Remote Computer Drift Detection Without Host Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems, particularly those requiring software agents on host computers, face issues such as high resource consumption, predictability, and vulnerability to intruders, while agentless systems suffer from bandwidth and resource load limitations and increased detection risk.

Innovation Solution

An agentless investigation system performs non-contiguous, time-delimited investigations using investigative modules that compare data fingerprints to detect drift and potential threats without requiring software agents on the host computer, utilizing cryptographic hashes to identify changes in data forms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software agents are installed on host computers to conduct security scans, then security monitoring capability is improved, but resource consumption (CPU, RAM) increases and reliability decreases due to agent failures and conflicts

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security scanning functionality from the host computer by using a remote investigation system that connects to the host without requiring software agents. The investigative modules are executed remotely on the investigation system rather than being installed on the host, thereby removing the source of agent-related problems while maintaining security monitoring capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary investigation system that acts as a mediator between the security administrator and the host computers. This intermediary system performs security scans remotely by establishing connections to hosts and executing investigative modules without requiring agents on the host, thus resolving the contradiction between monitoring capability and resource consumption

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If contiguous security scanning is performed at regular intervals, then comprehensive threat detection is improved, but predictability increases making the system vulnerable to intruders who can hide evidence during scan intervals

Engineering Contradiction:
Improvethreat detection comprehensivenessVSAvoidintruder detection risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic scanning intervals where the time between security scans varies rather than following a fixed schedule. This dynamic approach maintains comprehensive threat detection while preventing intruders from predicting scan times and hiding evidence accordingly, resolving the contradiction between detection comprehensiveness and intruder vulnerability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses periodic security scanning with variable intervals between scans. This periodic action ensures comprehensive coverage while the varying periods prevent intruders from identifying predictable patterns, thereby maintaining threat detection effectiveness while reducing detection risk

Inventive Principle:
Principle #19Periodic action

3Loss of energy

If security scans are scheduled to run when server load is low, then performance impact on the host is reduced, but the scanning window becomes predictable and vulnerable to intruder circumvention

Engineering Contradiction:
Improveperformance burden on hostVSAvoidpredictability to intruders
Core Design Contradiction:
Loss of energyVSObject-affected harmful factors

Solution Approach 1:

The patent dynamically determines scan timing based on multiple factors including host load conditions and randomness elements. This dynamic scheduling allows the system to perform scans when host performance permits while introducing variability that prevents intruders from predicting scan windows, thereby resolving the contradiction between performance protection and predictability

Inventive Principle:
Principle #15Dynamics

4Reliability

If software agents are updated across the network, then security software currency is improved, but network operations may be disrupted and extensive testing is required

Engineering Contradiction:
Improvesecurity software currencyVSAvoidnetwork operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security software update process from the host computers by maintaining investigative modules on the remote investigation system. When updates are needed, the investigation system retrieves new modules and executes them remotely without requiring updates on host machines, thereby maintaining security currency while eliminating network disruptions and update-related conflicts

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses copying by retrieving updated investigative modules from the investigation system and executing them temporarily on the host computer during remote scans. This approach allows security software to be updated on the central investigation system and immediately deployed without affecting host operations, maintaining currency while ensuring continuity

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach reduces resource consumption, minimizes detection risk, and enhances threat detection by providing context to changes, reducing false positives and enabling efficient monitoring of multiple devices with minimal resource usage.

Implementation Method 1

utilizing cryptographic hashes to identify changes in data forms

Methodology Applied
Scientific EffectCryptographic hashing:

Data Source

PatentUS20250258916A1Drift detection in remote computer systems
Publication Date: 2025.08.14 SANDFLY SECURITY LTD
  • US20250258916A1 patent drawing
  • US20250258916A1 patent drawing
  • US20250258916A1 patent drawing

AI summary

Investigation systems and methods can investigate a target host computer. A reference computer investigation of the reference host computer can be performed by the investigation system sending at least one investigative module to a reference host computer, and the at least one investigative module performing the at least one investigative function and returning reference investigation data. A target computer investigation of the target host computer can be performed by the investigation system sending the at least one investigative module to the target host computer, and the at least one investigative module performing the at least one investigative function and returning comparison investigation data. A reference data fingerprint of the reference investigation data is compared to a comparison data fingerprint of the comparison investigation data to determine if the reference and comparison data fingerprints are identical.