Systems and methods for detecting security threats

The system uses a profiler, normalizer, and detector engine to analyze historical and real-time data, generating high-severity alerts only when necessary, addressing the inefficiencies of existing security detection systems and supervised learning methods.

JP2025538144APending Publication Date: 2025-11-26SECUREWORKS CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025525702
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-03
Filing Date
2023-10-05
Publication Date
2025-11-26

AI Technical Summary

Technical Problem

Existing security detection systems generate numerous noisy and non-actionable alerts, consuming resources and time, while supervised learning methods are costly due to the need for expert-labeled training data.

Method used

A system utilizing a profiler engine to generate statistical profiles from historical data, a normalizer engine to format data, and a detector engine to correlate subsequences with these profiles, generating a high-severity alert only when a threshold is exceeded, thus reducing unnecessary alerts and increasing efficiency.

Benefits of technology

This approach enables the detection of high-severity threats with fewer alerts, improving analyst efficiency and reducing costs by focusing on less frequent but significant security events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025538144000001_ABST
    Figure 2025538144000001_ABST
Patent Text Reader

Abstract

A method and system for detecting malicious threat activity or event sequences is disclosed. In one embodiment, the method may include receiving security data from multiple data sources, normalizing the security data, generating one or more statistical profiles for one or more entities based on the normalized data, generating one or more detectors based on one or more subsequences organized into multiple threat chains, monitoring telemetry data for the one or more subsequences in real time via the one or more detectors, aggregating each detected one or more subsequences, generating a score based on a correlation of the aggregated detected subsequences with the one or more statistical profiles, and generating a high severity alert if the score exceeds a threshold.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (Technical field) The present disclosure relates generally to systems and methods for detecting security threats, and more particularly to systems and methods for analyzing state-of-storage and / or historical data and real-time data to determine whether a high severity alert is indicated via correlation between the analyzed state-of-storage and / or historical data and the analyzed real-time data. [Background technology]

[0002] (background) Statistical and unsupervised learning security detection engines or devices may generate noisy and / or many non-actionable security alerts. Such security alerts may not be sent to security analysts for investigation. Thus, some events that are actual threats and may include or comprise non-actionable security alerts may not be recognized or flagged. Furthermore, if all these alerts were sent to security analysts for review, reviewing such alerts may consume a large amount of time.

[0003] On the other hand, supervised learning utilizes training data that is labeled by experts and / or oracles prior to building a model or classifier, but this operation can be expensive as it may utilize many resources (e.g., security analysts or experts with high levels of expertise) to label large data volumes.

[0004] It can therefore be seen that a need exists for a system and method for threat or malicious activity detection that can monitor and process incoming security data, separate potential threats or malicious activity from non-actionable activity, and determine whether an alert should be issued and / or a security analyst notified. The present disclosure is directed to the foregoing and other related and unrelated problems / challenges in the art. Summary of the Invention [Means for solving the problem]

[0005] (summary) Briefly, according to various aspects, the present disclosure is directed to systems and methods for detecting security threats and / or malicious activity, and in embodiments, for detecting such security threats and / or malicious activity that may be part of and / or concealed during inoperable activity based on reviewing and determining correlations between occurrences or sequences of such inoperable activity contained within incoming security data in light of previous data, e.g., stored state data and / or historical data.

[0006] In embodiments, such systems and methods may comprise or utilize a memory (or multiple memories) and / or at least one processor. Such systems may further include a profiler engine, a normalizer engine, and / or a detector engine, each of which may include separate memories associated with or accessible by such engines. The normalizer engine may be configured to normalize the state-of-storage data and / or telemetry data prior to or after receipt by the profiler engine and / or detector engine (e.g., in certain examples, by one or more detectors). In embodiments, the state-of-storage data and / or telemetry data may include data in a format specific to an entity and / or organization or company (e.g., an organization or company including multiple entities). Accordingly, the normalizer engine may reformat or format the state-of-storage data and / or telemetry data so that the state-of-storage data and / or telemetry data can be processed by the profiler engine and / or detector engine.

[0007] The profiler engine may be configured to request, retrieve, and / or receive data, for example, in embodiments, security logs or other security data. The data may include state-of-the-art data, which may include historical data or older data (e.g., older than data received in real time). In some embodiments, the state-of-the-art data may be stored in a repository, a data lake, a database, and / or another type of storage and / or memory. The state-of-the-art data may correspond to one or more different entities. The state-of-the-art data may also include statistical information or data associated with each of the one or more different entities. In various embodiments, entities may include users, computing devices, IP addresses, etc. The profiler engine may be configured to utilize the state-of-the-art data to generate one or more statistical profiles for each of the one or more entities. In some embodiments, each profile may include trend data and / or other entity data rather than, or in addition to, statistical data.

