Threat control method and system
Patent Information
- Application Number
- JP2022156234
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-09-29
- Filing Date
- 2022-09-29
- Publication Date
- 2025-10-07
AI Technical Summary
Conventional computer network security systems face challenges in providing sufficient situational awareness and timely visibility into ongoing attacks due to unidirectional data flow from sensors to backends, leading to increased vulnerability windows and limited ability to combine multi-host detections.
Implementing a peer-to-peer communication mechanism between sensors to share contextual information and analyze security threats across nodes, allowing for distributed anomaly detection and enhanced situational awareness.
Enhances detection capabilities, particularly for multi-host attacks, reduces vulnerability windows, and improves adaptability by enabling real-time contextualization and decentralized data processing.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for threat control in a computer network security system and a computer network security system.
Background Art
[0002] Computer network security systems are beginning to spread. As an example of such, EDR (Endpoint Detection and Response) products and services are known. EDR focuses on detection and monitoring during and after a breach and helps determine how to optimally respond and / or take automated actions. The growth of EDR has been enabled in part by the emergence of machine learning, big data, and cloud computing.
[0003] Conventional EDR or other similar systems deploy data collectors on selected network endpoints (which can be any element of the IT infrastructure). The data collectors observe the activities occurring at the endpoints and then send the collected data to a central backend system (the "EDR backend"), often located within the cloud. When the EDR backend receives the data, the data is processed (e.g., aggregated and enriched) before being analyzed and scanned by the EDR provider for signs of security violations and anomalies.
[0004] Data volume and threat surfaces are expanding at an enormous pace. Threats to computer systems are changing rapidly, so security models against threats must also evolve. It is impossible to keep up with the ever-increasing cyber threats, both file-based and fileless, by using current methods to protect "simple" endpoints or simply by improving cloud and backend capabilities. Moreover, smarter endpoints present multiple challenges in terms of vulnerabilities, increasing functionality, and data privacy requirements. Therefore, traditional methods cannot cope with the speed of change and the diverse situations encountered.
[0005] In current systems, communication between the data collector, i.e., the sensor, and the backend is mostly one-way, although default mechanisms such as upgrades and updates exist. In conventional systems, the sensor collects data and submits it to the backend. The backend centrally processes the data submitted by the sensor, looking for indicators such as attacks and anomalies. The backend can manipulate the intensity and granularity level of data collection by preparing new updates that are sequentially communicated to the sensor. Conventional systems have a basic local anomaly detection mechanism for the sensor to flag threats, and mechanisms such as rules and / or machine learning generate additional events that are used by the backend to optimize its operation. This functionality is controlled by the backend via default upgrade and update mechanisms.
[0006] Current system problems include several cases such as exploitation, wormable threats (e.g., WannaCry), and hands-on keyboard attacks, but knowledge of malicious activity occurring at a single endpoint does not provide sufficient contextual awareness or help in remediating threats. In most cases, attacks involve multiple hosts, and the attacker searches for its ultimate target. It is clear that a data collector that operates primarily in one direction, i.e., a detection system with communication between sensors and a backend as described above, faces several challenges, including the following: 1. Combining detection and related information affecting multiple hosts to construct a single incident (meaning multi-host detection that provides sufficient visibility into the attack, along with all relevant context). 2. Providing timely visibility into ongoing attacks within the organization: The fact that the backend detection pipeline is centralized can lead to delays in processing events coming from under attack, which is undesirable. This results in a larger vulnerability window. 3. Acquisition of relevant data based on posthumous discovery. In fact, once the backend detects a potential vulnerability (breach) on the first host, its ability to acquire historical data on the second host is limited, and the second host is also assumed to be part of the security incident. [Overview of the project] [Problems that the invention aims to solve]
[0007] For these reasons, there is a need, both now and in the future, for improved computer network security systems that can address attacks that were difficult to detect using conventional methods. [Means for solving the problem]
[0008] The following is a simplified overview to provide a basic understanding of several aspects of various embodiments of the invention. This overview is not a comprehensive overview of the invention. It is not intended to identify any important or essential elements of the invention or to precisely define its scope. The following overview merely presents some concepts of the invention in a simplified form as a prelude to a more detailed description of exemplary embodiments of the invention.
