A zero-trust authentication system based on EDR

Through the EDR-based zero-trust authentication system, the problem of insufficient information acquisition granularity in zero-trust technology is solved, the reliability of extensive security information collection and behavior analysis is achieved, and the strategy is dynamically adjusted to optimize network security.

CN118784349BActive Publication Date: 2025-07-25CHINESE PEOPLES LIBERATION ARMY UNIT 61660
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411062288.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2025-07-25
Estimated Expiration
2044-08-05

AI Technical Summary

Technical Problem

The existing zero-trust technology has insufficient information acquisition granularity and resource management problems in user behavior abnormality detection, and lacks spatial and temporal state correlation mapping, resulting in frequent missed detection.

Method used

The EDR-based zero-trust authentication system is adopted, including the data acquisition layer, the data analysis layer and the trust authentication layer. Data acquisition, classification and aggregation are carried out through the EDR terminal and the analysis engine, and security status evaluation and resource access control are carried out in combination with the zero-trust system.

Benefits of technology

A wide range of security information collection is achieved, the reliability of behavioral analysis and resource management flexibility is enhanced, and policies are dynamically adjusted to optimize network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118784349B_ABST
    Figure CN118784349B_ABST
Patent Text Reader

Abstract

The present invention relates to a zero-trust authentication system based on EDR and belongs to the field of network security. The system of the present invention includes three levels, from bottom to top: a data collection layer, a data parsing layer, and a trust authentication layer; the data collection layer consists of EDR terminals, and the EDR terminals are deployed on various servers and hosts to provide the collection of detailed information on different types of terminal data; the data parsing layer consists of EDR analysis engines to realize the classification and aggregation of data and to realize data governance and behavior analysis; the trust authentication layer further analyzes the results of the data parsing layer, takes identity and behavior as the main body, constructs a security status assessment of each terminal node through the parsing and judgment of the collected data, and authenticates and authorizes all users and devices based on the characteristics of the zero-trust system. The trust evaluation layer of the present invention provides behavior authentication and authorization of the zero-trust system, and further strengthens the reliability of trust authentication in combination with the conclusions of the data parsing layer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and particularly relates to a zero-trust authentication system based on EDR. Background Art

[0002] For the existing extraction of user behaviors in zero-trust technology, it mainly focuses on the coarse-grained extraction of user behavior sequence features, lacking consideration of the spatio-temporal state of user behaviors, which leads to a large number of missed detections when the system performs anomaly detection on user behaviors. It is necessary to associate and map a large range of spatio-temporal state information and behavior types. Secondly, it is necessary to perform clustering analysis on user behaviors, identify behaviors from the perspective of multi-host spatio-temporal, and summarize and converge behavior information to achieve a wider range of information parsing. To solve the problem of insufficient acquisition granularity of zero-trust technology and improve the information breadth of user behaviors, the endpoint detection and response technology is combined with it to make up for the problems of zero-trust technology.

[0003] The endpoint detection and response technology, abbreviated as EDR, is a new generation of endpoint security product driven by threat intelligence, with the characteristics of accurate detection, rapid traceability, and efficient operation and maintenance. In terms of attack discovery, EDR has fine-grained dynamic behavior recognition integrating situation awareness and traceability analysis, actively discovers APT persistent attack behaviors, and comprehensively responds to network threats. The endpoint detection and response technology processes and analyzes the results of user behaviors through EDR endpoints and analysis engines, continuously collects user behavior information, provides a data basis for the trust assessment of zero-trust, and at the same time, the trust assessment results and access control results of zero-trust technology can also be issued as policies to EDR endpoints. The present invention proposes a zero-trust authentication system based on EDR, inheriting the advantages of traditional EDR, solving the problems that occur in the process of zero-trust system obtaining information, solving the resource management problem, and constructing a trust system. Summary of the Invention

[0004] (1) Technical Problems to be Solved

[0005] The technical problem to be solved by the present invention is how to provide a zero-trust authentication system based on EDR to solve the problem of insufficient acquisition granularity of zero-trust technology and the problem of constructing a loop of trust authentication and resource acquisition.

[0006] (2) Technical Solutions

[0007] To solve the above technical problems, the present invention proposes a zero-trust authentication system based on EDR. The system includes three levels, from bottom to top: the data collection layer, the data parsing layer, and the trust authentication layer;

[0008] The data collection layer is composed of EDR terminals. EDR terminals are deployed on various servers and hosts to provide detailed information collection of different types of terminal data. Some malicious behaviors that can be identified on the EDR terminals directly generate alarm information and report it to the EDR analysis engine, and provide traceability data.

