Enterprise Security Assessment Sharing for Incident Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise security solutions face high rates of false-positive and false-negative detection of security incidents due to partial data monitoring, leading to inefficient incident detection and costly manual integration and correlation across isolated security product islands, lacking a unified management and response system.

Innovation Solution

The Enterprise Security Assessment Sharing (ESAS) system creates a semantic abstraction called security assessments, which are concise, tentative, and time-bound, allowing endpoints to share contextual information, reducing data complexity, and enabling efficient detection and response to security incidents through a centralized audit point and publish/subscribe model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate local security products are used to monitor different parts of enterprise data, then each product can independently monitor its specific portion, but false-positive and false-negative detection rates increase due to lack of enterprise-wide context

Engineering Contradiction:
Improvesecurity incident detection accuracyVSAvoidnumber of separate security products
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate security product islands into a unified enterprise-wide security system. Security assessments from different products (host security, network security, application security) are correlated and shared across the enterprise, allowing each product to benefit from enterprise-wide context while maintaining its independent monitoring capabilities. This reduces false-positive and false-negative rates without eliminating the individual security products.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If enterprise-wide security data correlation is implemented, then unified security management and reduced false detection rates are achieved, but management and maintenance costs increase

Engineering Contradiction:
Improvesecurity incident detection accuracyVSAvoidmanagement and maintenance cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments enterprise-wide security data correlation into manageable units called security assessments. Each security product generates assessments about its monitored portion, and these assessments are distributed to relevant products through a publish/subscribe model. This segmentation allows enterprise-wide correlation without requiring centralized management of all raw security data, reducing management and maintenance costs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security assessments as an intermediary layer between separate security products. Instead of directly correlating all raw security data from multiple products, the system uses standardized security assessments that summarize and contextualize security events. This intermediary simplifies data correlation and reduces the complexity of management and maintenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive enterprise security monitoring is implemented, then complete security coverage is achieved, but data complexity and processing burden increase

Engineering Contradiction:
Improvesecurity incident detection accuracyVSAvoidamount of security data to be processed
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential security information from comprehensive enterprise security monitoring data. Security assessments contain only the most relevant security events and contextual information, filtering out unnecessary data. This extraction approach provides complete security coverage while reducing the volume of data that needs to be processed and shared across the enterprise.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8959568B2Enterprise security assessment sharing
Publication Date: 2015.02.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8959568B2 patent drawing
  • US8959568B2 patent drawing
  • US8959568B2 patent drawing

AI summary

An enterprise-wide sharing arrangement uses a semantic abstraction, called a security assessment, to share security-related information between different security products, called endpoints. A security assessment is defined as a tentative assignment by an endpoint of broader contextual meaning to information that is collected about an object of interest. Its tentative nature is reflected in two of its components: a fidelity field used to express the level of confidence in the assessment, and a time-to-live field for an estimated time period for which the assessment is valid. Endpoints may publish security assessments onto a security assessment channel, as well as subscribe to a subset of security assessments published by other endpoints. A specialized endpoint is coupled to the channel that performs as a centralized audit point by subscribing to all security assessments, logging the security assessments, and also logging the local actions taken by endpoints in response to security threats.