Network State Inventory Using File Signatures and Bitmaps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing and maintaining an inventory of files across large computer networks is challenging due to storage and network traffic issues, especially in networks with hundreds of thousands of devices and millions of files, where frequent updates and security patches are necessary to address security threats and exploits.
Innovation Solution
A method involving client and server computing devices that use hash functions to generate data signatures, compare them with exemplar signatures, and transmit state bitmaps to efficiently update a network database, reducing data transmission and storage requirements through the use of state bitmaps and exemplar data signatures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complete file inventory data is collected and stored for each computing device, then comprehensive network security monitoring is achieved, but storage requirements become intractable and network traffic increases significantly
Solution Approach 1:
The patent extracts only the essential security-relevant information (file presence/absence indicators) from complete file inventories, storing minimal data locally on devices and maintaining comprehensive security monitoring capability without requiring storage of all file details centrally
Solution Approach 2:
Instead of collecting complete file inventories from all devices and storing them centrally, the patent inverts the approach by having devices store minimal local indicators and allowing centralized reconstruction of inventory data when needed, reversing the traditional data collection paradigm
2Loss of information
If complete file inventory data is transmitted from each computing device, then accurate network state information is obtained, but network traffic becomes significant and scalable
Solution Approach 1:
The patent extracts only essential file presence/absence indicators for transmission to the server, eliminating the need to transmit complete file inventory data while maintaining accurate network state information
Solution Approach 2:
The patent inverts the traditional data transmission model by having devices transmit minimal indicators rather than complete inventories, and enabling the server to reconstruct comprehensive inventory data when needed through selective data retrieval
Data Source
AI summary
A client computing device has a storage device storing a plurality of files and a system agent. The system agent applies a hash function to binary data read from the plurality of files to generate a set of data signatures. A server computing device has a database interface to access a database representing a state of the network and storage for a set of exemplar data signatures resulting from a scan of one or more exemplar computing devices, each data signature generated by applying a hash function to binary data representing a file. The client computing device is configured to receive and compare the set of exemplar data signatures with the generated set of data signatures, and to transmit data to the server computing device based on the comparison. The server computing device is configured to obtain data received from the client computing device and update records in the database.


