Automatic Service Discovery and Protection System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
System administrators often lack knowledge of all applications accessing sensitive data, leading to vulnerabilities, as seen in the December 2014 JPMorgan breach, where overlooked servers remained vulnerable during two-factor authentication upgrades.
Innovation Solution
A system and method for automatic service discovery and protection, utilizing service discovery modules, a controller, and a database to detect services that benefit from two-factor authentication, notify administrators, and optionally configure two-factor authentication automatically, ensuring proactive security measures across corporate networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If system administrators manually deploy two-factor authentication, then security protection is provided for known applications, but administrators cannot fully protect all applications accessing sensitive data due to lack of knowledge about all services
Solution Approach 1:
The system enables services to automatically register themselves with the two-factor authentication system without administrator intervention. Services publish their own metadata and authentication requirements, allowing the system to self-discover and protect applications that administrators would otherwise be unaware of.
Solution Approach 2:
The system continuously monitors and discovers new services on the network, automatically updating the two-factor authentication configuration based on discovered services. This feedback loop ensures that newly deployed services are automatically identified and protected without requiring administrator knowledge or manual configuration.
2Reliability
If administrators increase monitoring and discovery efforts to find all services, then more services can be protected, but system complexity and administrative burden increase
Solution Approach 1:
Services automatically publish their own metadata, authentication requirements, and service characteristics to the system. This eliminates the need for administrators to manually discover and configure each service, reducing administrative complexity while maintaining comprehensive protection coverage.
Solution Approach 2:
The system combines service discovery, metadata collection, and two-factor authentication configuration into a single automated process. By merging these functions, the system reduces the complexity of multiple separate administrative tasks into one unified automated workflow.
3Reliability
If manual configuration of two-factor authentication is used, then security policies can be applied to known services, but new or overlooked services remain vulnerable as shown in the JPMorgan breach
Solution Approach 1:
The system pre-configures two-factor authentication capabilities and policies in advance, ready to be automatically applied when services are discovered. This preliminary preparation allows immediate protection of new services without delaying service deployment or requiring manual security configuration.
Solution Approach 2:
Services automatically register themselves and receive two-factor authentication configuration without waiting for administrator intervention. This self-service mechanism ensures that security protection is applied as quickly as services are deployed, maintaining both security and deployment productivity.
Data Source
AI summary
A system for automatically discovering services operating on a network including a service discovery database configured to store expected service behavioral characteristics and service identities of the services operating on the network, a set of service discovery modules configured to collect service behavioral data of the services operating on the network, and a service discovery module controller communicatively coupled to the service discovery module database and the set of service discovery modules, the service discovery module controller configured to generate service behavioral characteristics from the service behavioral data, analyze the service behavioral characteristics using the expected service behavioral characteristics, resulting in a first behavioral analysis, identify a first service identity of at least one service operating on the network from the first behavioral analysis and an association of the first service identity and the expected service behavioral characteristics.


