Security Management Apparatus for Targeted Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security management approaches consume excessive system resources when deployed in each running environment of applications, especially in distributed systems like cloud computing, making it inefficient to handle advanced targeted attacks such as APTs.

Innovation Solution

A security management method that receives suspected attack alarms from a centralized monitoring apparatus, determines the affected application, and performs behavior analysis only when an alarm is generated, reducing resource consumption by deploying monitoring programs selectively in the affected environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security management apparatus is deployed in each running environment to perform continuous application behavior analysis, then the ability to handle targeted attacks is improved, but system resource consumption increases

Engineering Contradiction:
Improveability to handle targeted attacksVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security management apparatus performs preliminary actions by deploying monitoring programs in running environments before attacks occur. When a suspected attack is detected by the centralized security monitoring apparatus, the system proactively deploys monitoring programs to the affected running environments to perform application behavior analysis, enabling early detection and response to targeted attacks like APTs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts its monitoring deployment based on real-time security conditions. Instead of static continuous monitoring in all environments, the security management apparatus dynamically deploys monitoring programs only to running environments where suspected attacks are detected, optimizing the balance between attack detection capability and resource consumption.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If the security management apparatus is deployed in all running environments, then application behavior analysis coverage is improved, but device complexity increases

Engineering Contradiction:
Improveapplication behavior analysis coverageVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the security monitoring function into two parts: a centralized security monitoring apparatus that handles initial attack detection and a security management apparatus that coordinates monitoring program deployment. This segmentation allows the system to maintain comprehensive coverage by deploying monitoring programs only to specific running environments where attacks are suspected, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security management apparatus acts as an intermediary between the centralized security monitoring apparatus and the running environments. It receives alarm information from the centralized apparatus, determines affected applications, and selectively deploys monitoring programs to appropriate running environments, simplifying the overall system architecture while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12137105B2Security management method and security management apparatus
Publication Date: 2024.11.05 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US12137105B2 patent drawing
  • US12137105B2 patent drawing
  • US12137105B2 patent drawing

AI summary

A security management arrangement for monitoring to detect a targeted attack on an application. Operation of the arrangement includes receiving a suspected attack alarm issued by a centralized security monitoring apparatus. The arrangement determines an application associated with the suspected attack alarm. The arrangement further operates to obtain monitoring information obtained through monitoring of the application. The arrangement further determines, based on the monitoring information, the application has been attacked.