Distributed Security System with Local Bounding Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital security systems are limited in their ability to detect broader patterns of security threats across multiple computing devices, often missing harmful network effects and being overwhelmed by irrelevant event data. Additionally, these systems struggle with synchronization of local and network components, data type compatibility, and allowing specialized configurations for testing and experimentation.

Innovation Solution

A distributed digital security system that includes distributed instances of a compute engine running locally on client devices and in a security network. This system processes event data using refinement and composition operations, and employs a bounding manager to control the amount and type of event data sent to the cloud, ensuring relevance and reducing noise. The system also uses an ontology service to standardize data formats and interfaces, and an experimentation engine to facilitate testing configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized security system collects all event data from multiple computing devices, then comprehensive threat detection capability is improved, but network bandwidth consumption and data processing load increase significantly

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements local compute engines at distributed security management positions that perform preliminary processing and filtering of event data before transmission to the central system. This local quality approach allows each distributed position to handle data locally, sending only relevant information to the central system, thereby maintaining comprehensive threat detection while reducing network bandwidth consumption.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If all event data from multiple devices is transmitted to the central system, then centralized analysis accuracy is improved, but data transmission time and network load increase

Engineering Contradiction:
Improvecentralized analysis accuracyVSAvoiddata transmission time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts and removes irrelevant or redundant event data at distributed security management positions before transmission to the central system. By taking out only the essential and relevant data elements needed for centralized analysis, the system maintains analysis accuracy while significantly reducing data transmission time and network load.

Inventive Principle:
Principle #2Taking out (Extraction)

3Speed

If local security agents operate independently on each device, then response speed is improved, but ability to detect cross-device threat patterns deteriorates

Engineering Contradiction:
Improvelocal response speedVSAvoidcross-device threat detection
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the security system into distributed compute engines at multiple security management positions, each capable of independent local response.同时,these segmented components are connected through a centralized system that aggregates data for cross-device pattern detection, thus maintaining both fast local response and comprehensive cross-device threat detection capability.

Inventive Principle:
Principle #1Segmentation

4Reliability

If the system processes and stores all raw event data, then detection completeness is improved, but system complexity and storage requirements increase

Engineering Contradiction:
Improvedetection completenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary processing, filtering, and aggregation of event data at distributed security management positions before data reaches the central system. This preliminary action reduces the volume and complexity of data that needs to be stored and processed centrally, while maintaining detection completeness through structured data preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4274167B1Distributed digital security system
Publication Date: 2025.05.07 CROWDSTRIKE
  • EP4274167B1 patent drawingFigure 1
  • EP4274167B1 patent drawingFigure 2~3
  • EP4274167B1 patent drawingFigure 4

AI summary

A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.