Sentinel Node System for Near Real-Time Malicious Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As information processing systems grow in size and complexity, identifying and reacting to malicious acts associated with secure information becomes increasingly challenging.

Innovation Solution

A sentinel node system is configured with an emitter portion, sensor portion, filter portion, and reaction portion to dynamically identify and respond to malicious or potentially malicious activities by generating and processing event data in near real-time, allowing users to customize configurations for efficient analysis and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If information processing systems grow in size and complexity to handle more data and operations, then the system's capability to process information increases, but the difficulty of identifying and reacting to malicious acts increases

Engineering Contradiction:
Improveinformation processing capabilityVSAvoiddifficulty of identifying malicious acts
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments the monitoring function into distributed sentinel nodes deployed throughout the information processing system. Each sentinel node independently monitors local events and generates event data, which is then aggregated and analyzed by filter modules. This segmentation allows the system to scale while maintaining detection capability, as each node handles a manageable portion of the overall monitoring task.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces filter modules as intermediary components that receive event data from multiple sentinel nodes and apply filtering algorithms to identify malicious acts. These filter modules act as mediators between the raw event data generation and the final detection/response actions, enabling sophisticated analysis without requiring direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If the system monitors and analyzes all event data in real-time to detect malicious acts, then the detection speed improves, but the computational resources and system complexity increase

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The filter modules apply filtering algorithms that process event data selectively rather than analyzing every single event in detail. The system generates alert data based on filtered and prioritized event data, focusing computational resources on the most suspicious or relevant events. This partial action approach enables near real-time detection while managing computational complexity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The monitoring system is divided into multiple independent sentinel nodes that each generate and filter event data locally before aggregation. This segmentation distributes the computational burden across multiple nodes rather than requiring a single centralized system to process all events, reducing overall system complexity while maintaining detection speed.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If the system generates alert data based on filtered event data to identify malicious acts, then the accuracy of malicious act identification improves, but the time and resources required for analysis increase

Engineering Contradiction:
Improveaccuracy of malicious act identificationVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Sentinel nodes perform preliminary filtering and processing of event data locally before generating alert data. This preliminary action reduces the volume of data requiring detailed analysis and ensures that only pre-processed, relevant events are subjected to more complex filtering algorithms, thereby improving accuracy while minimizing additional analysis time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously generates and processes event data through the filter modules in near real-time, maintaining a continuous flow of analysis rather than batch processing. This continuous action ensures that malicious acts are identified as quickly as they occur, balancing accuracy with minimal time loss.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9154515B1Systems and methods identifying and reacting to potentially malicious activity
Publication Date: 2015.10.06 AMAZON TECH INC
  • US9154515B1 patent drawing
  • US9154515B1 patent drawing
  • US9154515B1 patent drawing

AI summary

Information security may include defending information from unauthorized access, use, disclosure, modification, destruction, and so forth. Described herein are systems, methods and devices for enabling a user device to implement functions for dynamically identifying and reacting to potentially malicious activity. In one example, a user device configures a sentinel node to identify potentially malicious behavior by causing the sentinel node to analyze data from selected emitter nodes and selected algorithms. The user device may also specify how the sentinel node reacts to potential malicious activity.