Edge Node Threat Detection Using Local ML Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat detection systems face challenges in efficiently processing large volumes of data, leading to decreased quality of service, increased costs, and resource consumption, which can result in inadequate protection against advanced threats.
Innovation Solution
A threat detection network with interconnected nodes and a backend system that utilizes a local threat detection model based on machine learning, combining misuse detection and anomaly detection models to make security-related decisions at the node level, thereby reducing the data volume sent to the backend.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If backend-side data processing pipelines are used for threat detection, then detection precision is improved, but data processing time and resource consumption increase
Solution Approach 1:
The patent divides the threat detection system into two segments: a backend server that performs comprehensive data processing and model training, and edge nodes that perform local real-time detection using pre-trained models. This segmentation allows precision-heavy operations to occur offline while real-time detection happens locally with minimal delay.
Solution Approach 2:
The system performs preliminary actions by pre-training detection models on the backend server using large datasets before deploying them to edge nodes. This preliminary model training and preparation work is done in advance, so that when actual threat detection is needed at the edge, the models are already ready and no time-consuming training is required during real-time operation.
2Adaptability or versatility
If large volumes of data are collected and processed, then detection coverage is improved, but resource consumption and service costs increase
Solution Approach 1:
The patent extracts the computationally intensive data processing and model training functions from the edge nodes and relocates them to the backend server. Only the essential detection models are deployed to edge nodes, while the bulk data processing, model training, and updates are performed centrally on the server with access to larger computational resources.
Solution Approach 2:
The backend server serves multiple functions: it trains detection models, stores and processes large volumes of training data, manages model versions, and distributes updated models to edge nodes. This multi-functional backend architecture consolidates resource-intensive operations in a single location that can handle the computational load efficiently.
3Measurement precision
If comprehensive data processing is performed at the backend, then detection accuracy is improved, but service quality decreases due to processing delays
Solution Approach 1:
The system segments detection operations into offline comprehensive analysis (backend) and online real-time detection (edge). The backend performs thorough data processing and model training when service quality requirements are less critical, while edge nodes handle time-sensitive real-time detection with pre-trained models, ensuring both accuracy and responsiveness.
Data Source
AI summary
A threat detection network, a node of a threat detection network and a threat detection method in a threat detection network, the threat detection network comprising interconnected nodes (5a-5h) and a backend system (2), wherein the backend system utilizes a backend threat detection mechanism, and at least part of the nodes (5a-5h) comprise security agent modules (6a-6h) which collect data related to the respective node. The nodes (5a-5h) utilize at least one local threat detection model which comprises a machine learning-based model of a backend threat detection mechanism. The method comprises collecting data related to the node (5a-5h) by the security agent module at the node, applying the local threat detection model to the collected data, and making a security related decision at the node (5a-5h), such as an endpoint, based on results of the local threat detection model.


