Federated Security Analytics Using Swarm Nodes for Scalable Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security techniques face challenges with scalability, accuracy, and high computational and memory requirements due to overwhelming volumes of security event data, leading to inefficient detection and remediation of security events.

Innovation Solution

A swarm system architecture is employed for federated distributed security analytics, utilizing transformation and control plane components at different levels to process and analyze security event data, reducing computational complexity and memory usage by distributing the workload across nodes with varying capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a centralized service is used to analyze security event data, then comprehensive security analysis can be achieved, but storage requirements become overwhelming and scalability is limited

Engineering Contradiction:
Improvesecurity event detection accuracyVSAvoidstorage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent divides the centralized security analytics system into distributed swarm nodes that process security event data locally. Each node segments the overall computational workload, allowing comprehensive security analysis to be performed distributed across multiple devices rather than requiring centralized storage of all raw data. This segmentation reduces storage requirements while maintaining detection accuracy through collaborative analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional centralized architecture to a multi-dimensional distributed swarm architecture. By adding the spatial dimension of distribution across multiple nodes, the system achieves comprehensive security analysis without overwhelming centralized storage, as each node contributes its local processing capabilities to the collective intelligence of the swarm.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If all security event data is collected and stored for analysis, then a complete security picture can be obtained, but the time penalty for processing increases

Engineering Contradiction:
Improvesecurity landscape visibilityVSAvoiddetection and response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having swarm nodes perform local preprocessing and filtering of security event data before it needs to be aggregated. Nodes pre-compute security signals and pre-filter noise from raw events, so when data is collected centrally, the processing time is reduced because the heavy lifting of initial analysis has already been performed distributed across the swarm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables skipping of unnecessary processing steps by having distributed nodes perform local filtering and signal generation. This allows the system to rush through the analysis pipeline more efficiently, obtaining complete security visibility without the time penalty of processing all raw data centrally, as noise and irrelevant events are filtered out at the edge nodes.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Measurement precision

If comprehensive security event analysis is performed centrally, then accurate security outcomes are produced, but computational resources and costs increase significantly

Engineering Contradiction:
Improvesecurity event detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the computational workload of security event analysis across distributed swarm nodes rather than concentrating it centrally. Each node performs local analysis of security events in its domain, dividing the overall computational complexity into manageable pieces that can be processed in parallel, reducing the computational burden on any single device while maintaining accurate security detection through collective intelligence.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260046295A1Scalable federated distributed security analytics
Publication Date: 2026.02.12 CISCO TECHNOLOGY INC
  • US20260046295A1 patent drawing
  • US20260046295A1 patent drawing
  • US20260046295A1 patent drawing

AI summary

Techniques for federated distributed security analytics using a swarm node framework to provide a scalable way to improve efficiency and accuracy of determining and remediating security threats, while reducing computational complexity and resource usage of a system. A system may comprise node(s) executing a first engine and a second engine. The first engine may operate in a data plane and receive event data associated with security events, perform a specialized type of function, and generate two classes of output(s): (1) transformed event data output to other first engine(s) of other node(s) and (2) security signal(s) output to the second engine. The second engine may be configured to operate in a control plane. The second engine may receive input(s), including the security signal(s) and determine action(s) to perform with regard to security event(s). The second engine may output instruction(s) to other node(s) and/or derived security signal(s) to other second engine(s).