contradiction by providing immediate security response when compromises are detected, eliminating the delayed response associated with manual monitoring while maintaining stability through automated controlled deployment.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces manual mechanical update management processes with automated electronic security management. The security manager automatically performs vulnerability assessment, update selection, and deployment without human intervention, substituting the slow manual process with rapid automated systems. This substitution resolves the contradiction by dramatically reducing security response time while maintaining stability through programmed controlled update application.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8910289B1Automatic hardening of an uncompromised computer node
Publication Date: 2014.12.09 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8910289B1 patent drawing
  • US8910289B1 patent drawing

AI summary

A computer system and method responds to a compromise of a first computer node by automatically hardening one or more uncompromised nodes of the system.