Cloud-Based Shared Security Cache for Endpoint Reputation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The sheer volume of new and existing attacks on computing devices poses a challenge for security services, as unknown software objects often lack reliable reputations, leading to duplicated scanning and wasteful resource use, with existing security architectures relying on local caches that only benefit individual machines without sharing scanning results effectively.
Innovation Solution
A cloud-based shared security cache system where endpoints identify unknown software objects, query a global reputation store, compute local reputations, and share them with a global security cache, allowing for multi-dimensional metadata-based reputation assignment and reduced redundant scanning across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If local caches are used to store security reputations, then individual machines can quickly access reputation information, but scanning results cannot be shared effectively across devices leading to redundant scanning
Solution Approach 1:
The patent merges local security cache functionality with a cloud-based shared cache system. Local devices maintain their own caches for quick access while simultaneously contributing to and retrieving from a centralized cloud cache. This combination allows reputation information to be accessed quickly at local level while enabling effective sharing across devices to eliminate redundant scanning.
Solution Approach 2:
The cloud-based shared cache acts as an intermediary between individual local caches and the global security reputation system. It receives reputation data from multiple local devices, processes and stores it centrally, then distributes it back to other devices. This intermediary mechanism enables effective sharing of scanning results across the network while maintaining fast local access.
2Reliability
If comprehensive security scanning is performed on all unknown software objects, then security coverage is maximized, but resource consumption increases due to duplicated scanning across multiple devices
Solution Approach 1:
The system implements feedback mechanisms where local security agents continuously report their scanning results to the cloud-based shared cache. This feedback loop allows the system to learn from scanning results across all devices and use this information to make intelligent decisions about future scanning, thereby maintaining comprehensive security coverage while reducing redundant resource consumption.
Solution Approach 2:
The cloud-based shared cache serves multiple functions: it stores reputation data, distributes security information, coordinates scanning efforts across devices, and manages the global security database. This multi-functionality allows the system to achieve comprehensive security coverage through a single coordinated system rather than independent duplicate scanning on each device.
3Ease of operation
If individual devices perform independent security analysis, then each device maintains autonomous security control, but redundant scanning occurs and resource efficiency decreases
Solution Approach 1:
Local security agents autonomously perform security analysis on unknown software objects without requiring manual intervention. They automatically query the cloud cache, receive reputation information, and make security decisions independently. This self-service capability maintains autonomous security control while the background cloud-based sharing mechanism eliminates redundant scanning and improves resource efficiency.
Data Source
AI summary
There is disclosed in one example a computing apparatus, including: a processor and a memory; a network interface; and a security agent including instructions encoded within the memory to instruct the processor to: identify an unknown software object; query, via the network interface, a global reputation store for a global reputation for the unknown software object; receive a response from the global reputation store and determine that the unknown software object does not have a reliable global reputation; compute a local reputation for the unknown software object; and share the local reputation for the unknown software object with the global security cache.