[0008] The detector engine may utilize one or more subsequences and / or threat chains organized within the multiple threat chains to generate multiple or one or more detectors. In embodiments, the detectors may be configured to detect defined conditions, statistics, behaviors, or other data (e.g., based on the subsequences defined and / or organized in each of the multiple threat chains). Once one or more subsequences are detected, the detector engine may aggregate each of the detected subsequences and correlate the subsequences with one of the statistical profiles. The correlation may be utilized by the detector engine to generate a score. In another embodiment, correlating the aggregated detected subsequences with one of the statistical profiles may generate a score. If the score exceeds a threshold, the detector engine may generate and transmit an alert or a high-severity alert.

[0009] Thus, the systems and methods disclosed herein are adapted to enable and / or provide for the review, detection, and generation of a single alert for a high-severity threat that is comprised of a low-fidelity sequence or subsequence that may be considered to constitute a largely or completely inoperable activity or event by itself. Thus, a user is notified of the actual threat, rather than of many low-fidelity sequences or subsequences that may or may not be threatening. Furthermore, such systems and methods may enable a security professional or analyst to analyze potential high-severity threats that occur less frequently than many low-fidelity sequences or subsequences, thus increasing efficiency and reducing costs and time.

[0010] In one aspect, the present disclosure provides a system for detecting security threats. The system may include a series of engines, each having a memory and at least one processor. The system may include a profiler engine. The profiler engine may be configured to retrieve state-of-sate data corresponding to a plurality of entities from a repository. The profiler engine may be configured to mine selected statistical information from the retrieved state-of-sate data and generate a plurality of statistical profiles based on the retrieved state-of-sate data, the profiles relating to and including the selected statistical information regarding each of the plurality of entities. The profiler engine may be configured to store the plurality of statistical profiles in a profile database. The system may include a detector engine. The detector engine may be configured to generate one or more low-fidelity detectors based on the statistical profile of each of the plurality of entities organized into one or more threat chains, the one or more detectors being configured to detect different low-fidelity security threats within the one or more threat chains. The detector engine may be configured to monitor, via each of the one or more detectors, real-time data corresponding to the plurality of entities for a plurality of low-fidelity security threats. The detector engine may be configured to generate a score based on a correlation of the detected aggregation of the plurality of low-fidelity security threats with the plurality of statistical profiles. The detector engine may be configured to generate an alert if the score exceeds a threshold.

[0011] In one aspect, the state-of-the-art data may include historical data, and the repository comprises a data lake. In an embodiment, the plurality of entities may include one or more of users or computing devices. Each of the one or more threat chains may include a sequence of events defining a security threat, and the score is based on the occurrence of low-level security threats in one of the one or more threat chains. The score may further be based on the order in which the low-level security threats occur. Each of the plurality of statistical profiles may include a statistical analysis regarding the corresponding entity. Some of the plurality of profiles may include statistics corresponding to services accessed by the corresponding entity. The system may include a normalization engine. The normalization engine may be configured to receive data from a plurality of different data sources. The normalization engine may be configured to normalize the received data prior to generating the plurality of profiles and storing them in the profile database.

[0012] In another aspect, the present disclosure provides a method for detecting security threats. In an embodiment, the method may include receiving security data associated with one or more entities from a plurality of data sources. The method may include normalizing the security data, thereby forming normalized data. The method may include providing the normalized data to a profiler engine. The method may include generating, via the profiler engine, one or more statistical profiles for the one or more entities based on the normalized data. The method may include generating one or more detectors based on one or more subsequences organized into a plurality of threat chains. The method may include monitoring, via the one or more detectors, telemetry data in real time for one or more subsequences for each of the plurality of threat chains. The method may further include, in response to detection of one or more subsequences of one of the plurality of threat chains by the one or more detectors, aggregating each of the detected one or more subsequences. The method may also include generating a score based on correlation of the aggregated detected one or more subsequences with one or more entity profiles. The method may include generating a high severity alert if the score exceeds a threshold score.