[0009] According to a first aspect, the present invention relates to a method for detecting threats in a computer network, the method comprising: detecting, for example, an abnormal or malicious behavior, a security threat related to a digital object and / or context at a first node; collecting contextual information related to the detected security threat at the first node; reporting at least one detected security threat and the collected contextual information to at least a second node; analyzing the received information related to the security threat at the second node; collecting contextual information related to the analysis at the second node; and transmitting the threat-related information, along with additional analysis and contextual information collected from the second node, to at least one further node or backend.
[0010] In one embodiment of the present invention, the received information is analyzed and sent to further nodes or backends until investigation is no longer required, for example, until the detected threat is identified, or until the detected item no longer affects nodes other than the node where it was detected, and / or until it becomes clear that the collected information is actually a false positive.
[0011] In one embodiment of the present invention, a second node or further node to which information is transmitted by broadcast or the like is another host such as a neighbor, and / or a backend host or backend system.
[0012] In one embodiment of the present invention, the data relating to the detected security threat includes information about a specific node, and the second or further node to which the information is transmitted is the specific node referenced in the data relating to the detected security threat.
[0013] In one embodiment of the present invention, the detected security threat data includes information about a specific application being used, and a second or further node to which the information is transmitted includes at least one node on which the specific application is installed.
[0014] In one embodiment of the present invention, if the detected security threat data indicates a user exhibiting unexpected behavior, the node broadcasts information about the user-level anomaly to other nodes via a broadcast message, enabling further tracking by other nodes of the user exhibiting unexpected behavior.
[0015] In one embodiment of the present invention, the data is transmitted from a second node or further node to a node having a specific IP address or a node within a specific IP address range, and / or a node that has seen activity from a specific user, and / or a host having a specific asset ID.
[0016] In one embodiment of the present invention, contextual information includes a unique identifier for the detected threat and / or information about the node that transmitted the information.
[0017] In one embodiment of the present invention, contextual information includes a series of activities that led to the detection of a security threat.
[0018] In one embodiment of the present invention, a further node receiving information about detected security threats and collected contextual information from another host adds that contextual information, for example, information including a lead or initial context, before the analysis data is sent to at least one other host or backend.
[0019] In one embodiment of the present invention, a security threat is identified on a node by at least one sensor installed on that node, which is configured to implement a detection mechanism, such as a local anomaly detection mechanism, to identify a suspicious entity, such as a malicious process, user, application, or file.
[0020] In one embodiment of the present invention, a node analyzing security threats sends commands to its neighbors, such as by broadcasting, to increase the level of data collection and data submission.
[0021] According to a second aspect, the present invention relates to a system comprising a computer network having at least two nodes, the nodes being configured to detect, for example, anomalies or malicious behavior at the nodes, or security threats relating to digital objects and / or context. In the system, a first node is configured to detect security threats at the first node and to collect contextual information relating to the detected security threats at the first node. The first node is further configured to report at least one detected security threat and the collected contextual information to at least a second node, the second node being configured to analyze the received information relating to the security threats and to collect contextual information relating to the analysis at the second node. The second node is further configured to transmit threat-related information, along with additional analysis and contextual information collected from the second node, to at least one further node or backend.
[0022] In one embodiment of the present invention, the system is configured to implement the method according to any embodiment of the present invention.
[0023] According to a third aspect, the present invention relates to a computer program including instructions that, when executed by a computer, cause the computer to execute the method according to the present invention.
[0024] According to a fourth aspect, the present invention relates to a computer-readable medium including the computer program according to the present invention.
[0025] The present invention can solve the problems described below, for example, by providing a mechanism that enables sensors to communicate with each other. In the solution of the present invention, the context of detection can be further shared for analysis and investigation in a peer-to-peer manner. Information collected and created by a host, node, or any device within a network can flow between any type of entity as long as it is used in the solution of the present invention. In this approach, one node or entity can be a computer having its own sensors, and a second entity can be a node of a similar or different type, for example, a network-level IDS that manages the security of an entire network segment.
