Distributed Data Intake System for Untrusted Command Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data intake and query systems face challenges in seamlessly searching and analyzing diverse data types from various data sources, as their capabilities are often limited to internal data stores, and they lack the ability to route data to different destinations, restricting the scope of search and analytics operations.

Innovation Solution

A data intake and query system is developed that extends search and analytics capabilities by employing a search process master and query coordinators combined with a scalable network of distributed nodes, enabling the collection and processing of data from diverse data systems, including external data sources, and providing big data open stack integration to act as a big data pipeline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a data intake and query system is limited to internal data stores, then system complexity is reduced, but the scope of search and analytics operations is restricted

Engineering Contradiction:
Improvesystem complexityVSAvoidscope of search and analytics operations
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system is segmented into distinct functional components: a master node that manages query coordination and worker nodes that execute distributed search operations. This segmentation allows the system to handle external data sources while maintaining manageable complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The master node acts as an intermediary between the user interface and distributed worker nodes, coordinating query execution across multiple data sources. This intermediary layer abstracts the complexity of distributed operations while enabling extended analytics capabilities beyond internal data stores.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data from diverse data systems is collected and processed, then data analysis flexibility is improved, but data processing complexity increases

Engineering Contradiction:
Improvedata analysis flexibilityVSAvoiddata processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The distributed query system implements universal data processing capabilities that can handle multiple data types and formats from diverse sources through a unified query interface. The system processes structured, semi-structured, and unstructured data using the same distributed execution model, reducing processing complexity despite handling diverse data systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes parameters of data processing by using configurable query coordinates and distributed execution parameters. These parameter changes allow flexible adaptation to different data sources and types while maintaining consistent processing logic across the distributed system.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If a distributed execution model is used with untrusted commands, then system scalability is improved, but system security risks increase

Engineering Contradiction:
Improvesystem scalabilityVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The master node implements feedback mechanisms that monitor and validate commands before distributing them to worker nodes. This feedback loop allows the system to maintain scalability while checking for security issues, ensuring that untrusted commands are properly validated before execution in the distributed environment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10698897B2Executing a distributed execution model with untrusted commands
Publication Date: 2020.06.30 CISCO TECHNOLOGY INC
  • US10698897B2 patent drawing
  • US10698897B2 patent drawing
  • US10698897B2 patent drawing

AI summary

Systems and methods are disclosed for executing a distributed execution model with untrusted commands. The distributed execution model can be distributed to multiple nodes in a distributed computing environment. At least one node can process the distributed execution model to identify an untrusted command. The node can use data associated with the untrusted command to identify one or more files associated with the untrusted command. Based on the files, the node can generate a data structure, and execute at least a portion of the data structure.