Network Security Event Sharing via Centralized Repository

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Private networks face challenges in detecting and mitigating attacks due to the complexity of integrating disparate security products from different vendors, lack of mechanisms for sharing security event information, and the reluctance of providers to expose vulnerabilities by sharing risk data.

Innovation Solution

A system that enables sharing of network security event information through a centralized repository, using a common communication framework and caching protocol to facilitate interoperability between different security products, allowing for real-time and asynchronous responses, and enabling dynamic scaling of security services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security providers share security event information, then network security detection capability is improved, but providers risk exposing vulnerabilities and sensitive information

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidexposure of vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a centralized repository as an intermediary component that mediates between network security providers. This repository collects, stores, and distributes security event information in a controlled manner, allowing providers to benefit from shared intelligence without directly exposing their internal systems or vulnerabilities to each other. The intermediary structure enables information sharing while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If disparate security products from different vendors are integrated, then comprehensive security coverage is achieved, but system complexity and integration difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal communication framework that enables disparate security products from different vendors to interoperate through standardized protocols and data formats. This framework provides multi-functional capability by supporting multiple security tools and vendors through a single integration interface, thereby achieving comprehensive security coverage without proportionally increasing integration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies homogeneity by standardizing the communication protocols, data formats, and interaction mechanisms across the security system. By making the integration interface homogeneous and consistent, the system reduces the complexity of integrating disparate products, as all vendors can adhere to the same standardized framework rather than requiring custom integration for each product pair.

Inventive Principle:
Principle #33Homogeneity

3Reliability

If security providers manually interpret and deploy security systems, then specialized expertise is utilized, but deployment time and operational overhead increase

Engineering Contradiction:
Improvesecurity system accuracyVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service capabilities that allow security systems to automatically interpret, analyze, and deploy security measures without requiring constant manual intervention from specialized personnel. The system includes automated threat detection, analysis, and response mechanisms that can independently execute security operations, thereby reducing deployment time and operational overhead while maintaining reliable security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring security policies, rules, and response mechanisms that can be automatically activated when threats are detected. This pre-prepared framework enables the system to respond rapidly to security events without requiring time-consuming manual analysis and deployment decisions, thus reducing deployment time while maintaining accurate security enforcement.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If security systems are incrementally added based on dynamic need, then flexibility is achieved, but architecture efficiency deteriorates due to hodge-podge systems

Engineering Contradiction:
Improvesystem flexibilityVSAvoidarchitecture efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies segmentation by dividing the security system into modular, independently deployable components that can be incrementally added based on dynamic needs. Each module functions as a self-contained unit with standardized interfaces, allowing flexible expansion while maintaining overall system efficiency. This segmented architecture prevents the creation of a hodge-podge system by ensuring that each added component integrates cleanly through the universal framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamics by designing a security architecture that can dynamically adapt and scale based on changing requirements. The system allows components to be added, removed, or modified in real-time while maintaining operational efficiency through the standardized communication framework. This dynamic capability enables flexibility without sacrificing architecture efficiency, as the system can evolve organically while preserving overall structural coherence.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10412103B2Techniques for sharing network security event information
Publication Date: 2019.09.10 SERVICENOW INC
  • US10412103B2 patent drawing
  • US10412103B2 patent drawing
  • US10412103B2 patent drawing

AI summary

This disclosure provides an architecture for sharing information between network security administrators. Events converted to a normalized data format (CCF) are stored in a manner that can be queried by a third party (e.g., an administrator of another, trusted network). Optionally made available as a service, stored event records can be sanitized for third party queries (e.g., by clients of a service maintaining such a repository). In one embodiment, each contributing network encrypts or signs its (sanitized) records using a symmetric key architecture, the key being unique to the contributing network. This key is used (e.g., by the repository) to index a set of permissions or conditions of the contributing network in servicing any query, e.g., by matching a stored hash of the event record or by decrypting the record. The information sharing service can optionally be provided by a hosted information security service or on a peer-to-peer basis.