Remote Computer Drift Detection Without Host Agents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems, particularly those requiring software agents on host computers, face issues such as high resource consumption, predictability, and vulnerability to intruders, while agentless systems suffer from bandwidth and resource load limitations and increased detection risk.
Innovation Solution
An agentless investigation system performs non-contiguous, time-delimited investigations using investigative modules that compare data fingerprints to detect drift and potential threats without requiring software agents on the host computer, utilizing cryptographic hashes to identify changes in data forms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software agents are installed on host computers to conduct security scans, then security monitoring capability is improved, but resource consumption (CPU, RAM) increases and reliability decreases due to agent failures and conflicts
Solution Approach 1:
The patent extracts the security scanning functionality from the host computer by using a remote investigation system that connects to the host without requiring software agents. The investigative modules are executed remotely on the investigation system rather than being installed on the host, thereby removing the source of agent-related problems while maintaining security monitoring capability
Solution Approach 2:
The patent introduces an intermediary investigation system that acts as a mediator between the security administrator and the host computers. This intermediary system performs security scans remotely by establishing connections to hosts and executing investigative modules without requiring agents on the host, thus resolving the contradiction between monitoring capability and resource consumption
2Reliability
If contiguous security scanning is performed at regular intervals, then comprehensive threat detection is improved, but predictability increases making the system vulnerable to intruders who can hide evidence during scan intervals
Solution Approach 1:
The patent implements dynamic scanning intervals where the time between security scans varies rather than following a fixed schedule. This dynamic approach maintains comprehensive threat detection while preventing intruders from predicting scan times and hiding evidence accordingly, resolving the contradiction between detection comprehensiveness and intruder vulnerability
Solution Approach 2:
The patent uses periodic security scanning with variable intervals between scans. This periodic action ensures comprehensive coverage while the varying periods prevent intruders from identifying predictable patterns, thereby maintaining threat detection effectiveness while reducing detection risk
3Loss of energy
If security scans are scheduled to run when server load is low, then performance impact on the host is reduced, but the scanning window becomes predictable and vulnerable to intruder circumvention
Solution Approach 1:
The patent dynamically determines scan timing based on multiple factors including host load conditions and randomness elements. This dynamic scheduling allows the system to perform scans when host performance permits while introducing variability that prevents intruders from predicting scan windows, thereby resolving the contradiction between performance protection and predictability
4Reliability
If software agents are updated across the network, then security software currency is improved, but network operations may be disrupted and extensive testing is required
Solution Approach 1:
The patent extracts the security software update process from the host computers by maintaining investigative modules on the remote investigation system. When updates are needed, the investigation system retrieves new modules and executes them remotely without requiring updates on host machines, thereby maintaining security currency while eliminating network disruptions and update-related conflicts
Solution Approach 2:
The patent uses copying by retrieving updated investigative modules from the investigation system and executing them temporarily on the host computer during remote scans. This approach allows security software to be updated on the central investigation system and immediately deployed without affecting host operations, maintaining currency while ensuring continuity
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach reduces resource consumption, minimizes detection risk, and enhances threat detection by providing context to changes, reducing false positives and enabling efficient monitoring of multiple devices with minimal resource usage.
Implementation Method 1
utilizing cryptographic hashes to identify changes in data forms
Data Source
AI summary
Investigation systems and methods can investigate a target host computer. A reference computer investigation of the reference host computer can be performed by the investigation system sending at least one investigative module to a reference host computer, and the at least one investigative module performing the at least one investigative function and returning reference investigation data. A target computer investigation of the target host computer can be performed by the investigation system sending the at least one investigative module to the target host computer, and the at least one investigative module performing the at least one investigative function and returning comparison investigation data. A reference data fingerprint of the reference investigation data is compared to a comparison data fingerprint of the comparison investigation data to determine if the reference and comparison data fingerprints are identical.


