DXL Domain Master for Real-Time Threat Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise security, real-time threat intelligence sharing between autonomous network elements is challenging due to disparate data representations, lack of a single threat intelligence repository, and trustworthiness validation issues, leading to delayed and incomplete malware protection.

Innovation Solution

A data exchange layer (DXL) with a domain master that reconciles client properties from multiple sources into a common information model, providing real-time, bi-directional communications for secure and accurate security decision-making across heterogeneous network elements, using a publish-subscribe and request-response messaging fabric.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If real-time threat intelligence sharing is implemented across autonomous network elements, then network security response speed is improved, but data representation compatibility and trust validation complexity increase

Engineering Contradiction:
Improvesecurity update latencyVSAvoiddata exchange complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The DXL message format serves as a universal data exchange standard that enables heterogeneous security devices to communicate threat intelligence in a standardized way. The message structure includes standardized fields for threat indicators, device identifiers, and confidence scores, allowing different vendor devices to exchange information without custom integration for each device pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The domain master acts as an intermediary that receives DXL messages from multiple sources, validates trust credentials, reconciles conflicting threat intelligence, and distributes validated information to subscribed devices. This mediator approach centralizes complexity management while enabling simple client devices to benefit from coordinated security intelligence.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If a centralized threat intelligence repository is created, then data consistency is improved, but system scalability and single point of failure risks worsen

Engineering Contradiction:
Improvedata consistencyVSAvoidsystem scalability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system segments the threat intelligence repository into distributed domain masters, each responsible for specific device groups or threat types. This segmentation allows the system to scale by adding specialized domain masters without creating a single centralized bottleneck, while maintaining data consistency within each domain through standardized DXL message protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The architecture dynamically routes DXL messages to appropriate domain masters based on device identifiers and threat types. Devices can be dynamically assigned to different domain masters, and the system can adapt to changing security requirements by adding or removing domain masters without reconfiguring the entire system.

Inventive Principle:
Principle #15Dynamics

3Reliability

If trustworthiness validation is performed for all incoming threat intelligence, then security reliability is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improvetrust validation accuracyVSAvoidvalidation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Trust credentials are validated in advance when devices join the DXL network and register with domain masters. This preliminary validation establishes trusted relationships before threat intelligence exchange begins, allowing subsequent messages from validated devices to be processed with less overhead while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10715556B2Real-time policy distribution
Publication Date: 2020.07.14 MAGENTA SECURITY HOLDINGS LLC
  • US10715556B2 patent drawing
  • US10715556B2 patent drawing
  • US10715556B2 patent drawing

AI summary

In one example, there is disclosed a domain master for a data exchange layer (DXL), including: a hardware platform configured to execute instructions; and one or more memories having stored thereon instructions to instruct the hardware platform to: communicatively couple to the DXL; provide a DXL messaging service including native support for request-response (1:1) transactions via a publish-subscribe (1:N, N>1) fabric; provide DXL domain master services for a DXL domain; and provide DXL-based real-time policy and task distribution for DXL endpoints of the DXL domain.