[0009] The data analysis layer, composed of the EDR analysis engine, realizes the classification and aggregation of data, realizes data governance and behavior analysis, and extracts key information from a series of user behaviors and aggregates them into a behavior chain by building an attack chain to analyze user malicious behaviors. The data analysis layer directly interacts with the collected data to realize unified analysis and behavior construction of various types of data in the data collection layer.

[0010] The trust authentication layer further analyzes the results of the data parsing layer, taking identity and behavior as the main body, and constructs a security status assessment of each terminal node through analysis and judgment of the collected data. All users and devices are authenticated and authorized based on the characteristics of the zero-trust system, and the EDR analysis results are used as one of the bases for acceptance; each device is analyzed through the zero-trust system to find out the weak points of the entire network.

[0011] (III) Beneficial effects

[0012] The present invention proposes a zero-trust authentication system based on EDR. Compared with the prior art, the present invention has the following advantages:

[0013] 1. The data collection layer provides collected data covering a wide range of security information resources, with rich content and easy expansion, to achieve application scenarios in which software and hardware security functions are combined.

[0014] 2. The data parsing layer provides microservice-based incremental updates, which reduces resource overhead when updating configuration and dependent libraries.

[0015] 3. The trust assessment layer provides behavioral authentication and authorization for the zero-trust system, and combines the conclusions of the data analysis layer to further enhance the reliability of trust authentication.

[0016] 4. The trust assessment layer conducts trust assessment on the entire terminal based on zero-trust authentication, provides analysis and verification of problems within the network, dynamically adjusts strategies, and achieves network security optimization. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is the EDR-based zero-trust authentication system of the present invention;

[0018] Figure 2 It is a trust evaluation sequence diagram of the present invention;

[0019] Figure 3 A flow chart for dynamically adjusting the security policy of the present invention;

[0020] Figure 4 This is the flowchart for discovering weak points in the network of the present invention. Specific implementation manners

[0021] To make the objectives, content and advantages of the present invention clearer, the following further describes in detail the specific implementation manners of the present invention with reference to the accompanying drawings and embodiments.

[0022] The present invention relates to a zero-trust authentication system based on EDR. The zero-trust authentication system based on EDR consists of three levels, from bottom to top: a data collection layer responsible for collecting various data information of server hosts, a data parsing layer responsible for behavior recognition and data cleaning of the collected data, and a trust authentication layer responsible for zero-trust evaluation and access control.

[0023] The zero-trust authentication system based on EDR follows the standard EDR architecture and consists of an EDR terminal and an EDR analysis engine, realizing the analysis and traceability of the host data collected by the EDR terminal. The collection of the EDR terminal and the EDR analysis are separated from each other. Combining the zero-trust system, further evaluation is carried out based on the data collected by the EDR and the EDR analysis results, and the access to resources is controlled and managed. As an important part of the system, the data collection layer provides the collection of detailed information of different types of data such as terminal login information, processes, services, startup items, registry, network connection information, files, software, system logs, mobile storage medium usage information, and alarm information; the data parsing layer realizes the classification and aggregation of data, realizes the data governance work, and provides a basis for behavior analysis. Among them, the data parsing layer directly interacts with the collected data to realize the unified parsing and behavior construction of various types of data in the data collection layer; the trust authentication layer further analyzes the results of the data parsing, takes identity and behavior as the main body, estimates the security status of each terminal through the parsing and judgment of the collected data, and issues the resource access control policy for the EDR terminal based on the trust evaluation value.

[0024] The present invention proposes a zero-trust authentication system based on EDR, including three levels, from bottom to top: a data collection layer, a data parsing layer, and a trust authentication layer.

[0025] The data collection layer consists of EDR terminals. The EDR terminals are deployed on each server and host, providing the collection of detailed information of different types of terminal data such as terminal login information, processes, services, startup items, registry, network connection information, files, software, system logs, mobile storage medium usage information, and alarm information. Some malicious behaviors that can be determined on the EDR terminal, such as unauthorized access, can directly generate alarm information and report it to the EDR analysis engine, and give traceability data;

[0026] The data analysis layer, composed of the EDR analysis engine, realizes the classification and aggregation of data, realizes data governance and behavioral analysis, and extracts key information from a series of user behaviors and aggregates it into a behavioral chain by building an attack chain to analyze user malicious behaviors.

