Endpoint Device Container for Security Deployment Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for verifying security technology deployment efficacy across computer networks are inefficient, as they fail to accurately aggregate and visualize the deployment of multiple security technologies across endpoint devices, leading to incorrect assumptions about configuration and compliance.

Innovation Solution

A method that accesses and aggregates objects published by security technologies, partitions them into endpoint device containers, generates manifests, and labels devices with deployed security technologies, allowing for visualization of security technology permutations and compliance with security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current methods are used to verify security technology deployment, then the process is simple, but the accuracy of deployment verification is insufficient

Engineering Contradiction:
Improvedeployment verification accuracyVSAvoidverification process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The verification process is segmented into distinct phases: data collection from security technologies, data aggregation into endpoint device containers, manifest generation, and visualization. This segmentation allows complex verification to be broken down into manageable steps, improving accuracy while maintaining operational clarity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Endpoint device containers serve as intermediaries that aggregate data from multiple security technologies and normalize it into a unified structure. This intermediary mechanism enables accurate deployment verification across heterogeneous security products without increasing operational complexity at the user level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If multiple security technologies are aggregated, then deployment efficacy is accurately measured, but data processing complexity increases

Engineering Contradiction:
Improvedeployment information completenessVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

Data from multiple security technologies is merged into unified endpoint device containers that preserve information about all deployed technologies. This merging approach ensures complete deployment information is maintained while the system automatically handles the complexity of integrating heterogeneous data sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The endpoint device container structure serves multiple functions: it stores data from different security technologies, normalizes the data into a consistent format, and prepares it for visualization and analysis. This multi-functionality reduces overall system complexity by consolidating processing tasks into a unified framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive visualization is provided, then compliance assessment is improved, but system resource consumption increases

Engineering Contradiction:
Improvecompliance assessment accuracyVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Data aggregation and manifest generation are performed as preliminary actions before visualization is requested. By pre-processing and organizing data into structured containers and manifests, the system reduces resource consumption during visualization operations while maintaining comprehensive compliance assessment capabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240406184A1Method for verifying security technology deployment efficacy across a computer network
Publication Date: 2024.12.05 ARCTIC WOLF NETWORKS INC
  • US20240406184A1 patent drawing
  • US20240406184A1 patent drawing
  • US20240406184A1 patent drawing

AI summary

A method for monitoring endpoint devices affiliated with a computer network includes: for each security technology, accessing a set of objects generated by the security technology during a time interval and representing characteristics endpoint devices configured with the security technology, partitioning object groups representing individual endpoint devices, and aggregating characteristics represented in each object group into an endpoint device container associated with the security technology and containing identifying data and status data representing one endpoint device; identifying a first subset of endpoint devices configured with first and second security technologies based on correspondence between data contained endpoint device containers associated with the first and second security technologies; and identifying a second subset of endpoint devices configured with the first security technology and excluding the second security technology based on absence of correspondence between data contained in endpoint device containers associated with the first and second security technologies.