[0026] The solution of the present invention enables better detection capabilities, particularly in situations involving multiple endpoints. This is, for example, the case of an intrusion involving lateral movement and exploration as an attacker moves towards its target. Also, the solution of the present invention enables better contextualization of detection, meaning that not only is the information that triggered the detection specifically presented to the customer receiving the detection, but also the entire series of activities that led to that detection is presented.
[0027] The achievable benefits of the solution of the present invention also include the following: · A consistent and complete representation of cyber-relevant cross-host activities · Reduction of the vulnerability window of the EDR solution · Improvement of the adaptability of the solution regarding data collection and / or processing · The system can be driven both backend (e.g., when the backend receives a notification about an anomaly in a first elapsed time context, it can recognize this situation and appropriately adjust other sensors and its own logic) and sensor - to - sensor communication (e.g., a first sensor can broadcast an order to its neighbor to increase the data collection and submission level).
[0028] The various exemplary and non - limiting embodiments of the invention, together with its additional objectives and advantages, will be best understood from the following description of specific exemplary and non - limiting embodiments, read in conjunction with the accompanying drawings, regarding both its construction and method of operation.
[0029] The verb "comprising" is used in this specification as an open limitation that neither requires nor excludes the presence of features not recited. The features recited in the dependent claims can be freely combined with each other unless otherwise explicitly stated.
[0030] Furthermore, throughout this specification, it is to be understood that the use of the singular form does not exclude the plural form.
[0031] Embodiments of the present invention are shown by way of example and not limitation in the figures of the accompanying drawings.
Brief Description of the Drawings
[0032] [Figure 1] Shows the communication flow between the host and the backend of a prior - art system. [Figure 2] Shows the communication flow between the host and the backend according to an exemplary embodiment of the present invention. [Figure 3] Shows an example of a computer network system according to an embodiment. [Figure 4] A flowchart illustrating an example of a threat control method according to one embodiment is shown. [Modes for carrying out the invention]
[0033] Figure 1 illustrates the communication flow between a host and a backend in a conventional system. In conventional systems, sensor-backend communication is more or less unidirectional. In these systems, as shown in Figure 1, the host's sensor collects data and sends it to the backend. In these conventional solutions, the backend centrally processes the data sent by the sensor, looking for indicators of attack or anomaly. The backend can manipulate the intensity and granularity level of data collection by preparing new updates that are sequentially propagated to the sensor. Conventional systems have a basic local anomaly detection mechanism (such as a rule-based or machine learning mechanism) in which the sensor on the host flags threats and generates additional events used by the backend to optimize its operation. This can be controlled by the backend via a default upgrade or update mechanism.
[0034] As described above, the idea of the present invention is to provide a mechanism that enables sensors to communicate with each other. In the solution of the present invention, the context of the detection can be shared for further analysis and investigation in a peer-to-peer manner. Nodes may share detection-related data, such as context data related to the detection and data related to the response to the threat. In one embodiment of the present invention, this threat detection-related data is shared within a swarm network.
[0035] The present invention relates to a system and method for threat detection in a computer network, the method comprising: a first node detecting, for example, anomalous or malicious behavior, digital objects and / or security threats related to context at the first node; the first node collecting context information at the first node related to the detected security threat; reporting at least one detected security threat and the collected context information to at least a second node; the second node analyzing the received information related to the security threat; the second node collecting context information related to the analysis; and transmitting the collected analysis and context information, along with the added threat-related information, from the second node to at least one further node or backend.
[0036] In one embodiment of the present invention, the received information is analyzed and sent to further nodes or backends until investigation is no longer required, for example, until the detected threat is identified, or until the detected item no longer affects nodes other than the node where it was detected, and / or until it becomes clear that the collected information is actually a false positive.
[0037] Figure 2 shows a communication flow between a host and a backend according to one exemplary embodiment of the present invention. The solution of the present invention provides a mechanism that enables sensors to communicate with each other. This may be understood as a communication bus between hosts in a network (at least in some embodiments).