[0027] Among them, the data analysis layer directly interacts with the collected data to achieve unified analysis and behavior construction of various types of data in the data collection layer;

[0028] Among them, the EDR analysis engine classifies different types of terminal data collected by the EDR terminal, such as login information, processes, services, startup items, registries, network connection information, files, software, system logs, mobile storage media usage information, alarm information, etc., and performs correlation analysis to obtain correlation clues such as processes and network sockets, processes and files, processes and system calls, processes and users, etc., analyzes their correlation from the perspective of multiple terminals, and then obtains the attack behavior correlation between terminals, and conducts qualitative and definition analysis on a series of suspicious behaviors, clusters them, sorts out the behavior chain and displays complete attack surface information.

[0029] The trust authentication layer further analyzes the results of the data analysis layer, taking identity and behavior as the main body, and constructs a security status assessment of each terminal node through the analysis and judgment of the collected data. All users and devices are authenticated and authorized based on the characteristics of the zero-trust system, and the EDR analysis results are used as one of the bases for acceptance. Through the zero-trust system, each device is analyzed to find out the weaknesses of the entire network, strengthen the system construction of the network, and further enhance the ability of the authentication system to discover problems.

[0030] Among them, the trust authentication layer judges user behavior based on the EDR analysis results, detects whether each user operation behavior is under the zero trust system, whether it passes the zero trust verification, and conducts a trust assessment on the user behavior analysis; based on the trust assessment results, each terminal is analyzed and calculated through the zero trust system to determine whether the terminal behavior is trustworthy and dynamically adjust its security policy; based on the evaluation of the trust status of all EDR terminals, the weak links in the network are discovered, the network system construction is strengthened, and the ability of the authentication system to discover problems is further enhanced.

[0031] According to an embodiment of the EDR-based zero-trust authentication system of the present invention, the user behavior is judged according to the EDR analysis result, whether each operation behavior of the user is in the zero-trust system and whether it passes the zero-trust verification, and the trust evaluation of the user behavior analysis includes the following steps:

[0032] S11, the data collection layer obtains terminal data through the EDR terminal;

[0033] S12. Transfer the data to the EDR analysis engine for data analysis;

[0034] S13. The trust authentication layer obtains the data analysis results of the EDR analysis engine and the data acquisition layer traceability data of the relevant analysis results;

[0035] S14. For any user behavior, determine whether it passes the zero-trust authentication check;

[0036] S15. The trust authentication layer conducts a trust assessment on all user operations within the EDR terminal based on whether the determination result of the user operation is an alarm event, and obtains the trust assessment value of the EDR terminal.

[0037] According to an embodiment of the zero-trust authentication system based on EDR of the present invention, wherein according to the trust assessment result, each terminal is analyzed and calculated through the zero-trust system to determine whether the terminal behavior is trustworthy and dynamically adjust its security policy, including the following steps:

[0038] S21. The trust authentication layer obtains the alarm information of the data parsing layer;

[0039] S22. Trace the alarm information, obtain the collected data of the data acquisition layer based on the subject, object and time elements, and based on the alarm result of the EDR analysis engine, determine the corresponding terminal of the alarm information, and determine whether various behaviors of the terminal pass the zero-trust authentication;

[0040] S23. If it does not pass the zero-trust authentication, judge according to the authentication and authorization situation and adjust its trust assessment value; if there is a threat event, reduce the credibility of the terminal, and if there is no threat event within a certain period of time, increase the terminal credibility.

[0041] S24. Based on the change in the trust assessment of the EDR terminal, the zero-trust authentication system modifies the resource access control policy of the EDR terminal, so that highly trusted terminals can obtain more and better resources.

[0042] According to an embodiment of the zero-trust authentication system based on EDR of the present invention, wherein, the steps of discovering weak links in the network according to the trust status assessment of all EDR terminals include:

[0043] S31. The trust authentication layer obtains the list of EDR terminals;

[0044] S32. Based on the zero-trust verification result of the EDR terminal behavior, read the trust assessment values of all current EDR terminals;

[0045] S33. Based on the trust assessment values of the EDR terminals, conduct a risk analysis on all EDR terminals and draw the situation distribution of the overall network;

[0046] S34. Based on the events occurring at each EDR terminal, EDR terminals with lower trust assessment values are considered weak devices, and weak network intervals are marked and rectification suggestions are given.

[0047] Embodiment 1:

[0048] The present invention provides an EDR-based zero-trust authentication system, which is built based on the traditional EDR analysis engine architecture standard. On this basis, the zero-trust system is built by combining the EDR terminal collection data and the EDR engine analysis results. The system is divided into a three-level structure, which is respectively a data collection layer, a data analysis layer and a trust authentication layer from bottom to top.

