Cloud-Based Shared Security Cache for Endpoint Reputation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The sheer volume of new and existing attacks on computing devices poses a challenge for security services, as unknown software objects often lack reliable reputations, leading to duplicated scanning and wasteful resource use, with existing security architectures relying on local caches that only benefit individual machines without sharing scanning results effectively.

Innovation Solution

A cloud-based shared security cache system where endpoints identify unknown software objects, query a global reputation store, compute local reputations, and share them with a global security cache, allowing for multi-dimensional metadata-based reputation assignment and reduced redundant scanning across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If local caches are used to store security reputations, then individual machines can quickly access reputation information, but scanning results cannot be shared effectively across devices leading to redundant scanning

Engineering Contradiction:
Improvereputation information accessVSAvoidscanning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges local security cache functionality with a cloud-based shared cache system. Local devices maintain their own caches for quick access while simultaneously contributing to and retrieving from a centralized cloud cache. This combination allows reputation information to be accessed quickly at local level while enabling effective sharing across devices to eliminate redundant scanning.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cloud-based shared cache acts as an intermediary between individual local caches and the global security reputation system. It receives reputation data from multiple local devices, processes and stores it centrally, then distributes it back to other devices. This intermediary mechanism enables effective sharing of scanning results across the network while maintaining fast local access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security scanning is performed on all unknown software objects, then security coverage is maximized, but resource consumption increases due to duplicated scanning across multiple devices

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The system implements feedback mechanisms where local security agents continuously report their scanning results to the cloud-based shared cache. This feedback loop allows the system to learn from scanning results across all devices and use this information to make intelligent decisions about future scanning, thereby maintaining comprehensive security coverage while reducing redundant resource consumption.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The cloud-based shared cache serves multiple functions: it stores reputation data, distributes security information, coordinates scanning efforts across devices, and manages the global security database. This multi-functionality allows the system to achieve comprehensive security coverage through a single coordinated system rather than independent duplicate scanning on each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If individual devices perform independent security analysis, then each device maintains autonomous security control, but redundant scanning occurs and resource efficiency decreases

Engineering Contradiction:
Improveautonomous security controlVSAvoidresource efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

Local security agents autonomously perform security analysis on unknown software objects without requiring manual intervention. They automatically query the cloud cache, receive reputation information, and make security decisions independently. This self-service capability maintains autonomous security control while the background cloud-based sharing mechanism eliminates redundant scanning and improves resource efficiency.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11463440B2Cloud-based shared security cache
Publication Date: 2022.10.04 MCAFEE LLC
  • US11463440B2 patent drawing
  • US11463440B2 patent drawing
  • US11463440B2 patent drawing

AI summary

There is disclosed in one example a computing apparatus, including: a processor and a memory; a network interface; and a security agent including instructions encoded within the memory to instruct the processor to: identify an unknown software object; query, via the network interface, a global reputation store for a global reputation for the unknown software object; receive a response from the global reputation store and determine that the unknown software object does not have a reliable global reputation; compute a local reputation for the unknown software object; and share the local reputation for the unknown software object with the global security cache.