Distributed Threat Intelligence in Clustered Network Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing centralized approach to threat intelligence and log data analysis is complex, time-consuming, and vulnerable to single points of failure, allowing potential attacks to go undetected and compromising the security of network-connected devices.

Innovation Solution

A distributed system where clustered devices share and analyze threat information within peer groups, using a consensus algorithm to identify and neutralize potential security threats, eliminating the need for a central authority and enhancing security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized authority is used for threat intelligence and log data analysis, then the system can maintain centralized control, but the system becomes complex, time-consuming, and vulnerable to single points of failure

Engineering Contradiction:
Improvesystem reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized threat intelligence system into distributed peer groups where each node independently analyzes threats. This segmentation eliminates the single point of failure while reducing overall system complexity through modular, independent operation of each node.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each node in the peer group performs self-service by independently analyzing threats and making local decisions. This eliminates the need for complex centralized control mechanisms while maintaining system reliability through autonomous operation.

Inventive Principle:
Principle #25Self-service

2Reliability

If a centralized authority is used for threat intelligence and log data analysis, then the system can maintain centralized control, but the process becomes time-consuming and threat information doesn't trickle back in time

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidthreat response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Nodes perform preliminary threat analysis locally and immediately, rather than waiting for centralized processing. This preliminary action enables real-time threat detection and response, eliminating time delays associated with centralized authority processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements direct feedback mechanisms where nodes immediately share threat information with peer groups and update their threat intelligence databases in real-time. This rapid feedback loop eliminates the time delay inherent in centralized processing cycles.

Inventive Principle:
Principle #23Feedback

3Reliability

If a centralized authority is used for threat intelligence and log data analysis, then the system can maintain centralized control, but it introduces a single point of failure that is an excellent target for attackers

Engineering Contradiction:
Improvesystem reliabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized authority into distributed peer nodes, eliminating the single point of failure. Each node operates independently, so compromising one node does not affect the entire system, thereby reducing vulnerability to attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Nodes perform autonomous threat analysis and decision-making without requiring centralized authority. This self-service capability eliminates the vulnerable centralized control point while maintaining system reliability through distributed autonomous operation.

Inventive Principle:
Principle #25Self-service

4Reliability

If a distributed peer group system is used for threat intelligence and log data analysis, then the system eliminates single points of failure and improves response time, but requires nodes to have trust relationships and reach consensus

Engineering Contradiction:
Improvesystem reliabilityVSAvoidtrust and consensus mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by establishing trust relationships between specific peer nodes based on their individual characteristics and behaviors. This localized trust assessment simplifies the overall system complexity compared to universal trust mechanisms, as trust is evaluated and maintained at the node level rather than system-wide.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240048568A1Threat intelligence and log data analysis across clustered devices
Publication Date: 2024.02.08 LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD
  • US20240048568A1 patent drawing
  • US20240048568A1 patent drawing
  • US20240048568A1 patent drawing

AI summary

A method for threat intelligence in a peer group includes identifying, at a first node in a network, a potential security threat. The first node is one of a plurality of nodes in a peer group and each node in the peer group has a level of trust for each node in the peer group. The method includes receiving a security communication from one or more other nodes of the peer group. Each security communication indicates that the node of the peer group sending the security communication has identified a potential security threat similar to the potential security threat identified by the first node. The method includes taking a corrective action to neutralize the potential security threat in response to reaching a consensus with the other nodes of the peer group that sent a security communication regarding the identified potential security threats that are similar.