[0049] Among them, the data collection layer is composed of EDR terminals, which are deployed on various servers and hosts. They provide collection of different types of data detailed information such as terminal login information, processes, services, startup items, registry, network connection information, files, software, system logs, mobile storage media usage information, alarm information, etc. Some malicious behaviors that can be identified on the EDR terminal, such as unauthorized behavior, can directly generate alarm information and report it to the EDR analysis engine, and provide traceability data.

[0050] The data analysis layer is composed of the EDR analysis engine, which realizes the classification and aggregation of data, realizes data governance and behavior analysis, and extracts key information from a series of user behaviors and aggregates them into a behavior chain by building an attack chain to analyze user malicious behaviors. The data analysis layer directly interacts with the collected data to realize the unified analysis and behavior construction of various types of data in the data collection layer.

[0051] The trust authentication layer further analyzes the results of the data analysis layer, taking identity and behavior as the main body, and constructs a security status assessment of each terminal node through analysis and judgment of the collected data. All users and devices are authenticated and authorized based on the characteristics of the zero-trust system, and the EDR analysis results are used as one of the bases for acceptance. Through the zero-trust system, each device is analyzed to find out the weaknesses of the entire network, strengthen the system construction of the network, and further enhance the ability of the authentication system to discover problems.

[0052] Furthermore, the types of resources are gathered. Different from the traditional software-defined system, this system comprehensively considers the data fields required by terminal detection and response technology and zero-trust technology. The data collection layer collects all kinds of fields in an all-round way, and also includes lightweight virtualization containers, virtual machines, peripherals, etc. in the overall scope of data collection, so that the data collection layer can meet the comprehensive detection and analysis of user behavior, and further provide support for data analysis.

[0053] Furthermore, the data analysis layer that directly interacts with data collection uses the collected data as a basis, further splits the behavior information according to the type, builds a behavior chain, and aggregates the various preparation steps, operations, permission settings, links, accessed files and other information of the behavior into an attack chain, and analyzes whether it is malicious behavior. The data analysis layer incrementally updates the configuration and dependency library based on microservices, which reduces the resource overhead when updating the configuration and dependency library. The data analysis layer provides data analysis results and data collection traceability interfaces for use by the trust authentication layer.

[0054] Furthermore, in addition to traditional zero-trust authentication, EDR-based behavioral analysis results are added to zero-trust as the basis for zero-trust authentication. On this basis, the issue of data collection of zero-trust technology is supplemented, and the authentication and authorization of EDR terminals are guaranteed in real time through zero-trust authentication, and the behavioral analysis of authorized content of zero-trust is strengthened to find hidden security issues. By generating a trust evaluation value for trust authentication, the overall network situation is displayed based on the analysis of each terminal, and network weaknesses are marked, displayed, and rectified.

[0055] Compared with the prior art, the present invention has the following advantages:

[0056] 1. The data collection layer provides collected data covering a wide range of security information resources, with rich content and easy expansion, to achieve application scenarios in which software and hardware security functions are combined.

[0057] 2. The data parsing layer provides microservice-based incremental updates, which reduces resource overhead when updating configuration and dependent libraries.

[0058] 3. The trust assessment layer provides behavioral authentication and authorization for the zero-trust system, and combines the conclusions of the data analysis layer to further enhance the reliability of trust authentication.

[0059] 4. The trust assessment layer conducts trust assessment on the entire terminal based on zero-trust authentication, provides analysis and verification of problems within the network, dynamically adjusts strategies, and achieves network security optimization.

