Distributed Security Compute Engines for Filtered Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital security systems struggle with local-only execution, missing broader patterns across multiple devices, cloud-based systems getting overloaded with irrelevant data, synchronization issues between local and cloud components, and lack of specialized configurations for testing and experimentation.
Innovation Solution
A distributed digital security system with local and cloud instances of compute engines that process event data, using ontological definitions for consistent data formats and patterns, and a bounding manager to filter relevant data, along with a compiler and experimentation engine for configuration and testing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a cloud-based security system collects all event data from multiple devices, then it can detect broader threat patterns, but the cloud system becomes overloaded with irrelevant data
Solution Approach 1:
The system divides security processing into two segments: local compute engines on client devices that perform initial event data filtering and processing, and cloud compute engines that receive only refined, relevant data for broader pattern analysis. This segmentation allows the cloud to detect broader threats while avoiding overload with raw irrelevant data.
Solution Approach 2:
Local compute engines extract and remove irrelevant data from event streams before transmitting to the cloud. Only refined, potentially relevant event data is extracted and sent to cloud-based compute engines, reducing the quantity of data the cloud must process while maintaining threat detection capability.
2Quantity of substance
If a local-only security system processes event data, then it reduces cloud data overload, but it misses broader patterns across multiple devices
Solution Approach 1:
The system divides security processing into two segments: local compute engines on client devices that perform initial event data filtering and processing, and cloud compute engines that receive only refined, relevant data for broader pattern analysis. This segmentation allows the cloud to detect broader threats while avoiding overload with raw irrelevant data.
3Adaptability or versatility
If local and cloud components use different data formats, then each can be optimized independently, but synchronization issues occur
Solution Approach 1:
The system implements a universal data format based on ontological definitions that works across both local and cloud components. Event data is structured with standardized fields and types that can be processed by local compute engines and cloud compute engines alike, ensuring synchronization consistency while maintaining configuration flexibility through the extensible ontological framework.
4Reliability
If existing security systems process all event data, then they ensure comprehensive analysis, but they waste resources on irrelevant data
Solution Approach 1:
Local compute engines extract and remove irrelevant data from event streams before transmitting to the cloud. Only refined, potentially relevant event data is extracted and sent to cloud-based compute engines, reducing the quantity of data the cloud must process while maintaining threat detection capability.
Solution Approach 2:
The system applies partial processing at the local level, where compute engines perform selective filtering and refinement of event data based on local context before sending to the cloud. This partial action at the local level prevents excessive data transmission and processing at the cloud level, optimizing resource utilization while maintaining comprehensive security analysis.
Data Source
AI summary
A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.


