Enterprise Security Assessment Sharing System for Unified Incident Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise security solutions face high rates of false-positive and false-negative detections of security incidents due to partial monitoring of enterprise-wide data, leading to inefficient incident detection and management, with isolated security products lacking a unified response channel and language, resulting in significant management and maintenance costs.

Innovation Solution

The Enterprise Security Assessment Sharing (ESAS) system creates a semantic abstraction called a security assessment, which enables endpoints to share security-related information using a concise vocabulary, allowing for tentative assignments of contextual meaning to objects with fidelity and time-to-live fields, facilitating distributed processing and unified response policies across the enterprise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple discrete security products are used to monitor different parts of enterprise data, then security coverage is provided, but false-positive and false-negative detection rates increase due to partial monitoring

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidnumber of security products
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple discrete security products into a unified enterprise security management system that consolidates security data from various sources (firewalls, intrusion detection systems, antivirus software, etc.) into a single platform. This consolidation enables comprehensive enterprise-wide security monitoring while reducing false positives through correlated analysis of data from multiple security tools, thereby improving detection accuracy without requiring each individual product to operate in isolation.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If enterprise-wide security data correlation is implemented, then unified security management is achieved, but management and maintenance costs increase

Engineering Contradiction:
Improveunified security managementVSAvoidmanagement and maintenance costs
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent implements a universal enterprise security management platform that performs multiple functions including data collection from various security sources, centralized data correlation and analysis, policy enforcement, and incident response coordination. This multi-functional system consolidates what would otherwise require separate management tools and personnel for each security product, thereby achieving unified security management while controlling operational costs through resource consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive enterprise security monitoring is implemented, then detection accuracy improves, but system scalability is reduced due to high management costs

Engineering Contradiction:
Improvesecurity incident detectionVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the enterprise security management system into modular components including data collection agents deployed at various security perimeters, a centralized correlation engine, policy management modules, and incident response systems. This modular architecture enables the system to scale by adding or removing individual components based on enterprise needs without requiring complete system redesign, thereby maintaining detection accuracy while improving scalability and reducing incremental management costs.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8136164B2Manual operations in an enterprise security assessment sharing system
Publication Date: 2012.03.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8136164B2 patent drawing
  • US8136164B2 patent drawing
  • US8136164B2 patent drawing

AI summary

An enterprise-wide sharing arrangement uses a semantic abstraction, called a security assessment, to share security-related information between different security products, called endpoints. A security assessment is defined as a tentative assignment by an endpoint of broader contextual meaning to information that is collected about an object of interest. Endpoints may publish security assessments onto a security assessment channel, as well as subscribe to a subset of security assessments published by other endpoints. A specialized endpoint is coupled to the channel that performs as a centralized audit point by subscribing to all security assessments, logging the security assessments, and also logging the local actions taken by endpoints in response to received security assessments. Manual operations are supported by the specialized endpoint including manual approval of actions, security assessment cancellation, and manual injection of security assessments into the security assessment channel.