[0038] In the solution of this invention, one of the roles of the backend is to facilitate the augmentation of distributed anomaly contexts. Sensors installed at endpoints such as hosts or nodes rely on local anomaly detection mechanisms to identify suspicious entities such as malicious processes, contexts, or users.
[0039] A node or host may have a mechanism for determining when to report to other specific hosts, and local anomalies may be measured by sensors and / or broadcasted. In some exemplary cases, for example: Anomalies are reported to a specific host or backend if it is known which element is running to continue checking for the anomaly. • Anomalies are reported to specific hosts known to be at risk of being affected by the detected anomaly: for example, (1) To all hosts, or at least some hosts, that have a specific application (2) To a host having a specific network address such as a specific IP address, or a host located within a specific network address range such as a specific IP address range. (3) To the host that was viewing activity from a specific user (4) To a host with a specific asset ID
[0040] In one embodiment of the present invention, the data relating to the detected security threat includes information about a specific node, and the second or further node to which that information is transmitted is the specific node referenced in the data relating to the detected security threat.
[0041] In one embodiment of the present invention, the detected security threat data includes information about a specific application being used, and a second node or further node to which the information is transmitted includes at least one node on which the specific application is installed.
[0042] In one embodiment of the present invention, if the detected security threat data indicates a user exhibiting unexpected behavior, the node broadcasts information about the user-level anomaly to other nodes via a broadcast message, enabling further tracking by other nodes of the user exhibiting unexpected behavior.
[0043] In one embodiment of the present invention, the second node or further node to which the data is transmitted is a node having a specific IP address or a node within a specific IP address range, and / or a node that was viewing activity from a specific user, and / or a host having a specific asset ID.
[0044] In one embodiment of the present invention, a second node or further node to which information is transmitted, such as by broadcast, is another host, such as a neighbor, and / or a backend host or backend system. In one embodiment of the present invention, if it is unclear to whom an anomaly should be reported, a node can broadcast data related to the detected anomaly. In this case, for example, other nodes can investigate the findings and take further action.
[0045] Based on the received information and the data related to the detected anomaly received from the first node, additional information may be collected by other nodes in the network. For example, a node investigates the anomaly and adds its own context and findings to the original findings received by the node. The node can then send further data related to the anomaly and, at the same time, add its own findings regarding the anomaly. This can continue as long as necessary, for example, until further investigation by further nodes is no longer required.
[0046] The structure of an anomaly detection report is as follows in one exemplary embodiment of the present invention. The data transmitted from one node to another node and / or backend may consist of at least one of the following: • A unique ID to make the context easier to handle from a backend perspective. • Information regarding the context of the detected anomaly (e.g., initial context and additional context), • Information regarding changes in ownership Other meaningful observations
[0047] One embodiment of the present invention includes contextual information that includes a unique identifier for the detected threat and / or information about the node that transmitted the information.
[0048] One embodiment of the present invention includes a series of activities in which contextual information guides the detection of security threats.
[0049] In one embodiment of the present invention, a further node that receives information about security threats detected and collected contextual information from another host adds that contextual information, for example, information including read or initial context, before that analysis data is sent to at least one other host or backend.
[0050] In one embodiment of the present invention, a security threat is identified at a node by at least one sensor provided at the node, which is configured to implement a detection mechanism such as a local anomaly detection mechanism, and identifies a suspicious entity such as a malicious process, user, application, or file.
[0051] In one embodiment of the present invention, a node analyzing security threats sends, for example, a command to its neighbor to increase the level of data collection and data submission.
[0052] Figure 3 schematically shows a portion of a first computer network 1 on which a computer system, such as an EDR system, is installed. Any other computer system capable of carrying out embodiments of the present invention can be used instead of, or in addition to, the EDR system used in this example. The first computer network is connected to a security services network, which is connected to a security backend / server 2 via a cloud 3. The backend / server 2 forms a node on the security services computer network relative to the first computer network. The security services computer network is managed by an EDR system provider and can be isolated from the cloud 3 by a gateway or other interface (not shown) or other network elements suitable for the backend 2. The first computer network 1 may also be isolated from the cloud 3 by a gateway 4 or other interface. Other network structures are also conceivable.
