Threat Intelligence Service Integration in Disaster Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Executing threat intelligence tests on actual computing systems is disruptive and resource-intensive, impacting system performance and user convenience.
Innovation Solution
Integrating a threat intelligence service into existing disaster recovery solutions to perform threat intelligence tests on system images, leveraging disaster recovery platforms to identify known cybersecurity threats and anomalous activity within isolated restored image environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If threat intelligence tests are executed on actual computing systems, then threat detection capability is improved, but system performance deteriorates and resource consumption increases
Solution Approach 1:
The patent creates a virtual copy (virtual machine) of the actual computing system to perform threat intelligence tests. This copy includes replicated file systems, registry hives, and system configurations that mirror the production environment. By executing tests on this virtual copy rather than the actual system, the patent achieves thorough threat detection while preventing performance degradation and resource consumption on the production system.
Solution Approach 2:
The patent segments the testing function from the production system by creating a separate virtual machine environment. This segmentation allows threat intelligence tests to run in isolation on the virtual copy, preventing interference with the actual computing system's performance while maintaining the ability to detect threats through the replicated system structures.
2Reliability
If threat intelligence tests are executed on actual computing systems, then threat detection capability is improved, but user convenience deteriorates
Solution Approach 1:
By creating a virtual copy of the computing system, the patent enables threat testing without requiring users to experience the disruptions that would occur during actual system testing. Users continue to access and operate their systems normally while threat intelligence tests run independently on the virtual replica, maintaining user convenience while achieving comprehensive threat detection.
3Reliability
If threat intelligence tests are executed on actual computing systems, then threat detection capability is improved, but resource consumption increases
Solution Approach 1:
The patent creates a virtual machine that replicates essential system components (file systems, registry hives, system configurations) rather than duplicating the entire physical infrastructure. This selective copying approach enables comprehensive threat intelligence testing while consuming fewer computing resources compared to running equivalent tests directly on the production system, as the virtual environment can be optimized and isolated from production resource constraints.
Data Source
AI summary
A method and system for implementing threat intelligence as a service in a cloud computing environment. Specifically, the disclosed method and system entail leveraging existing disaster recovery (DR) solutions to perform threat intelligence tests and identify known cyber security threats and/or anomalous activity instigated by unknown cyber security threats, if any, on system images backed up on the existing DR solution. In leveraging existing DR solutions, a threat intelligence service is integrated into the existing DR solution as an additional feature.


