Peer-to-Peer Network Nodes for Multi-Host Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional computer network security systems face challenges in detecting and remediating complex threats that involve multiple hosts, due to one-directional communication between sensors and backends, leading to delayed visibility and limited contextual awareness.

Innovation Solution

A method and system that enable peer-to-peer communication between nodes in a computer network, allowing for the detection of security threats, collection of context information, and sharing of threat-related data across nodes and to a backend, facilitating more comprehensive and timely threat analysis and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional one-directional communication between sensors and backend is used, then system simplicity is maintained, but detection capability for multi-host threats and situational awareness deteriorates

Engineering Contradiction:
Improvecommunication architectureVSAvoidmulti-host threat detection
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent inverts the traditional one-way communication model by enabling sensors to initiate communications with each other and with the backend based on detected threats. This allows sensors to push threat information bidirectionally, transforming the passive data collection model into an active threat-response model that improves multi-host threat detection capability.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system implements feedback mechanisms where sensors receive responses from the backend and from each other based on threat information. This feedback loop enables dynamic adjustment of detection and response strategies, allowing the system to adapt to evolving threats and improve situational awareness across the network.

Inventive Principle:
Principle #23Feedback

2Device complexity

If centralized backend processing is used, then data processing control is simplified, but response time for ongoing attacks deteriorates

Engineering Contradiction:
Improvedata processing controlVSAvoidresponse time for attacks
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent segments the centralized processing function by enabling sensors to perform local analysis and respond to threats independently. Each sensor can detect, analyze, and respond to threats locally without waiting for backend processing, significantly reducing response time for ongoing attacks while maintaining backend coordination for broader strategic decisions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Sensors are equipped with preliminary detection and response capabilities that allow them to take immediate action upon detecting threats. This preliminary action enables rapid response to ongoing attacks before backend processing completes, reducing the vulnerability window while the backend continues to provide coordinated strategic guidance.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If basic local anomaly detection at sensors is used, then sensor simplicity is maintained, but contextual awareness and threat analysis capability deteriorates

Engineering Contradiction:
Improvesensor capabilityVSAvoidcontextual awareness
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent merges local sensor detection capabilities with contextual information from multiple sources including other sensors, backend systems, and external threat intelligence. This combination enriches basic anomaly detection with comprehensive contextual awareness, enabling sensors to understand the broader threat landscape while maintaining operational simplicity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Sensors are designed with multi-functionality to perform not only local anomaly detection but also contextual analysis, threat enrichment, and coordinated response. This universal capability allows sensors to handle diverse threat scenarios and provide comprehensive contextual awareness without requiring complex dedicated systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Device complexity

If data collection intensity is controlled by backend updates, then system control is simplified, but adaptability to evolving threats deteriorates

Engineering Contradiction:
Improvesystem controlVSAvoidthreat response adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic data collection control where sensors can autonomously adjust their data gathering intensity and scope based on detected threats and received feedback. This dynamic adaptation allows the system to respond flexibly to evolving threats while the backend maintains overall system coordination and policy guidance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Sensors possess self-service capabilities to autonomously manage their own data collection and processing needs based on detected threats. This self-service approach enables rapid adaptation to evolving threats without requiring constant backend intervention, while the backend continues to provide strategic direction and resource coordination.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12284198B2Threat control method and system
Publication Date: 2025.04.22 F SECURE CORP
  • US12284198B2 patent drawing
  • US12284198B2 patent drawing
  • US12284198B2 patent drawing

AI summary

Disclosed is a system and a method of threat detection in a computer network, the method including detecting by a first node a security threat, e.g. relating to anomalous or malicious behavior, digital object and/or context, at the first node, collecting context information at the first node relating to the detected security threat, reporting at least one detected security threat and the collected context information to at least a second node, analyzing at the second node the received information relating to the security threat and collecting context information relating to the analysis at the second node, and sending the threat related information with added analysis and context information collected from the second node to at least one further node or backend.