Secure SOAR Data Replication via Tenant Filtering and Outbound Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
MSSPs face challenges in managing privacy, heterogeneity, scalability, and network infrastructure when providing centralized security services to multiple customers, including the need to manage sensitive information, handle diverse customer environments, and reduce VPN overhead.
Innovation Solution
A distributed multi-tenancy MSSP architecture with a master SOAR node and secure router enables selective data-replication and automated response, allowing customers to control data sharing, simplifying workflows, and eliminating the need for direct VPN connections by using outbound TCP connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If a centralized platform is used to manage multiple customer organizations, then security service orchestration capability is improved, but customer privacy and sensitivity of information leaving premises deteriorates
Solution Approach 1:
The system segments the centralized platform into distributed tenant nodes, each operating independently within customer premises. Each tenant node processes and filters data locally before sending only aggregated, non-sensitive information to the master node, thus maintaining automation capability while protecting customer privacy through spatial segmentation of processing functions.
Solution Approach 2:
The master node acts as an intermediary that receives only summarized, non-sensitive data from tenant nodes rather than raw sensitive information. This intermediary architecture enables centralized orchestration while preserving customer privacy by filtering and aggregating data at the tenant node level before transmission to the master node.
2Productivity
If a centralized platform handles multiple customer environments, then service consolidation is improved, but handling diversity of customer environments deteriorates
Solution Approach 1:
Each tenant node is configured with local quality characteristics specific to its customer environment, allowing customization of data collection, processing, and filtering rules. This enables each node to adapt to local heterogeneity while the master node benefits from consolidated service management, resolving the contradiction between consolidation efficiency and environmental diversity handling.
3Reliability
If dedicated VPN connections are established with each customer site, then secure incident investigation capability is improved, but network infrastructure burden and complexity deteriorates
Solution Approach 1:
The system extracts the secure communication requirement from the traditional VPN model by implementing encrypted channels between tenant nodes and the master node. This extraction eliminates the need for complex dedicated VPN infrastructure while maintaining secure incident investigation capability, as each tenant node establishes independent encrypted connections rather than requiring site-to-site VPNs.
Data Source
AI summary
Systems and methods for providing selective data-replication among nodes of a distributed multi-tenancy MSSP architecture for performing secure orchestration and automated response (SOAR) are provided. According to one embodiment a master SOAR node of an MSSP receives multiple messages via a secure router coupling a computing environment of the MSSP in communication with respective computing environments of multiple customers of the MSSP. The messages contain information regarding alerts relating to network infrastructure of the customers and the information is controlled by data sharing policies implemented by tenant SOAR nodes within the respective computing environments of the customers. Based on an investigation into an alert relating to a network infrastructure of a particular customer, the master SOAR node causes a workflow to be remotely executed by a tenant SOAR node within the computing environment of the particular customer.


