Heterogeneous Computing Network Monitoring with Attack Path Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex hybrid computing platforms with diverse cloud and physical resources face challenges in maintaining cybersecurity due to limited visibility, fragmented security tools, and evolving threats, necessitating a comprehensive and adaptive monitoring and protection strategy.
Innovation Solution
A cybersecurity system comprising Network Monitoring Elements (NMEs), Attack Path Tracer (APT), Network Security Controller (NSC), Discovery and Handshake Modules (DHM), dashboard code generator, and data router, which collectively monitor, map, and manage network security across heterogeneous environments, providing real-time threat detection and adaptive response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud computing services are adopted to provide flexible and scalable computing resources, then resource scalability and efficiency are improved, but control and visibility over processing accessing organizational data are lost
Solution Approach 1:
The patent introduces a cloud security posture management system as an intermediary layer between the organization and cloud service providers. This mediator collects security configuration data from multiple cloud services, analyzes it against security baselines, and provides visibility into security postures without requiring direct control over the cloud infrastructure. The system acts as a bridge that maintains organizational awareness while preserving cloud service autonomy.
Solution Approach 2:
The system implements continuous feedback loops by monitoring cloud security configurations, comparing them against established baselines, and providing real-time alerts when deviations are detected. This feedback mechanism enables organizations to maintain visibility into cloud processing activities by receiving ongoing security posture information, allowing them to respond to configuration changes while preserving the scalability benefits of cloud services.
2Adaptability or versatility
If multiple cloud services and SaaS solutions are integrated into hybrid computing platforms, then functional capabilities are improved, but security monitoring complexity increases
Solution Approach 1:
The patent implements a universal security posture management system that can interface with multiple different cloud service providers and SaaS solutions through standardized APIs and connectors. This multi-functional platform consolidates security monitoring across diverse services into a single system, reducing the complexity that would otherwise arise from managing separate monitoring tools for each service. The system performs multiple functions including data collection, analysis, baseline comparison, and alerting within a unified architecture.
3Ease of manufacture
If cloud services are accessed via the Internet with pay-as-you-use pricing, then upfront hardware investment costs are reduced, but control over processing is lost
Solution Approach 1:
The system enables organizations to self-monitor and self-manage their cloud security postures without requiring direct control over the underlying cloud infrastructure. By automatically collecting security configuration data from cloud services and analyzing it against baselines, the system allows organizations to maintain operational control and awareness while benefiting from the cost efficiency of cloud services. The autonomous nature of the monitoring system preserves ease of operation while reducing the need for manual control mechanisms.
Data Source
AI summary
Disclosed is methods, devices, systems, and functionally associated machine executable code for monitoring a heterogeneous computing network which includes multiple computing domains hosted on physical and virtual computing clusters which may interconnect through a plurality of data network segments. Systems according to methods of the disclosed invention may include a heterogeneous set of Network Monitoring Elements (NME), wherein at least some of the monitoring elements are deployed to different respective nodes and or segments on the heterogeneous computer network and are configured to detect network related parameters and events associated with their respective node. An attack path tracer or generator may scan the heterogeneous network to discover possible attacks paths through which the cybersecurity posture on the network may be attacked, compromised and or breached.


