Dual Threat Management Model for Distributed Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat management systems for distributed systems face challenges in providing continuous threat identification and remediation due to intermittent connectivity, which prevents centralized approaches from effectively protecting the systems.

Innovation Solution

Implementing a dual threat management model that shifts between centralized and decentralized approaches based on connectivity. The decentralized model uses anomaly detection and peer-to-peer communication among data processing systems to identify and remediate threats even when disconnected from the centralized system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized threat management model is used, then threat identification and remediation can be performed when connected, but continuous threat protection cannot be provided during intermittent connectivity

Engineering Contradiction:
Improvethreat protection continuityVSAvoidconnectivity dependency
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The threat management system is segmented into two distinct models: a centralized threat management model for connected operations and a decentralized threat management model for disconnected operations. This segmentation allows the system to adapt its architecture based on connectivity status, ensuring continuous threat protection regardless of network availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically switches between centralized and decentralized threat management models based on connectivity status. When connected to the threat management server, the centralized model is used; when disconnected, the decentralized model activates. This dynamic adaptation ensures continuous threat identification and remediation capabilities throughout connectivity transitions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If a decentralized threat management model is used, then continuous threat protection can be provided during disconnection, but system complexity increases

Engineering Contradiction:
Improvethreat protection continuityVSAvoidthreat management architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments threat management functionality into centralized and decentralized components, with the decentralized model serving as a lightweight local implementation that activates only when needed. This segmentation reduces the burden of complexity by organizing functions into distinct, context-dependent modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The decentralized threat management model enables data processing systems to perform threat identification and remediation autonomously without requiring continuous connection to the threat management server. Each system serves its own threat management needs locally using the decentralized model when disconnected, reducing the operational complexity of managing centralized dependencies.

Inventive Principle:
Principle #25Self-service

3Reliability

If anomaly detection is implemented in the decentralized model, then new threats can be identified without centralized connectivity, but computational resources are consumed

Engineering Contradiction:
Improvethreat identification capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The decentralized anomaly detection model performs threat identification using available local data and resources without requiring exhaustive analysis. It applies anomaly detection algorithms to identify potential threats using partially available information and local system data, providing sufficient protection without consuming excessive computational resources during disconnected operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12326932B2System and method for threat management in distributed systems
Publication Date: 2025.06.10 DELL PROD LP
  • US12326932B2 patent drawing
  • US12326932B2 patent drawing
  • US12326932B2 patent drawing

AI summary

Methods and systems for managing threats to data processing systems are disclosed. To manage the threats, multiple threat management models may be utilized. The threat management models may include centralized models that rely on operable connectivity to particular systems, and distributed models that do not rely on operable connectivity to the particular systems. The data processing systems may flexibly switch between use of these models to respond to changes in operably connectivity of a distributed system.