Coordinated Threat Response for Trusted Device Fleets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security information and event management (SIEM) solutions struggle to develop cohesive and coordinated threat detection and mitigation strategies across multiple electronic devices, as they typically treat each device independently without considering inter-device impacts, limiting effective threat response coordination.

Innovation Solution

A computer-implemented method for coordinating threat detection and mitigation among a fleet of trusted devices, which involves transmitting event reports, generating threat responses based on security-related messages, and distributing these responses across connected devices using a threat response profile, allowing for device-specific and coordinated security actions such as disabling services or re-routing tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional SIEM solutions treat each device independently for threat detection and response, then device-specific security monitoring is simplified, but coordinated threat response across the fleet is lost

Engineering Contradiction:
Improvedevice-specific security monitoringVSAvoidcoordinated threat response
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the fleet into individual device monitoring units while maintaining a centralized coordination layer. Each device independently monitors its own security events through simplified local SIEM tools, but these segmented monitoring results are aggregated and coordinated through a fleet-wide threat response platform that considers inter-device impacts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention merges individual device security monitoring capabilities with fleet-wide coordination by integrating local SIEM tools with a centralized threat response system. This combination allows devices to maintain simple independent monitoring while achieving coordinated fleet-level threat response through shared intelligence and unified action.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If each device connects to a centralized SIEM solution for threat detection, then coordinated security management is enabled, but device complexity and connection requirements increase

Engineering Contradiction:
Improvecoordinated security managementVSAvoidconnection requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces a fleet coordination platform as an intermediary layer between individual devices and the centralized SIEM solution. This mediator aggregates data from multiple devices, performs coordinated threat analysis, and distributes responses back to affected devices, thereby enabling coordinated security management without requiring each device to directly connect to the SIEM system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The fleet coordination platform serves multiple functions: it collects security events from numerous devices, analyzes threats across the fleet, determines coordinated responses considering inter-device impacts, and distributes actions to affected devices. This multi-functional approach enables coordinated security management through a single intermediary system rather than complex direct connections from each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If threat responses are customized for each device in the fleet, then device-specific security needs are met, but coordination consistency across the fleet is reduced

Engineering Contradiction:
Improvedevice-specific security customizationVSAvoidcoordination consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system applies local quality by allowing each device to receive customized threat responses tailored to its specific security needs and configuration. However, these localized customizations are made within the framework of a coordinated fleet response, ensuring that device-specific actions remain consistent with overall fleet security strategy and maintain coordination integrity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250103724A1Systems and methods for coordinating threat detection and mitigation among a fleet of trusted devices
Publication Date: 2025.03.27 GENESEE VALLEY INNOVATIONS LLC
  • US20250103724A1 patent drawing
  • US20250103724A1 patent drawing
  • US20250103724A1 patent drawing

AI summary

The present disclosure is directed to systems and methods of coordinating threat detection and mitigation among a fleet of trusted devices. As described herein, cybersecurity is a growing concern of many individuals and organizations, especially for those that use multiple electronic devices. In expansive computing environments such as these, security information and event management (SIEM) solutions have been developed. However, providing a holistic solution to a distributed environment remains challenging. According, the systems and methods described utilize an SIEM solution in conjunction with a threat response profile hosted locally on a trusted device within a fleet of trusted devices to provide a coordinated threat response that can be narrowly and/or broadly applied to one or more devices of the fleet of trusted devices.