Network Security Event Sharing via Centralized Repository
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Private networks face challenges in detecting and mitigating attacks due to the complexity of integrating disparate security products from different vendors, lack of mechanisms for sharing security event information, and the reluctance of providers to expose vulnerabilities by sharing risk data.
Innovation Solution
A system that enables sharing of network security event information through a centralized repository, using a common communication framework and caching protocol to facilitate interoperability between different security products, allowing for real-time and asynchronous responses, and enabling dynamic scaling of security services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security providers share security event information, then network security detection capability is improved, but providers risk exposing vulnerabilities and sensitive information
Solution Approach 1:
The patent introduces a centralized repository as an intermediary component that mediates between network security providers. This repository collects, stores, and distributes security event information in a controlled manner, allowing providers to benefit from shared intelligence without directly exposing their internal systems or vulnerabilities to each other. The intermediary structure enables information sharing while maintaining security boundaries.
2Adaptability or versatility
If disparate security products from different vendors are integrated, then comprehensive security coverage is achieved, but system complexity and integration difficulty increase
Solution Approach 1:
The patent implements a universal communication framework that enables disparate security products from different vendors to interoperate through standardized protocols and data formats. This framework provides multi-functional capability by supporting multiple security tools and vendors through a single integration interface, thereby achieving comprehensive security coverage without proportionally increasing integration complexity.
Solution Approach 2:
The patent applies homogeneity by standardizing the communication protocols, data formats, and interaction mechanisms across the security system. By making the integration interface homogeneous and consistent, the system reduces the complexity of integrating disparate products, as all vendors can adhere to the same standardized framework rather than requiring custom integration for each product pair.
3Reliability
If security providers manually interpret and deploy security systems, then specialized expertise is utilized, but deployment time and operational overhead increase
Solution Approach 1:
The patent implements self-service capabilities that allow security systems to automatically interpret, analyze, and deploy security measures without requiring constant manual intervention from specialized personnel. The system includes automated threat detection, analysis, and response mechanisms that can independently execute security operations, thereby reducing deployment time and operational overhead while maintaining reliable security protection.
Solution Approach 2:
The patent applies preliminary action by pre-configuring security policies, rules, and response mechanisms that can be automatically activated when threats are detected. This pre-prepared framework enables the system to respond rapidly to security events without requiring time-consuming manual analysis and deployment decisions, thus reducing deployment time while maintaining accurate security enforcement.
4Adaptability or versatility
If security systems are incrementally added based on dynamic need, then flexibility is achieved, but architecture efficiency deteriorates due to hodge-podge systems
Solution Approach 1:
The patent applies segmentation by dividing the security system into modular, independently deployable components that can be incrementally added based on dynamic needs. Each module functions as a self-contained unit with standardized interfaces, allowing flexible expansion while maintaining overall system efficiency. This segmented architecture prevents the creation of a hodge-podge system by ensuring that each added component integrates cleanly through the universal framework.
Solution Approach 2:
The patent implements dynamics by designing a security architecture that can dynamically adapt and scale based on changing requirements. The system allows components to be added, removed, or modified in real-time while maintaining operational efficiency through the standardized communication framework. This dynamic capability enables flexibility without sacrificing architecture efficiency, as the system can evolve organically while preserving overall structural coherence.
Data Source
AI summary
This disclosure provides an architecture for sharing information between network security administrators. Events converted to a normalized data format (CCF) are stored in a manner that can be queried by a third party (e.g., an administrator of another, trusted network). Optionally made available as a service, stored event records can be sanitized for third party queries (e.g., by clients of a service maintaining such a repository). In one embodiment, each contributing network encrypts or signs its (sanitized) records using a symmetric key architecture, the key being unique to the contributing network. This key is used (e.g., by the repository) to index a set of permissions or conditions of the contributing network in servicing any query, e.g., by matching a stored hash of the event record or by decrypting the record. The information sharing service can optionally be provided by a hosted information security service or on a peer-to-peer basis.


