Enterprise Security Assessment Sharing for Endpoint Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise security solutions are not scalable in a cost-effective manner and lack straightforward extensibility, with high management and maintenance costs due to the inability to provide effective common management across disparate security product 'islands' and inefficient incident detection.
Innovation Solution
The Enterprise Security Assessment Sharing (ESAS) system enables sharing of security-related information between endpoints using semantic abstractions called security assessments, which include a concise vocabulary for categorizing security incidents with confidence levels and time validity, allowing endpoints to publish and subscribe to assessments for enhanced incident detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple discrete security products are deployed to monitor different parts of enterprise data, then security coverage is improved, but system complexity and management difficulty increase
Solution Approach 1:
The patent merges multiple discrete security products into a unified framework where all security endpoints (host, network, application) share common data structures and management mechanisms. The security assessment framework consolidates monitoring across different security products by using a unified vocabulary and data sharing approach, reducing overall system complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The security assessment framework provides universal data structures and communication protocols that can be applied across different security product types. The same assessment mechanisms work for host security, network security, and application security, allowing a single framework to serve multiple security functions without requiring product-specific implementations.
2Adaptability or versatility
If security products operate as separate local islands, then product independence is maintained, but enterprise-wide correlation capability deteriorates
Solution Approach 1:
The security assessment framework acts as an intermediary layer between discrete security products. Each security product generates assessments in a standardized format that can be shared and correlated across the enterprise. The framework mediates communication between products by translating their local findings into a common vocabulary, enabling correlation without requiring products to be tightly integrated.
3Measurement precision
If raw data is shared throughout the enterprise for security analysis, then detection accuracy is improved, but data volume and processing burden increase
Solution Approach 1:
The framework extracts only the essential security-relevant information from raw data and transforms it into condensed security assessments. Instead of sharing complete raw data streams, the system extracts key findings, context, and actionable information, reducing data volume while maintaining detection accuracy. This extraction process occurs at each security endpoint before data is shared across the enterprise.
4Stability of the object's composition
If existing security rules are reconfigured when new endpoints are provisioned, then rule consistency is maintained, but deployment time and operational overhead increase
Solution Approach 1:
The framework segments security rules into endpoint-specific configurations that can be independently deployed. Each new endpoint receives its own rule set without affecting existing endpoints. This segmentation allows rule consistency to be maintained through centralized management while enabling rapid deployment of new endpoints without requiring reconfiguration of the entire rule base.
Data Source
AI summary
An enterprise-wide sharing arrangement uses a semantic abstraction, called a security assessment, to share security-related information between security products, called endpoints. A security assessment is defined as a tentative assignment by an endpoint of broader contextual meaning to information that is collected about an object of interest. Endpoints utilize an architecture that comprises a common assessment sharing agent and a common assessment generating agent. The common assessment sharing agent is arranged for subscribing to security assessments, publishing security assessments onto a channel, maintaining an awareness of configuration changes on the channel (e.g., when a new endpoint is added or removed), and implementing security features like authorization, authentication and encryption. A common assessment generating engine handles endpoint behavior associated with a security assessment including assessment generation, cancellation, tracking, and rolling-back actions based on assessments that have expired. The common assessment generating engine generates and transmits messages that indicate which local actions are taken.


