Network Activity Detector Configuration via UDP Peer-to-Peer Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital security technologies face challenges in scalability and configurability due to large virus signature files, which consume significant network bandwidth and processing power, and require centralized update control, limiting their effectiveness and flexibility in managing network activity detectors across diverse network nodes.

Innovation Solution

A system of network activity detectors that utilize User Datagram Protocol (UDP) packets to request and share configuration information for detecting digital security threats, allowing for decentralized management and consistent configuration settings across network nodes, enhancing scalability and configurability while minimizing bandwidth and processing overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional digital security technologies use large virus signature files for updates, then detection effectiveness is improved, but network bandwidth consumption increases and scalability deteriorates

Engineering Contradiction:
Improvedetection effectivenessVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the centralized update model into a distributed peer-to-peer configuration dissemination model. Instead of all nodes downloading from a central server, configuration information is propagated through the network using epidemic algorithms, where each node acts as both receiver and distributor. This segmentation reduces the load on any single server and improves overall system scalability while maintaining effective threat detection through consistent configuration updates.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional digital security technologies use large virus signature files, then detection effectiveness is improved, but processing power requirements increase

Engineering Contradiction:
Improvedetection effectivenessVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts the configuration management function from the core virus detection engine. By separating configuration dissemination from actual threat detection operations, the system allows nodes to receive and process only the necessary configuration information through lightweight epidemic algorithms, while the heavy lifting of virus detection is handled by the extracted detection engine. This extraction reduces processing power requirements for configuration updates while maintaining detection effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If centralized update control is used to ensure authenticity, then security is improved, but configurability for local networks deteriorates

Engineering Contradiction:
Improveupdate authenticityVSAvoidconfigurability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic configuration management system where nodes can operate in different modes. In high-security environments, nodes can verify configurations through cryptographic signatures from trusted authorities. In local network scenarios, nodes can dynamically switch to accepting configurations from peer nodes within the same network. This dynamic adaptability allows the system to maintain update authenticity through multiple mechanisms while providing configurability for different operational contexts.

Inventive Principle:
Principle #15Dynamics

4Device complexity

If a flat network architecture with few authorized servers is used, then update control is simplified, but ability to provide unique local configurations deteriorates

Engineering Contradiction:
Improveupdate control complexityVSAvoidlocal configuration capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent enables nodes to serve themselves and their peers in the configuration dissemination process. Each node that receives configuration information automatically becomes a source for other nodes, eliminating the need for a hierarchical structure with dedicated authorized servers. This self-service approach simplifies the overall architecture by making every node equally capable of both consuming and distributing configurations, while simultaneously enabling local networks to generate and share their own unique configurations without external intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10440038B2Configuration management for network activity detectors
Publication Date: 2019.10.08 SECURESKY INC
  • US10440038B2 patent drawing
  • US10440038B2 patent drawing
  • US10440038B2 patent drawing

AI summary

Network activity detectors, such as firewalls, communicate with one another to form a Unified Threat Management System. A first network activity detector sends a request for configuration settings to a second network activity detector. The second network activity detector sends a set of configuration settings in response to the request. The configuration settings include information for detecting digital security threats and/or for responding to detected digital security threats. In this way, configuration settings are propagated from one network activity detector to another so that network activity detectors within a UTMS system are configured consistently, e.g., have up-to-date information for detecting and/or responding to digital security threats.