Network Node Vulnerability Consensus Using Distributed Security Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions lack a decentralized method to assess the vulnerability of network nodes participating in a network, relying on centralized patch management tools and failing to provide a reliable assessment of security patch installation across multiple nodes.
Innovation Solution
A decentralized consensus mechanism using a Master Miner and Miners within a trusted zone to determine vulnerability levels through a distributed ledger, leveraging security patch information and CVE lists to achieve a consensus-based vulnerability certification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized patch management tools are used to assess vulnerability, then vulnerability assessment can be performed, but the system has single points of failure and hacking risks
Solution Approach 1:
The system divides the centralized vulnerability assessment function into multiple distributed security management nodes (Miners) that independently assess vulnerability and reach consensus through a distributed ledger, eliminating single points of failure while maintaining assessment capability
Solution Approach 2:
A distributed ledger technology acts as an intermediary between multiple security management nodes, enabling them to share and verify vulnerability assessment results without requiring a centralized authority, thus improving reliability while distributing system complexity
2Reliability
If multiple security management nodes perform vulnerability assessment, then decentralization and reliability are improved, but consensus determination complexity increases
Solution Approach 1:
Security management nodes exchange vulnerability assessment results and reach consensus through iterative feedback loops recorded on the distributed ledger, where each node's assessment is verified and validated by others before final determination, managing complexity through structured feedback mechanisms
Solution Approach 2:
Multiple independent vulnerability assessments from different security management nodes are merged into a single consensus result through the distributed ledger, combining individual assessments into a unified reliable determination while distributing the computational complexity across nodes
Data Source
AI summary
A method for determining a vulnerability of a network node. The method includes a master security management node obtaining security patch information regarding one or more security patches installed on the network node. The method also includes the master security management node using the security patch information to determine a first vulnerability value for the network node. The method also includes the master security management node obtaining a set of other vulnerability values for the network node, wherein each other vulnerability value was determined by different security management node. The method also includes the master security management node determining, based on the set of other vulnerability values, whether a consensus regarding the vulnerability level of the network node has been reached. If the master security management node determines that a consensus regarding the vulnerability level of the network node has been reached, the first vulnerability value is assigning to the network node.


