Distributed Security Provisioning for Network Edge Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing layered security systems in enterprises face inefficiencies due to repeated processing of files, lack of communication between security layers, limited bandwidth, and resource constraints, leading to delayed threat detection and increased costs, especially in distributed networks with multiple locations.
Innovation Solution
A distributed security provisioning system that deploys content processing nodes external to the network edge, utilizing authority nodes to share security policies, threat data, and detection processing filters across nodes, enabling near-real-time defense event sharing and reducing the need for local security updates and maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security processes independently scan and process each file, then security coverage is improved, but processing time and resource consumption increase significantly
Solution Approach 1:
The patent segments the security processing function into two distinct parts: a centralized security server that performs initial file analysis and threat detection, and local security agents that execute and coordinate the scanning process. This segmentation allows the heavy computational workload to be distributed, with the centralized server providing threat intelligence and local agents performing rapid scanning based on received security policies, thereby maintaining comprehensive security coverage while reducing overall processing time.
Solution Approach 2:
The patent introduces a centralized security server as an intermediary between the local security agents and the threat intelligence sources. This intermediary receives files from local agents, performs initial analysis using security policies and threat data, then distributes processed security information back to local agents. This intermediary approach eliminates redundant scanning by multiple independent processes while maintaining comprehensive security coverage through coordinated multi-layered detection.
2Reliability
If security threat data is propagated across all enterprise locations in real-time, then defense capabilities are improved, but bandwidth consumption increases
Solution Approach 1:
The patent implements local quality by allowing each location to maintain local security agents that store and process security policies and threat data locally. Instead of continuously propagating all threat data across the enterprise network, each location's security agent processes files using locally cached security intelligence. This approach maintains strong defense capabilities at each location while significantly reducing network bandwidth consumption by eliminating redundant data transmission.
Solution Approach 2:
The patent applies preliminary action by having the centralized security server pre-process files and generate security policies before distributing them to local agents. Threat intelligence and security signatures are propagated in advance and cached locally at each location. When security events occur, local agents can immediately respond using pre-loaded security data without requiring real-time network communication, thus maintaining robust defense capabilities while minimizing ongoing bandwidth usage.
3Measurement precision
If security monitoring is performed at the network edge, then threat detection is improved, but available bandwidth is reduced
Solution Approach 1:
The patent extracts the primary threat detection function from the network edge devices and relocates it to a centralized security server. Local security agents at the network edge perform minimal functions such as file collection and basic scanning using cached security policies, while the centralized server performs comprehensive analysis. This extraction maintains high threat detection precision through centralized intelligence while preserving network bandwidth by reducing the volume of data that must be inspected at the network edge.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Systems, methods and apparatus for a distributed security that provides security processing external to a network edge. The system can include many distributed processing nodes and one or more authority nodes that provide security policy data, threat data, and other security data to the processing nodes. The processing nodes detect and stop the distribution of malware, spyware and other undesirable content before such content reaches the destination network and computing systems.