[0053] The first computer network 1 consists of a plurality of interconnected network nodes 5a-5h, each representing an element within the computer network 1, such as a computer, smartphone, tablet, laptop, or other network-connectable hardware. The nodes can communicate with each other according to the solution of the present invention. Each network node 5a-5h shown in the computer network may also represent an EDR endpoint on which security agent modules 6a-6h, including a data collector or "sensor," are installed. The security agent modules may also be installed on any other element of the computer network, such as on a gateway or other interface. Security agent module 4a is installed on gateway 4 in Figure 1. Security agent modules 6a-6h, 4a collect various types of data on nodes 5a-5h or gateway 4, including, for example, program or file hashes, files stored on nodes 5a-5h, network traffic logs, process logs, binaries or files extracted from memory (e.g., DLLs, EXEs, or memory forensic artifacts), and / or logs from monitoring actions (e.g., TCP dumps) performed by programs or scripts running on nodes 5a-5h or gateway 4.
[0054] The data collected by the network nodes may include information related to detected anomalies, with additional context added based on the solution of the present invention. The collected data may be stored in a database or a similar model for storing information to be used further. Any kind of behavioral profile / representation of application / service / process behavior may be further constructed by the security application on nodes 5a-5h, backend / server 2 and / or a second server, and stored in a database. Nodes 5a-5h and server 2 are typically equipped with hard drives, processors, and RAM.
[0055] Any type of data that can assist in the detection and monitoring of security threats, such as security breaches or system intrusions, can be collected by security agent modules 6a-6h, 4a during their lifecycle, and the type of data observed and collected is expected to be set according to rules defined by the EDR system provider, depending on whether it is at the time of EDR system installation or by instructions from the EDR backend 2. In one embodiment of the present invention, at least some of the security agent modules 6a-6h may also be capable of making decisions on the type of data observed and collected by themselves. For example, security agents 6a-6h, 4a can collect data on the behavior of programs running on EDR endpoints and can observe when new programs are started. Where appropriate resources are available, the collected data can be stored permanently or temporarily by the security agent modules 6a-6h, 4a on their respective network nodes or in appropriate storage locations on the first computer network 1.
[0056] Security agent modules 6a-6h and 4a are configured to transmit information such as data they collect to other hosts and / or backends, as described herein. The security agent modules can send and receive commands to and from other hosts and / or backends 2, for example, via the cloud 3. This makes it possible to remotely manage the EDR system without the need for the EDR system provider to maintain a certain presence of personnel in the organization managing the first computer network 1.
[0057] In one embodiment of the present invention, security agent modules 6a-6h and 4a can also be configured to build a swarm intelligence network including security agent modules of multiple network nodes 5a-5h interconnected in a local computer network 1. Since each security agent module 6a-6h and 4a collects data related to its respective network node 5a-5h, they are further configured to share information based on the collected data in the established swarm intelligence network according to the solution of the present invention. The swarm intelligence network consists of multiple semi-independent security nodes (security agent modules) that can function independently. Therefore, the number of instances in a group can vary considerably. Also, there may be multiple connected groups cooperating with each other within a single local computer network.
[0058] Security agent modules 6a-6h and 4a are further configured to use data and information received and collected from the internal swarm intelligence network to generate and adapt models relevant to their respective network nodes 5a-5h. For example, if a known security threat is detected, security agent modules 6a-6h and 4a are configured to generate and send security alerts to the internal swarm intelligence network and local center nodes (not shown) in the local computer network, and to activate security measures to respond to the detected security threat. Furthermore, if an anomaly is identified that is highly likely to be a new threat, security agent modules 6a-6h and 4a are configured to verify and block the threat, generate a new threat model based on the collected data and received information, and share the generated new threat model in the internal swarm intelligence network and local center nodes. The data collected by the nodes of the swarm intelligence network may include information related to the detected anomaly, with additional context collected based on the solution of the present invention.
[0059] Next, we will describe some practical exemplary steps of operation according to several embodiments.
