Distributed Security System with Local Bounding Manager
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital security systems are limited in their ability to detect broader patterns of security threats across multiple computing devices, often missing harmful network effects and being overwhelmed by irrelevant event data. Additionally, these systems struggle with synchronization of local and network components, data type compatibility, and allowing specialized configurations for testing and experimentation.
Innovation Solution
A distributed digital security system that includes distributed instances of a compute engine running locally on client devices and in a security network. This system processes event data using refinement and composition operations, and employs a bounding manager to control the amount and type of event data sent to the cloud, ensuring relevance and reducing noise. The system also uses an ontology service to standardize data formats and interfaces, and an experimentation engine to facilitate testing configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized security system collects all event data from multiple computing devices, then comprehensive threat detection capability is improved, but network bandwidth consumption and data processing load increase significantly
Solution Approach 1:
The patent implements local compute engines at distributed security management positions that perform preliminary processing and filtering of event data before transmission to the central system. This local quality approach allows each distributed position to handle data locally, sending only relevant information to the central system, thereby maintaining comprehensive threat detection while reducing network bandwidth consumption.
2Measurement precision
If all event data from multiple devices is transmitted to the central system, then centralized analysis accuracy is improved, but data transmission time and network load increase
Solution Approach 1:
The patent extracts and removes irrelevant or redundant event data at distributed security management positions before transmission to the central system. By taking out only the essential and relevant data elements needed for centralized analysis, the system maintains analysis accuracy while significantly reducing data transmission time and network load.
3Speed
If local security agents operate independently on each device, then response speed is improved, but ability to detect cross-device threat patterns deteriorates
Solution Approach 1:
The patent segments the security system into distributed compute engines at multiple security management positions, each capable of independent local response.同时,these segmented components are connected through a centralized system that aggregates data for cross-device pattern detection, thus maintaining both fast local response and comprehensive cross-device threat detection capability.
4Reliability
If the system processes and stores all raw event data, then detection completeness is improved, but system complexity and storage requirements increase
Solution Approach 1:
The patent performs preliminary processing, filtering, and aggregation of event data at distributed security management positions before data reaches the central system. This preliminary action reduces the volume and complexity of data that needs to be stored and processed centrally, while maintaining detection completeness through structured data preparation.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.