Real-time Security Model for Multi-device Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems lack real-time processing and contextual analysis of security-relevant information across multiple devices, making them ineffective in detecting and responding to security exploits in a timely and comprehensive manner.

Innovation Solution

A security service cloud system that represents system components and events of monitored devices as data objects in a graph model, allowing for real-time updates and analysis, and enabling intelligent responses based on device-specific, group-specific, and global scopes to detect and respond to security concerns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If retrospective analysis tools are used to detect security exploits, then security threats can be identified, but the detection is always delayed and one step behind the attacker

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoiddetection response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing security-relevant information from multiple devices in real-time, building a comprehensive model of system states before attacks occur. This enables the system to detect and respond to security threats as they are being executed, rather than after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where security events are detected, analyzed, and used to update the model of system states in real-time. This feedback mechanism allows the system to adapt and respond dynamically to emerging threats, maintaining current awareness of security conditions across the network.

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If single-device security monitoring is used, then device-specific security issues can be detected, but contextual information from other devices is missing

Engineering Contradiction:
Improvedevice-specific threat detectionVSAvoidcontextual security information
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The system merges security information from multiple devices into a unified model that represents the collective state of the network. By combining data from various sources and maintaining relationships between devices, the system preserves contextual information while enabling comprehensive security analysis that spans across the entire network.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security monitoring system is designed with multi-functionality to handle both device-specific monitoring and network-wide contextual analysis simultaneously. The same infrastructure that tracks individual device states also captures inter-device relationships and patterns, providing universal security monitoring capabilities across multiple levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If real-time security monitoring across multiple devices is implemented, then comprehensive security awareness is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity situation awarenessVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex task of multi-device security monitoring into manageable components: individual device state tracking, inter-device relationship mapping, and global security pattern recognition. This segmentation allows each component to handle specific aspects of security monitoring independently while contributing to the overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary model structure that mediates between raw security events from multiple devices and the final security analysis. This intermediary layer processes and organizes incoming data, maintaining device states and relationships in a structured format that simplifies subsequent analysis and reduces the complexity of handling raw multi-device data directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3152869B1Real-time model of states of monitored devices
Publication Date: 2020.09.02 CROWDSTRIKE
  • EP3152869B1 patent drawingFigure 1
  • EP3152869B1 patent drawingFigure 2
  • EP3152869B1 patent drawingFigure 3

AI summary

A model representing system components and events of a plurality of monitored devices as data objects is described herein. The model resides on a security service cloud and is updated in substantially real-time, as security- relevant information about the system components and events is received by the security service cloud. Each data object in the model has a scope and different actions are taken by security service cloud modules depending on different data object scopes. Further, the security service cloud maintains a model specific to each monitored device built in substantially real-time as the security-relevant information from that device is received. The security service cloud utilizes these device-specific models to detect security concerns and respond to those concerns in substantially real-time.