[0060] Deployment: Since all agents essentially share the same codebase and the ability to adapt to their roles by activating different components within a modular architecture and duplicating themselves, only one initial agent needs to be deployed within the customer network with sufficient access rights. This agent will then discover servers, install copies of itself in appropriate locations, build the internal communication network, and establish backend updates, reporting, and communication channels. Furthermore, authentication and other necessary issues may need to be considered, and in the initial stages, agents may be deployed on individual hosts.
[0061] Normal operation: The agent continuously monitors its environment, collects data, learns from what it sees, and builds a model of its host and its surroundings. These models can be shared across nodes in the swarm and used, for example, to learn user behavior on one computer or another within the network. Furthermore, abstract information may be sent to other nodes or backends in a privacy-preserving manner. The agent also utilizes the aforementioned learned models, which should be prepared to know what is normal.
[0062] Addressing Known Threats: An agent that detects either a known threat or an anomaly indicating a known threat can, as described above, immediately alert its swarm mates to the situation and, in preparation for a threat that could render them inactive, request additional resources as needed (spin up a new virtual agent or have one delivered from another host if there is a risk of compromise). If the agent already has the means to address the issue, that action is taken. The detected anomaly can be communicated to other nodes or backends according to the solution of the present invention. Nodes can share detection-related data, such as detection-related context data and data related to responses to the threat.
[0063] Addressing New Threats: Agents constantly learn what is normal and are equipped to detect new threats, with personnel finely allocated according to the data and specificities of their own nodes. Detected threats or anomalies can be communicated to other nodes or backends according to the solutions of the present invention. The ability of user-interactive nodes is used to verify threats, and if a threat is confirmed, actions are taken to contain it, as well as to build a new threat model distributed in a known language to both GroupMate and other customers via a central link. In some embodiments, if a threat is deemed to pose a very high risk, autonomous containment measures can be taken before a final decision is made. The degree of autonomous action can always be adjusted as needed. The connect model also allows for the assistance of human experts as needed.
[0064] Neutralizing New Threats: The agent may also include sandbox functionality that can be used for a secure environment and containment, employing a incremental approach to detect ways to neutralize new threats (trial-evaluate-mutate-retry), and further enabling a more detailed understanding of the behavior of such threats and the further dissemination of that information.
[0065] Sharing New Threat Knowledge: When new threats are identified, they are encoded into an internal language representation for centralized sharing across agents and from there to other customers, ensuring optimal protection for all customers in a privacy-preserving manner.
[0066] Backend Preparation: While in operation, information about both events and threats can be abstracted and sent to the backend at all times. This allows the backend "laboratory" to continue experimenting with more effective defense tools in a secure (sandbox-like) environment, providing further correlation and analysis of data sent from numerous individual intelligent sensors.
[0067] Figure 4 is a flowchart showing an example of a threat control method according to one embodiment.
[0068] In S201, the first node detects, for example, anomalous or malicious behavior, and security threats related to digital objects and / or context on the first node.
[0069] In S202, contextual information is collected at the first node related to the detected security threat.
[0070] In S203, at least one detected security threat and collected contextual information are reported to at least a second node.
[0071] In S204, the second node analyzes the received information regarding security threats, and the second node collects contextual information related to the analysis.
[0072] In S205, threat-related information is sent to at least one further node or backend, along with the additional analysis and contextual information collected from the second node.
[0073] In one embodiment, suspicious events among the monitored events can be detected by one or more detection mechanisms used. In one embodiment, the detection mechanism used to detect suspicious events may include using at least one of machine learning models, scan engines, heuristic rules, statistical anomaly detection, fuzzy logic-based models, or any predetermined rules.
[0074] In one embodiment, information regarding alerts, statuses, and other related entities is shared by using at least one language model so that the information can be interpreted by both computer systems and human experts.
[0075] As described above, the threat detection model used in the system (e.g., EDR) may actually be one or more of the following elements: a neural network trained using a training dataset, precise rules or heuristic rules (e.g., hardcoded logic), fuzzy logic-based modeling, and statistical inference-based modeling, or a combination of these elements. The threat detection model may be defined to take into account specific patterns, files, processes, connections, and inter-process dependencies.
