Remote Network Management Platform Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in timely identification and mitigation of security threats, particularly zero-day threats, due to the complexity of managing hundreds of thousands of devices and applications, and the lack of effective sharing of threat information between enterprises.

Innovation Solution

An automated, anonymized, and rapid information-sharing system between enterprises using a remote network management platform, where computational instances detect and transmit threat levels exceeding a predetermined threshold, allowing other managed networks to identify and address similar threats without exposing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprises implement comprehensive security scanning and threat detection measures, then security threat detection capability is improved, but the time required to identify and address threats increases

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidtime to identify and address threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary threat detection and characterization by analyzing software profiles and calculating threat levels before threats can spread extensively across networks. By pre-identifying potential threats and their characteristics, the system enables faster response times when threats are detected, as the foundational analysis is already completed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback mechanism where threat information is shared between enterprises through the remote network management platform. When one enterprise detects a threat, this information is fed back to other enterprises, enabling them to proactively detect and address the same threat without having to independently discover it, thereby reducing overall response time.

Inventive Principle:
Principle #23Feedback

2Productivity

If enterprises share security threat information with other enterprises, then the speed of threat mitigation is improved, but the risk of exposing sensitive information increases

Engineering Contradiction:
Improvespeed of threat mitigationVSAvoidexposure of sensitive information
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system extracts only the essential threat-related information (software profile characteristics, threat level, threat type) needed for detection and mitigation, while deliberately excluding sensitive enterprise-specific data. This extraction approach enables information sharing for security purposes without exposing proprietary or confidential information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The remote network management platform serves as an intermediary that facilitates secure information exchange between enterprises. The platform mediates the sharing process by receiving, processing, and distributing threat information in a controlled manner, ensuring that sensitive data remains protected while enabling collaborative threat mitigation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If enterprises independently analyze and respond to security threats, then information security is maintained, but security efforts are duplicated across enterprises

Engineering Contradiction:
Improveinformation securityVSAvoidduplicated security efforts
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system creates a universal threat detection framework that can be applied across multiple enterprises through the remote network management platform. By establishing common threat criteria, software profiles, and detection methodologies, the system enables multiple enterprises to benefit from a unified approach rather than each independently developing separate solutions, reducing redundant efforts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The feedback mechanism allows enterprises to share threat detection results and responses, enabling other enterprises to learn from and replicate successful mitigation strategies without having to independently conduct the same analysis. This reduces duplicated security efforts while maintaining information security through controlled information sharing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11240271B2Distributed detection of security threats in a remote network management platform
Publication Date: 2022.02.01 SERVICENOW INC
  • US11240271B2 patent drawing
  • US11240271B2 patent drawing
  • US11240271B2 patent drawing

AI summary

A system may include a plurality of computational instances dedicated to different managed networks and a central instance communicatively coupled to the plurality of computational instances. A first computing device disposed within a first computational instance may be configured to: obtain a profile of a software application operational within a first managed network to which the first computational instance is dedicated, calculate a threat level of the software application based on the profile, determine that the threat level exceeds a pre-determined threshold, and transmit, to the central instance, an indication that the threat level exceeds the pre-determined threshold. A second computing device disposed within the central instance may be configured to: receive the indication, determine that the software application is also operational within a second managed network to which a second computational instance, and transmit, to the second computational instance, an indication that the threat level exceeds the pre-determined threshold.