Decentralized Security Controllers for Distributed Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized network security systems are vulnerable to distributed attacks due to their reliance on a single point of failure and delayed response times, which can allow attacks to go undetected and compromise endpoint security.

Innovation Solution

A decentralized security system utilizing a distributed set of security controllers that synchronize cumulative threat states across the network to independently detect and respond to attacks without relying on a central site, using conflict-free replicated data types and gossip protocols for state synchronization and attack protection implementation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a centralized security system is used to protect against distributed attacks, then the ability to detect cumulative attack traffic is improved, but the system introduces a single point of failure and delayed response time

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem availability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent divides the centralized security system into multiple distributed security controllers, each capable of independently monitoring and detecting attacks. This segmentation eliminates the single point of failure while maintaining cumulative attack detection through peer-to-peer communication between controllers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines the detection capabilities of multiple distributed security controllers to achieve cumulative attack traffic analysis. Each controller shares threat intelligence and attack patterns with others, enabling the system to detect distributed attacks that would be invisible to individual controllers alone.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If a centralized security system is used to aggregate and analyze cumulative attack traffic, then the detection of distributed attacks is improved, but the response time is significantly delayed

Engineering Contradiction:
Improvedistributed attack detectionVSAvoidattack response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having each security controller locally pre-process and analyze attack traffic before it reaches the endpoint. Controllers maintain local state information about ongoing attacks and can immediately block malicious traffic without waiting for centralized analysis, reducing response time from minutes to seconds.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where security controllers continuously share attack detection information and threat intelligence with each other. When one controller detects an attack pattern, it immediately notifies other controllers, enabling coordinated real-time response across the distributed system.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If independent security systems are used at each endpoint, then the system complexity is reduced and ease of operation is improved, but the ability to protect against distributed attacks is lost

Engineering Contradiction:
Improvesystem simplicityVSAvoidvulnerability to distributed attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security controllers as intermediary components between endpoints and the network. These controllers maintain independent operation for each endpoint while simultaneously serving as mediators that share threat information with other controllers, enabling distributed attack detection without compromising system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service by enabling each security controller to independently detect and respond to attacks at its protected endpoint using locally maintained state information. Controllers autonomously make blocking decisions without requiring constant centralized coordination, maintaining operational simplicity while providing collective security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12192249B2Systems and methods for decentralized security against defined and undefined threats
Publication Date: 2025.01.07 IMPART SECURITY INC
  • US12192249B2 patent drawing
  • US12192249B2 patent drawing
  • US12192249B2 patent drawing

AI summary

A decentralized security system and associated methods are implemented by a distributed set of security controllers that independently detect threats and implement attack protections for endpoints based on cumulative threat states that are synchronized across the distributed set of security controllers in a decentralized manner. A particular security controller receives different states associated with different hashed identifiers from the other security controllers, and also receives a request from a client that is directed to a particular endpoint. The particular security controller generates a hashed value from hashing an identifier from the request that identifies the particular endpoint, updates a first state based on the first hashed value matching a hashed identifier that is associated with the first state, and implements a protective action in response to an updated value generated from updating the first state violating a security rule.