Distributed Cloud Security Service Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security schemes in cloud networks often require extensive software installation and maintenance on multiple devices, leading to increased costs and potential security bottlenecks, while also facing challenges in efficiently analyzing and managing client content segments for security risks.
Innovation Solution
A distributed security service architecture that employs light instances and central instances to apply and update security policies, where light instances apply stored policies and send unknown content segments to central instances for analysis, reducing the need for extensive software installation and maintenance on each device and enhancing security by utilizing multiple software programs for risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple instances of anti-virus and anti-malware services are positioned in the cloud, then security coverage is improved, but device complexity and maintenance burden increase
Solution Approach 1:
The patent segments the security service into two distinct components: light instances deployed on user devices and central instances deployed in the cloud. Light instances provide basic security functionality with minimal resource requirements, while central instances handle complex analysis and policy management. This segmentation allows security coverage to be extended to multiple devices without proportionally increasing complexity on each device.
Solution Approach 2:
The light instance acts as an intermediary between the user device and the central security instances. It receives content segments, applies local security policies, and only forwards suspicious or unknown content to central instances for full analysis. This intermediary role reduces the maintenance burden on end devices while maintaining comprehensive security coverage.
2Measurement precision
If full security analysis is performed on every client content segment, then security detection accuracy is improved, but network bandwidth consumption and processing time increase
Solution Approach 1:
The system applies partial security analysis at the light instance level by enforcing security policies on known content segments without performing full analysis. Full security analysis is reserved for suspicious or unknown content segments that are forwarded to central instances. This partial action approach maintains detection accuracy for known threats while reducing network bandwidth consumption.
Solution Approach 2:
Security policies are pre-computed and stored at light instances based on previous full analyses performed by central instances. When the same content segments are encountered again, the pre-computed policies are applied immediately without requiring another full analysis, thereby reducing network bandwidth consumption and processing time while maintaining detection accuracy.
3Stability of the object's composition
If security policies are centralized and pushed to all devices, then policy consistency is improved, but network traffic and update overhead increase
Solution Approach 1:
The system implements local quality by allowing light instances to store and apply security policies locally once received from central instances. Each light instance maintains its own copy of the policy database, enabling policy consistency across devices without requiring continuous network communication for policy enforcement. This reduces network traffic for policy updates while maintaining consistency.
Solution Approach 2:
Central instances push security policy updates to light instances in advance before they are needed for content analysis. This preliminary action ensures that light instances have the latest policies available locally, maintaining policy consistency across the distributed system while minimizing network traffic during actual content security operations.
4Ease of operation
If light instances are used to reduce device complexity, then ease of operation is improved, but the ability to handle new security threats may be reduced
Solution Approach 1:
The system implements feedback by having light instances forward suspicious or unknown content segments to central instances for full analysis. The central instances analyze these segments using advanced security tools and update security policies accordingly. This feedback loop ensures that light instances, despite their simplicity, can handle new security threats by leveraging the analytical capabilities of central instances and the updated policies they receive.
Solution Approach 2:
The light instance serves as an intermediary that maintains ease of operation on user devices while connecting to central instances that provide advanced threat detection capabilities. The light instance's role is to identify and forward suspicious content, acting as a bridge between the simple local environment and the powerful centralized analysis system, thereby maintaining both ease of operation and adaptability to new threats.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Various embodiments provide a method and apparatus of providing a distributed security service that runs light instances in a number of security devices and central instances of the security services in select security devices. A received or transmitted client content segment is directed to a light instance which either applies a security policy corresponding to the client content segment if the client content segment has been previously analyzed and has a valid security policy, or else, the light instance sends the client content segment to a central instance to be analyzed. The central instance may then provide a complete security analysis on the client content segment, determine a security policy corresponding to the client content segment and push the determined security policy to one or more of the light instances. Advantageously, a distributed security service delivery may provide highly secure, network efficient and cost effective security service delivery.