Centralized Security System for Networked Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing decentralized security measures for networked devices are inadequate in monitoring and mitigating security risks, as they lack a centralized approach to identify and counter threats effectively.

Innovation Solution

A centralized system that monitors networked devices for security risks, initiates actions to alleviate risks exceeding a specified tolerance, and consolidates data from similar devices to enhance risk identification and mitigation, including remediation and quarantine of affected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If decentralized security measures are deployed on each individual device, then device autonomy and local security control are improved, but security risk monitoring effectiveness and threat mitigation capability deteriorate

Engineering Contradiction:
Improvedevice autonomyVSAvoidsecurity risk monitoring effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges decentralized device-level security operations with centralized cloud-based coordination. Devices execute local security functions autonomously while simultaneously reporting to and receiving guidance from a centralized security management system, combining the advantages of both distributed and centralized approaches

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a centralized security management system as an intermediary between individual devices and the broader network. This intermediary consolidates security data from multiple devices, performs centralized analysis, and coordinates responses, thereby enhancing overall security monitoring effectiveness while preserving device autonomy

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If security actions are automatically initiated when risks are detected, then threat response speed is improved, but false positive rates and unnecessary disruptions worsen

Engineering Contradiction:
Improvethreat response speedVSAvoidfalse positive rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary risk assessment and validation steps before automatically executing security actions. The system evaluates detected risks against established criteria, consolidates data from multiple sources, and verifies threat legitimacy before triggering automated responses, thereby reducing false positives while maintaining rapid response capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the outcomes of security actions are monitored and fed back into the risk assessment system. This continuous feedback loop allows the system to learn from past actions, refine its risk evaluation algorithms, and adjust future response thresholds to minimize false positives

Inventive Principle:
Principle #23Feedback

3Measurement precision

If data from multiple networked devices is consolidated for analysis, then security risk identification accuracy is improved, but data privacy concerns and system complexity worsen

Engineering Contradiction:
Improvesecurity risk identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses a centralized security management system as an intermediary that consolidates and analyzes data from multiple devices. This intermediary handles the complexity of data aggregation, processing, and cross-device pattern recognition centrally, allowing individual devices to remain relatively simple while benefiting from enhanced collective intelligence

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security system into distinct functional components: local device-level security agents that collect and report data, a centralized management system that consolidates and analyzes data, and automated response mechanisms. This segmentation distributes complexity appropriately across different system levels

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10460103B2Security for devices connected to a network
Publication Date: 2019.10.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10460103B2 patent drawing
  • US10460103B2 patent drawing
  • US10460103B2 patent drawing

AI summary

According to one embodiment of the present invention, a system provides security for a device and includes at least one processor. The system monitors a plurality of networked devices for a security risk. Each networked device is associated with a corresponding security risk tolerance. In response to a monitored security risk for one or more of the plurality of networked devices exceeding the corresponding risk tolerance, a network service is initiated to perform one or more actions on each of the one or more networked devices to alleviate the associated security risk. Embodiments of the present invention further include a method and computer program product for providing security to a device in substantially the same manner described above.