Security Information Plane for Enterprise Cloud Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise clouds face security challenges due to the lack of coordination and correlation of security-relevant information across disparate security mechanisms, leading to ineffective protection against sophisticated attacks and overwhelming false positives from security software, which can result in vulnerability to actual threats.

Innovation Solution

A system that integrates a Security Information Plane (SIP) to aggregate and correlate security-relevant data from various components across the network, using a SIP manager and database to generate network-wide aggregated security information, and a global security endpoint manager to enhance the detection and analysis of security threats by utilizing both local and global security data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security software is deployed at each computing system using local security-relevant data, then security detection capability is improved, but false-positive rate increases and becomes unmanageable

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidfalse-positive rate
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges local security detection capabilities with centralized security-relevant information from across the enterprise cloud. Security software at each computing system combines local analysis with globally correlated security data, allowing false positives to be filtered through cross-system context while maintaining distributed detection coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a centralized security information platform as an intermediary that collects, correlates, and distributes security-relevant information across the enterprise cloud. This mediator enables local security software to access global context without directly communicating with all other systems, reducing false positives through centralized correlation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If piecemeal security solutions are deployed at various locations, then specific security problems are addressed, but coordination and correlation of security information is lost

Engineering Contradiction:
Improvespecific security problem resolutionVSAvoidsecurity information coordination
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent creates a universal security information platform that serves multiple security mechanisms simultaneously. The centralized system collects and correlates security-relevant information from diverse sources (network monitors, firewalls, endpoint security software) and distributes correlated insights back to all components, enabling each to maintain its specialized function while gaining coordinated context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback loops where security information is collected from distributed security mechanisms, correlated centrally, and then fed back to the originating and related security systems. This continuous feedback enables dynamic adjustment of security policies and improves detection accuracy across the entire enterprise cloud.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11316879B2Security protection for a host computer in a computer network using cross-domain security-relevant information
Publication Date: 2022.04.26 VMWARE INC
  • US11316879B2 patent drawing
  • US11316879B2 patent drawing
  • US11316879B2 patent drawing

AI summary

A computer-implemented method and system for protecting a host computer in a computer network from security threats uses local security-relevant data for the host computer, as well as global security-relevant data for other components in the computer network downloaded from a security information plane system to the host computer, to determine a security threat to the host computer. When a security threat is determined to be a legitimate threat, a security alert is issued, and then an action is initiated in response to the security alert.