Enterprise Search System Automates Endpoint Security Audits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems overwhelm network administrators with diverse and voluminous data from endpoint devices, making it difficult to detect vulnerabilities, malware presence, and software patch status, which hinders timely protection and remediation of networks.

Innovation Solution

An enterprise search system that automates the search for operational attributes across network devices, using a scalable approach with flexible queries and proactive endpoint inspection, employing agents to execute audit scripts and filter results based on input information, thereby simplifying the detection of indicators of compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of data from diverse endpoint devices is performed, then detection accuracy of security threats may be improved, but administrator workload and time consumption increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidadministrator time consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automated self-analysis of endpoint device data through intelligent agents that autonomously collect, analyze, and report security threats. The agents perform self-service functions including automatic data gathering from multiple sources, threat detection using machine learning algorithms, and generating security reports without requiring manual administrator intervention for each analysis task.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An intermediary analysis system is introduced between the endpoint devices and administrators. This system includes intelligent agents that act as mediators to automatically process and analyze data from diverse endpoint devices, transforming raw data into actionable security insights. The intermediary system handles the complexity of data integration and analysis, freeing administrators from manual work while maintaining high detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive data collection from all endpoint devices is performed, then complete security coverage is improved, but data volume and system complexity increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex task of comprehensive security analysis into smaller, manageable components distributed across multiple intelligent agents. Each agent is responsible for specific endpoint devices or security functions, dividing the overall system into independent modular units. This segmentation reduces system complexity by allowing each component to handle only its designated tasks while maintaining complete security coverage through coordinated operation of all segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimensional layer of intelligence by deploying software agents across endpoint devices. This creates a distributed multi-dimensional architecture where analysis occurs not only centrally but also at the endpoint level. The additional dimension of endpoint-based autonomous analysis enables comprehensive security coverage without overwhelming central systems, as the complexity is distributed across multiple dimensional layers of the architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Speed

If real-time monitoring of all network devices is implemented, then threat detection speed is improved, but resource consumption and processing load increase

Engineering Contradiction:
Improvethreat detection speedVSAvoidprocessing resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system implements partial monitoring by deploying intelligent agents that selectively focus on critical security parameters and high-risk endpoint devices rather than uniformly monitoring all devices at maximum intensity. The agents perform partial analysis on less critical devices while allocating more resources to high-priority targets, achieving fast threat detection speed where needed while reducing overall resource consumption through differentiated monitoring intensity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12130909B1Enterprise search
Publication Date: 2024.10.29 MAGENTA SECURITY HOLDINGS LLC
  • US12130909B1 patent drawing
  • US12130909B1 patent drawing
  • US12130909B1 patent drawing

AI summary

A method performed by an enterprise search system to conduct an automated, computerized search for select operational attributes of a plurality of network devices is shown. The method comprises initiating the search via a user interface based on receipt of input information, which is used to form a query. The method then determines based on the query, one or more audits each specifying one or more tasks to be performed by at least a first network device to search for the select operational attributes. Subsequently, the method makes the one or more audits available to the first network device via a network, and receives, from the first network device, one or more responses to the query. The method may include generating one or more filter conditions to apply to results of executing the one or more tasks to yield the select operational attributes when included in the results.