Security Data Aggregation for Distributed Asset Risk Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Global companies face challenges in managing and securing geographically dispersed computing assets due to security risks and the need for real-time monitoring and control across multiple locations, exacerbated by the global reach of the Internet and potential hacking threats.
Innovation Solution
A system and method for aggregating and analyzing security data from multiple assets to compute metrics and change effort estimates, generating aggregate scores, and providing risk reduction recommendations, allowing for the prioritization and visualization of security improvements across assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real-time monitoring and control is implemented across geographically dispersed computing assets, then security management capability is improved, but system complexity and resource requirements increase
Solution Approach 1:
The system divides the global computing asset management into segmented components: local agents deployed on individual assets collect and preprocess security data, regional servers aggregate data from multiple assets, and central management systems provide overall coordination. This segmentation allows real-time monitoring without requiring a monolithic complex system, as each segment operates semi-independently with standardized interfaces.
Solution Approach 2:
The patent introduces intermediary components including local security agents that mediate between computing assets and the central management system, and regional aggregation servers that mediate between multiple local agents and the central system. These intermediaries simplify the overall system architecture by handling data preprocessing, filtering, and initial analysis, reducing the complexity burden on the central system while enabling real-time monitoring.
2Measurement precision
If comprehensive security data is collected from multiple geographically dispersed assets, then security analysis accuracy is improved, but data transmission time and processing overhead increase
Solution Approach 1:
Local security agents perform preliminary actions by collecting, filtering, and pre-processing security data at the source before transmission. They aggregate events locally, perform initial threat assessment, and prepare data in standardized formats. This preliminary processing ensures that only relevant, processed data is transmitted to central systems, maintaining analysis accuracy while reducing transmission time and network overhead.
Solution Approach 2:
The system introduces a spatial dimension to data processing by distributing computation across multiple levels: local agents process data at the asset level, regional servers process aggregated data at the regional level, and central systems perform comprehensive analysis. This multi-dimensional processing architecture allows comprehensive security analysis without requiring all data to traverse the entire network path, reducing transmission time while maintaining analysis completeness.
3Measurement precision
If detailed security metrics and aggregate scores are computed for each asset, then risk assessment quality is improved, but computational resources and processing time increase
Solution Approach 1:
The system applies local quality by computing detailed security metrics and aggregate scores at the appropriate hierarchical level rather than uniformly across all assets. Local agents compute basic security metrics for their host assets, regional servers compute aggregated metrics for groups of assets, and central systems compute overall organizational risk assessments. This distributed computation strategy maintains high risk assessment quality while distributing computational load, reducing the energy and resource requirements at any single point in the system.
Data Source
AI summary
A system and method are provided for managing data, such as for example security or other business data. For the example of security data, security data is received from a plurality of assets that may or may not be remotely located. A plurality of security metrics are computed and normalized according to thresholds. Security metrics are aggregated to generate an aggregate score, this may include weighting the metrics according to metric priorities. A change effort corresponding to each metric is also received and a corresponding change effort for the aggregate score is calculated. Aggregate scores and aggregate change efforts are analyzed to generate risk reduction recommendations. Upon instruction, metrics corresponding to an aggregate score may be displayed including recommendations of metrics for risk reduction. The recommended metrics may be selected according to analysis of change-to-effort ratios for the metrics.


