Distributed Peer Attack Alerting for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security event and alerting systems face delays in detecting and responding to attacks due to centralized data analysis and limited monitoring of localized network attacks, leading to potential widespread damage from self-propagating malicious code outbreaks.

Innovation Solution

A distributed peer attack alerting method where a community of nodes identifies attacks and transmits alerts, automatically configuring protection measures through a petition model and voting process to rapidly contain threats within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized security event analysis is used, then manual or automatic response can occur, but the round trip time for alerting is long

Engineering Contradiction:
Improvesecurity response capabilityVSAvoidalert round trip time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the centralized security analysis function into distributed peer nodes. Each peer independently monitors its local network segment and can immediately alert others without waiting for centralized processing, eliminating the long round trip time while maintaining coordinated security response capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Peers perform self-monitoring and self-alerting within their local network segments. When a peer detects suspicious activity, it automatically generates and transmits alerts to other peers without requiring centralized intervention, thereby reducing response time while maintaining reliable security coordination.

Inventive Principle:
Principle #25Self-service

2Difficulty of detecting and measuring

If monitoring is performed only at network gateway egress and ingress points, then security events can be detected at boundaries, but highly localized network attacks within subnets are missed

Engineering Contradiction:
Improvesecurity event detection capabilityVSAvoiddetection coverage for localized attacks
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The system divides the network into multiple peer segments, with each peer monitoring its local subnet independently. This segmentation enables detection of localized attacks within each peer's network segment that would otherwise be invisible to centralized gateway monitors, while maintaining the ability to detect attacks at network boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each peer is equipped with local monitoring capabilities tailored to its specific network segment. This local quality approach allows each peer to detect attacks occurring within its own subnet using appropriate local monitoring techniques, while the distributed architecture maintains overall network security awareness.

Inventive Principle:
Principle #3Local quality

3Reliability

If centralized alerting model is used, then coordinated response can occur, but the system cannot rapidly contain localized threats

Engineering Contradiction:
Improvecoordinated security responseVSAvoidthreat containment speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

By segmenting the security response function across distributed peers, each peer can independently and rapidly contain threats within its local segment without waiting for centralized authorization. The segmentation enables both speed of local response and coordination through peer-to-peer communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements rapid feedback loops where peers immediately alert each other of detected threats and can automatically configure protective measures. This feedback mechanism enables rapid containment of localized threats while maintaining coordinated network-wide security response through continuous peer communication.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7779465B2Distributed peer attack alerting
Publication Date: 2010.08.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7779465B2 patent drawing
  • US7779465B2 patent drawing
  • US7779465B2 patent drawing

AI summary

A system and method for distributed peer attack alerting is disclosed. The method includes accessing a peer community wherein the peer community comprises a plurality of nodes comprising a network and wherein at least one of the plurality of nodes comprises an attack identifier. The method further includes identifying an attack at one of the plurality of nodes. In addition, the method includes transmitting an alert to the plurality of nodes, the alert comprising information associated with the attack and automatically configuring at least one attack identifier associated with one of the plurality of nodes in response to the alert.