[0076] While preferred embodiments of the present invention have been described above, it should be understood that these embodiments are merely illustrative and the claims are not limited to these embodiments. Those skilled in the art will be able to modify and substitute based on the disclosures that are considered to be within the scope of the appended claims. Each feature disclosed or illustrated herein may be incorporated into the invention alone or in any suitable combination with any other features disclosed or illustrated herein. The list and groups of examples provided in the above description are not exhaustive unless specifically noted.
Claims
1. 1. A method of threat detection in a computer network, comprising: Detecting, at a first node, anomalous or malicious behavior, security threats related to digital objects and / or contexts at the first node; collecting contextual information at the first node related to the detected security threat; reporting at least one of the detected security threats and the collected contextual information to at least a second node; analyzing the security threat information received at the second node and collecting contextual information related to the analysis at the second node; A method of transmitting information related to the security threat together with added analysis and collected contextual information from the second node to at least one further node or backend.
2. 10. The method of claim 1, wherein the received information is analyzed and sent to further nodes or a backend until the detected threat has been identified, the detected item no longer affects nodes other than the node where it was detected, and / or the collected information no longer requires investigation, such as if it becomes clear that the situation is in fact a false positive.
3. 2. The method of claim 1, wherein the second node or the further node to which the information is broadcast is a neighbor host and / or another host, such as a backend host or system.
4. 2. The method of claim 1, wherein the data regarding the detected security threat includes information of a specific node, and the second node or further node to which the information is sent is the specific node referenced in the data regarding the detected security threat.
5. 2. The method of claim 1, wherein the data regarding the detected security threat includes information about a particular application being used, and the second node or the further node to which the information is sent includes at least one node on which the particular application is installed.
6. 2. The method of claim 1, wherein if the data related to the detected security threat indicates a user behaving unexpectedly, the node issues a broadcast message to other nodes with information about user-level anomalies, allowing the user behaving unexpectedly to be further tracked by the additional nodes.
7. 5. The method of claim 4, wherein the second node or further node to which the data is sent is a node with a particular IP address or a node in a particular IP address range, and / or a node that has seen activity from a particular user, and / or a node with a particular asset id.
8. The method described in claim 5, wherein the second node or further node to which the data is sent is a node with a specific IP address or a node in a specific IP address range, and / or a node that has seen activity from a specific user, and / or a node with a specific asset ID.
9. The method described in claim 6, wherein the second node or further node to which the data is sent is a node with a particular IP address or a node in a particular IP address range, and / or a node that has seen activity from a particular user, and / or a node with a particular asset ID.
10. The method of claim 1 , wherein the context information includes a unique identifier for the detected security threat and / or information about the node that transmitted the information.
11. The context information defines a sequence of activities that lead to the detection of the security threat.
10. The method of claim 1 comprising:
12. 2. The method of claim 1, wherein the further node receiving information about detected security threats and the collected context information from another host adds the context information, including lead or initial context, before the analytical data is sent to at least one other host or backend.
13. 10. The method of claim 1, wherein the security threat is identified at a node by at least one sensor provided at the node configured to implement a detection mechanism, such as a local anomaly detection mechanism, to identify suspicious entities, such as unauthorized processes, users, applications, or files.
14. The method of claim 1 , wherein the node analyzing the security threat broadcasts instructions to its neighbors to increase data collection and data submission levels.
15. 1. A system comprising a computer network comprising at least two nodes, the nodes configured to detect security threats related to anomalous or malicious behavior, digital objects, and / or contexts at the nodes; In the system, a first node is configured to detect a security threat at the first node and collect contextual information at the first node related to the detected security threat; the first node is further configured to report at least one detected security threat and the collected contextual information to at least a second node; the second node is configured to analyze the received information related to the security threat and collect contextual information related to the analysis at the second node; The second node further sends information related to the security threat along with added analysis and context gathered from the second node to at least one further node or backend.
16. A system according to claim 15, configured to carry out the method according to any one of claims 2 to 12.
17. A computer program comprising instructions which, when executed by a computer, cause the computer to carry out the method of any one of claims 1 to 14.
18. A computer-readable medium comprising the computer program of claim 17.