Distributed Security Provisioning for Network Edge Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing layered security systems in enterprises face inefficiencies due to repeated processing of files, lack of communication between security layers, limited bandwidth, and resource constraints, leading to delayed threat detection and increased costs, especially in distributed networks with multiple locations.

Innovation Solution

A distributed security provisioning system that deploys content processing nodes external to the network edge, utilizing authority nodes to share security policies, threat data, and detection processing filters across nodes, enabling near-real-time defense event sharing and reducing the need for local security updates and maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security processes independently scan and process each file, then security coverage is improved, but processing time and resource consumption increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the security processing function into two distinct parts: a centralized security server that performs initial file analysis and threat detection, and local security agents that execute and coordinate the scanning process. This segmentation allows the heavy computational workload to be distributed, with the centralized server providing threat intelligence and local agents performing rapid scanning based on received security policies, thereby maintaining comprehensive security coverage while reducing overall processing time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized security server as an intermediary between the local security agents and the threat intelligence sources. This intermediary receives files from local agents, performs initial analysis using security policies and threat data, then distributes processed security information back to local agents. This intermediary approach eliminates redundant scanning by multiple independent processes while maintaining comprehensive security coverage through coordinated multi-layered detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security threat data is propagated across all enterprise locations in real-time, then defense capabilities are improved, but bandwidth consumption increases

Engineering Contradiction:
Improvedefense capabilitiesVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements local quality by allowing each location to maintain local security agents that store and process security policies and threat data locally. Instead of continuously propagating all threat data across the enterprise network, each location's security agent processes files using locally cached security intelligence. This approach maintains strong defense capabilities at each location while significantly reducing network bandwidth consumption by eliminating redundant data transmission.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies preliminary action by having the centralized security server pre-process files and generate security policies before distributing them to local agents. Threat intelligence and security signatures are propagated in advance and cached locally at each location. When security events occur, local agents can immediately respond using pre-loaded security data without requiring real-time network communication, thus maintaining robust defense capabilities while minimizing ongoing bandwidth usage.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If security monitoring is performed at the network edge, then threat detection is improved, but available bandwidth is reduced

Engineering Contradiction:
Improvethreat detectionVSAvoidavailable bandwidth
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent extracts the primary threat detection function from the network edge devices and relocates it to a centralized security server. Local security agents at the network edge perform minimal functions such as file collection and basic scanning using cached security policies, while the centralized server performs comprehensive analysis. This extraction maintains high threat detection precision through centralized intelligence while preserving network bandwidth by reducing the volume of data that must be inspected at the network edge.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3270564B1Distributed security provisioning
Publication Date: 2024.04.10 ZSCALER INC
  • EP3270564B1 patent drawingFigure 1
  • EP3270564B1 patent drawingFigure 2
  • EP3270564B1 patent drawingFigure 3~4

AI summary

Systems, methods and apparatus for a distributed security that provides security processing external to a network edge. The system can include many distributed processing nodes and one or more authority nodes that provide security policy data, threat data, and other security data to the processing nodes. The processing nodes detect and stop the distribution of malware, spyware and other undesirable content before such content reaches the destination network and computing systems.