Decentralized Security Controllers for Distributed Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized network security systems are vulnerable to distributed attacks due to their reliance on a single point of failure and delayed response times, which can allow attacks to go undetected and compromise endpoint security.
Innovation Solution
A decentralized security system utilizing a distributed set of security controllers that synchronize cumulative threat states across the network to independently detect and respond to attacks without relying on a central site, using conflict-free replicated data types and gossip protocols for state synchronization and attack protection implementation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a centralized security system is used to protect against distributed attacks, then the ability to detect cumulative attack traffic is improved, but the system introduces a single point of failure and delayed response time
Solution Approach 1:
The patent divides the centralized security system into multiple distributed security controllers, each capable of independently monitoring and detecting attacks. This segmentation eliminates the single point of failure while maintaining cumulative attack detection through peer-to-peer communication between controllers.
Solution Approach 2:
The patent combines the detection capabilities of multiple distributed security controllers to achieve cumulative attack traffic analysis. Each controller shares threat intelligence and attack patterns with others, enabling the system to detect distributed attacks that would be invisible to individual controllers alone.
2Measurement precision
If a centralized security system is used to aggregate and analyze cumulative attack traffic, then the detection of distributed attacks is improved, but the response time is significantly delayed
Solution Approach 1:
The patent implements preliminary action by having each security controller locally pre-process and analyze attack traffic before it reaches the endpoint. Controllers maintain local state information about ongoing attacks and can immediately block malicious traffic without waiting for centralized analysis, reducing response time from minutes to seconds.
Solution Approach 2:
The patent implements feedback mechanisms where security controllers continuously share attack detection information and threat intelligence with each other. When one controller detects an attack pattern, it immediately notifies other controllers, enabling coordinated real-time response across the distributed system.
3Ease of operation
If independent security systems are used at each endpoint, then the system complexity is reduced and ease of operation is improved, but the ability to protect against distributed attacks is lost
Solution Approach 1:
The patent introduces security controllers as intermediary components between endpoints and the network. These controllers maintain independent operation for each endpoint while simultaneously serving as mediators that share threat information with other controllers, enabling distributed attack detection without compromising system simplicity.
Solution Approach 2:
The patent implements self-service by enabling each security controller to independently detect and respond to attacks at its protected endpoint using locally maintained state information. Controllers autonomously make blocking decisions without requiring constant centralized coordination, maintaining operational simplicity while providing collective security.
Data Source
AI summary
A decentralized security system and associated methods are implemented by a distributed set of security controllers that independently detect threats and implement attack protections for endpoints based on cumulative threat states that are synchronized across the distributed set of security controllers in a decentralized manner. A particular security controller receives different states associated with different hashed identifiers from the other security controllers, and also receives a request from a client that is directed to a particular endpoint. The particular security controller generates a hashed value from hashing an identifier from the request that identifies the particular endpoint, updates a first state based on the first hashed value matching a hashed identifier that is associated with the first state, and implements a protective action in response to an updated value generated from updating the first state violating a security rule.


