LSAS Engine Segmentation and Dilution for Intrusion Swelling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mechanisms for computer security and data privacy do not adequately address the 'swelling' aspect of computing system intrusions, which is analogous to the biological response of swelling in response to injuries, providing automated countermeasures for segmentation, dilution, and scaffolding to isolate and mitigate attacks.

Innovation Solution

Implementing a Local Segment Analysis and Security (LSAS) engine in data processing systems that collects status metrics, analyzes for attacks, and responds with segmentation, dilution, and scaffolding actions, similar to biological responses, to isolate affected areas, dilute attack traffic, and provide temporary support mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional computer security mechanisms are used, then basic security functions are provided, but the system cannot adequately respond to swelling aspects of intrusions and lacks automated self-healing capabilities

Engineering Contradiction:
Improvesystem security and self-healing capabilityVSAvoidsecurity system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the computing environment into multiple segments with LSAS engines deployed in each segment. When an intrusion is detected in one segment, the system can isolate that segment from others, preventing the swelling aspect of the intrusion from spreading to the entire system. This segmentation approach enables localized response to attacks while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including LSAS engines, agents, and communication mechanisms that mediate between detection of intrusions and implementation of security responses. These intermediaries enable automated coordination of security actions across segments, providing the self-healing capability needed to address swelling intrusions without direct human intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If manual security response actions are taken, then security incidents can be addressed, but the response time is delayed and human intervention is required

Engineering Contradiction:
Improveautomated security responseVSAvoidsystem operation simplicity
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The LSAS engine operates autonomously to detect intrusions, analyze status metrics, determine appropriate security response actions, and implement those actions without requiring human intervention. The system monitors its own segments, communicates with other LSAS engines, and automatically executes segmentation, dilution, or scaffolding responses, enabling the security system to serve itself.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously collects status metrics from agents in each segment, analyzes these metrics to detect intrusions, and uses this feedback to trigger appropriate security responses. The feedback loop enables automated adaptation to changing security conditions, with the LSAS engine adjusting its responses based on real-time system state information.

Inventive Principle:
Principle #23Feedback

3Speed

If security responses are implemented quickly, then the spread of intrusions can be limited, but the precision of attack detection and response selection may be compromised

Engineering Contradiction:
Improvesecurity response speedVSAvoidattack detection accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system performs preliminary analysis of status metrics and pre-determines appropriate security response actions based on detected intrusion patterns. By preparing response strategies in advance based on analyzed metrics, the system can quickly implement pre-planned actions when intrusions are detected, achieving both speed and precision in security responses.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10951646B2Biology based techniques for handling information security and privacy
Publication Date: 2021.03.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10951646B2 patent drawing
  • US10951646B2 patent drawing
  • US10951646B2 patent drawing

AI summary

A local segment analysis and security (LSAS) engine method, computer program product, and apparatus are provided. The LSAS engine collects status metrics indicating a current operational status of the computing resources within a first segment of a computing environment, analyzes the status metrics to determine whether the first segment is the target of a first attack, and receives, from another LSAS engine of a second segment of the computing environment, a message indicating a status of the second segment with regard to the second segment being a target of a second attack. The LSAS engine determines a security response action to implement based on the received message and results of the analysis and transmits a control message to a computing resource of the first segment to implement the determined security response action. The security response action is at least one of a segmentation, dilution, or scaffolding security response action.