Dynamic Timeout for Remote Security Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in securing endpoints that regularly interact with external content and services, as existing techniques are inadequate in managing security locally and effectively, especially in heterogeneous networks where device compatibility and security policy compliance are difficult to enforce.

Innovation Solution

A threat management facility that remotely stores global reputation information is combined with a locally deployed machine learning classifier on endpoints to evaluate the risk of network communications, dynamically setting timeouts for requests and adjusting security parameters, such as scanning aggressiveness and content retrieval rates, to enhance security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a remote threat management facility is used to store global reputation information, then security coverage is improved, but network latency and response time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security system is segmented into two parts: a remote threat management facility for comprehensive global reputation data and a local machine learning classifier for rapid risk assessment. This segmentation allows the system to maintain both broad security coverage and fast response times by dividing functionality between centralized and distributed components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The local machine learning classifier performs preliminary risk assessment of network communications before queries are sent to the remote threat management facility. This preliminary action filters out low-risk communications locally, reducing network latency for safe communications while maintaining comprehensive security coverage for suspicious activities.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If a local machine learning classifier is deployed on endpoints, then response time is improved, but device complexity increases

Engineering Contradiction:
Improveresponse timeVSAvoidendpoint complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The machine learning classifier acts as an intermediary layer between the endpoint and the remote threat management facility. It simplifies the endpoint's burden by handling local risk assessments and only communicating with the remote facility when necessary, thereby improving response time while managing device complexity through intelligent delegation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts security parameters such as timeout values and scanning aggressiveness based on risk assessments. This allows the local classifier to operate efficiently with varying levels of complexity depending on the threat level, improving response time for low-risk communications while maintaining security for high-risk scenarios.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If dynamic timeout adjustment is implemented based on risk assessment, then security effectiveness is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The timeout parameter is made dynamic rather than static, adjusting automatically based on the risk assessment of each network communication. High-risk communications receive longer timeouts for comprehensive checking, while low-risk communications use shorter timeouts, improving security effectiveness without uniformly increasing processing overhead across all communications.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different timeout values and security parameters are applied locally to different network communications based on their specific risk profiles. This localized approach ensures that processing overhead is concentrated only on suspicious communications that require enhanced security checks, rather than applying uniform overhead to all network traffic.

Inventive Principle:
Principle #3Local quality

4Reliability

If security parameters such as scanning aggressiveness are adjusted dynamically, then threat detection capability is improved, but system resource consumption increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial security measures (adjusted scanning aggressiveness) based on the assessed risk level of each communication. Low-risk communications receive minimal scanning to conserve resources, while high-risk communications receive more intensive scanning. This partial action approach maintains threat detection capability for suspicious activities while reducing system resource consumption for benign traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10951642B2Context-dependent timeout for remote security services
Publication Date: 2021.03.16 SOPHOS LTD
  • US10951642B2 patent drawing
  • US10951642B2 patent drawing
  • US10951642B2 patent drawing

AI summary

A threat management facility that remotely stores global reputation information for network content can be used in combination with a recognition engine such as a machine learning classifier that is locally deployed on endpoints within an enterprise network. More specifically, the recognition engine can locally evaluate reputation for a network address being accessed by an endpoint, and this reputation information can be used to dynamically establish a timeout for a request from the endpoint to the threat management facility for corresponding global reputation information.