[0060] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A zero-trust authentication system based on EDR, characterized in that, The system consists of three layers, from bottom to top: data collection layer, data analysis layer and trust authentication layer; The data collection layer is composed of EDR terminals. EDR terminals are deployed on various servers and hosts to provide detailed information collection of different types of terminal data. Some malicious behaviors that can be identified on the EDR terminals directly generate alarm information and report it to the EDR analysis engine, and provide traceability data. The data analysis layer, which consists of the EDR analysis engine, realizes data classification and aggregation, data governance and behavior analysis. By building an attack chain, it extracts key information from a series of user behaviors and aggregates it into a behavior chain to analyze user malicious behaviors. The data analysis layer directly interacts with the collected data to achieve unified analysis and behavior construction of various types of data in the data collection layer; The trust authentication layer further analyzes the results of the data analysis layer, taking identity and behavior as the main body, and constructs a security status assessment of each terminal node through the analysis and judgment of the collected data. All users and devices are authenticated and authorized based on the characteristics of the zero-trust system, and the EDR analysis results are used as one of the basis for acceptance; each device is analyzed through the zero-trust system to find out the weaknesses of the entire network; in, The EDR analysis engine classifies different types of terminal data collected by the EDR terminal, and performs correlation analysis to obtain clues of association between processes and network sockets, processes and files, processes and system calls, and processes and users, analyzes their correlation from the perspective of multiple terminals, and then obtains the attack behavior association between terminals, and conducts qualitative and definition analysis on a series of suspicious behaviors, clusters them, sorts out the behavior chain and displays complete attack surface information; The trust authentication layer determines user behavior based on the EDR analysis results, detects whether each user operation behavior is under the zero trust system, whether it has passed the zero trust verification, and performs a trust assessment on the user behavior analysis; based on the trust assessment results, each terminal is analyzed and calculated through the zero trust system to determine whether the terminal behavior is trustworthy and dynamically adjust its security policy; based on the evaluation of the trust status of all EDR terminals, the weak links in the network are discovered, the network system construction is strengthened, and the ability of the authentication system to discover problems is further enhanced.

2. The zero-trust authentication system based on EDR according to claim 1, wherein, Detailed information on different types of terminal data includes: terminal login information, processes, services, startup items, registry, network connection information, files, software, system logs, mobile storage media usage information and alarm information.

3. The zero-trust authentication system based on EDR according to claim 2, characterized in that, The data collection layer collects all kinds of fields in an all-round way, and also includes lightweight virtualization containers, virtual machines, and peripherals in the overall scope of data collection.

4. The zero-trust authentication system based on EDR according to claim 1, wherein The data analysis layer is based on the collected data, further splits the behavior information according to the type, builds a behavior chain, and aggregates the various preparation steps, operations, permission settings, links, and accessed file information into an attack chain to analyze whether it is malicious behavior.

5. The zero-trust authentication system based on EDR according to claim 4, wherein The data parsing layer incrementally updates configuration and dependency libraries based on microservices.

6. The zero-trust authentication system based on EDR according to claim 1, characterized in that, Determine user behavior based on the EDR analysis results, detect whether each user operation behavior is under the zero-trust system, whether it passes the zero-trust verification, and conduct a trust assessment of the user behavior analysis, including the following steps: S11. The data collection layer obtains terminal data through the EDR terminal; S12. Transmit the data to the EDR analysis engine for data analysis; S13. The trust authentication layer obtains the data analysis results of the EDR analysis engine and the traceability data of the data collection layer of the relevant analysis results; S14. For any user behavior, judge whether it is verified by zero-trust authentication; S15. The trust authentication layer conducts a trust assessment on all user operations in the EDR terminal according to whether the judgment result of the user operation is an alarm event, and obtains the trust assessment value of the EDR terminal.

7. The zero-trust authentication system based on EDR according to claim 1, wherein According to the trust assessment results, analyze and calculate each terminal through the zero-trust system, judge whether the terminal behavior is trustworthy and dynamically adjust its security policy, including the following steps: S21. The trust authentication layer obtains the alarm information of the data parsing layer; S22. Trace the alarm information, obtain the collected data of the data collection layer based on the subject, object, and time elements, and based on the alarm results of the EDR analysis engine, judge the terminal corresponding to the alarm information, and judge whether various behaviors of the terminal pass the zero-trust authentication; S23. If it fails to pass the zero-trust authentication, judge according to the authentication and authorization situation and adjust its trust assessment value; if there is a threat event, reduce the credibility of the terminal, and if there is no threat event within a certain period of time, increase the terminal credibility; S24. Based on the change in the trust assessment of the EDR terminal, the zero-trust authentication system modifies the resource access control policy of the EDR terminal, so that highly trusted terminals can obtain more and better resources.

8. The zero-trust authentication system based on EDR according to claim 1, wherein Discover weak links in the network according to the trust status assessment of all EDR terminals, including the following steps: S31. The trust authentication layer obtains the list of EDR terminals; S32. Based on the zero-trust verification results of the EDR terminal behavior, read the trust assessment values of all current EDR terminals; S33. Based on the trust assessment values of the EDR terminals, conduct a risk analysis on all EDR terminals and draw the situation distribution of the overall network; S34. Based on the events occurring in each EDR terminal, regard the EDR terminal with a lower trust assessment value as a weak device, mark the weak interval of the network and give rectification opinions.