Threat Intelligence Cloud for Real-Time Customized Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in effectively detecting and responding to unknown threats and variations of known threats due to universal, non-customized IPS signatures and the lack of global intelligence integration, leading to delayed manual adjustments that can allow infections to spread.
Innovation Solution
A system and method that correlates global threat intelligence with local intelligence through a threat intelligence cloud and event analysis sub-cloud, providing real-time customized security policies and updates to sensors and hosts, enabling proactive threat detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If universal IPS signatures are used for threat detection, then broad coverage is achieved, but detection precision for unknown and variant threats deteriorates
Solution Approach 1:
The patent segments the monolithic IPS signature system into hierarchical components: universal signatures for broad coverage, customized signatures for specific threats, and behavioral analysis for unknown threats. This segmentation allows each component to operate at its optimal level, resolving the contradiction between broad coverage and detection precision.
Solution Approach 2:
The system performs preliminary actions by proactively generating customized signatures and updating sensors before threats fully propagate. Threat intelligence is collected and analyzed in advance, enabling preemptive deployment of targeted detection rules that improve precision without sacrificing broad coverage.
2Adaptability or versatility
If manual adjustments are made to security policies, then customization is achieved, but response time deteriorates
Solution Approach 1:
The system implements self-service through automated signature generation and policy adjustment mechanisms. When threats are detected, the system automatically generates customized signatures and pushes updates to sensors without requiring manual administrator intervention, thereby achieving both customization and rapid response time.
Solution Approach 2:
The system establishes feedback loops where threat detection results automatically trigger signature generation and policy updates. This closed-loop feedback mechanism enables continuous adaptation to new threats while maintaining rapid response times, eliminating the delay inherent in manual adjustment processes.
3Reliability
If global intelligence integration is implemented, then threat detection capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces an event analysis sub-cloud as an intermediary layer between local sensors and the global threat intelligence cloud. This intermediary aggregates events locally, performs preliminary analysis, and only transmits relevant information globally, thereby improving threat detection capability while managing system complexity through hierarchical abstraction.
4Reliability
If real-time updates are pushed to sensors, then protection effectiveness is improved, but network bandwidth consumption increases
Solution Approach 1:
The system applies partial updates by pushing only the specific signature changes and threat intelligence relevant to each sensor's context, rather than transmitting complete policy sets. This selective update approach maintains protection effectiveness while significantly reducing network bandwidth consumption compared to full system updates.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method is provided in one example embodiment that includes receiving event information associated with reports from sensors distributed throughout a network environment and correlating the event information to identify a threat. A customized security policy based on the threat may be sent to the sensors.