[0013] In some embodiments, the method may include retrieving at-rest data from the data lake prior to generating the one or more entity profiles, where the at-rest data includes historical data. The one or more subsequences may include one or more of an event, a file associated with the event, a timestamp, or identifying or identifying data. The identifying or identifying data may include one or more of a username or an IP address. In some embodiments, the method may include storing the one or more entity profiles in a profile database. The one or more entities may further include one or more of a user, a server, an IP address, or another computing device. The user may comprise a cloud-based platform.

[0014] In another aspect, the present disclosure provides a non-transitory machine-readable storage medium storing processor-executable instructions executed by at least one processor. In some embodiments, execution of the instructions may cause the at least one processor to normalize the security data in response to receiving security data associated with one or more entities from multiple data sources. The processor may generate one or more statistical profiles for the one or more entities based on the security data. The processor may generate one or more detectors based on one or more subsequences organized within multiple threat chains. The processor may monitor telemetry data from a cloud-based platform for one or more subsequences for each of the multiple threat chains in real time via the one or more detectors. The processor may aggregate each detected one or more subsequences in response to detection of one or more subsequences of one of the multiple threat chains by the one or more detectors. The processor may generate a score based on correlation of the aggregated detected one or more subsequences with the one or more entity profiles. The processor may generate a high severity alert if the score exceeds a threshold score.

[0015] In an embodiment, the one or more entity profiles may include statistical data. The one or more entities may include one or more users. The statistical data may include a number of times each of the one or more users accessed a cloud-based service on the cloud-based platform.

[0016] In another aspect, the present disclosure provides systems and methods for detecting security threats. For example, in embodiments, a method is provided that may include storing historical storage state telemetry data in a data lake. The method may include building a statistical profile based on the historical storage state telemetry data in the data lake. The method may include receiving definitions for one or more low-fidelity detectors. The method may include generating one or more low-fidelity detectors based on the one or more definitions. The method may include listening to real-time telemetry data via the one or more low-fidelity detectors. The method may include correlating the low-fidelity threat with the statistical profile and generating a score in response to the detection of a low-fidelity threat by the one or more low-fidelity detectors. The method may include generating a high-severity alert in response to the score exceeding a threshold. In an embodiment, a security computing device may provide the definitions for the one or more detectors, and the high-severity alert may be transmitted to the security computing device and / or another security computing device.

[0017] Various objects, features and advantages of the present disclosure will become apparent to those skilled in the art upon review of the following detailed description when considered in conjunction with the accompanying drawings.

[0018] It should be understood that for simplicity and clarity of illustration, elements illustrated in the figures have not necessarily been drawn to scale. For example, the dimensions of some elements may be exaggerated relative to other elements. Embodiments incorporating the teachings of the present disclosure are shown and described with reference to the drawings herein. [Brief explanation of the drawings]

[0019] [Figure 1] FIG. 1 is a block diagram of an exemplary data center including a networked system of information handling systems in accordance with the principles of the present disclosure.

[0020] [Figure 2A] 2A and 2B are schematic diagrams of a system for detecting security threats in accordance with the principles of the present disclosure. [Figure 2B] 2A and 2B are schematic diagrams of a system for detecting security threats in accordance with the principles of the present disclosure.

[0021] [Figure 3] FIG. 3 is a schematic diagram of a system operative to detect security threats in accordance with the principles of the present disclosure.

[0022] [Figure 4] FIG. 4 is a flow diagram for detecting security threats in accordance with the principles of the present disclosure.

[0023] [Figure 5] FIG. 5 is a schematic diagram of an exemplary information handling system capable of implementing each of the illustrative embodiments according to the principles of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0024] The use of the same reference symbols in different drawings indicates similar or identical items.

[0025] (Detailed explanation) The following description in combination with the figures is provided to aid in understanding the teachings disclosed herein. This description focuses on specific implementations and embodiments of the present teachings and is provided to help explain the present teachings. This focus should not be construed as a limitation on the scope or applicability of the present teachings.

[0026] Briefly, according to various aspects, the present disclosure is directed to systems and methods for detecting security threats. Such systems and methods may comprise or utilize memory and / or at least one processor. Such systems may include a profiler engine, a normalizer engine, and / or a detector engine. The profiler engine may be configured to request, acquire, and / or receive data. The data may be state-of-the-art data. The state-of-the-art data may be historical data or older data (e.g., older than data received in real time). The state-of-the-art data may be stored in a repository, a data lake, a database, and / or another type of storage and / or memory. The state-of-the-art data may correspond to one or more different entities. The state-of-the-art data may include statistical information or data associated with each of the one or more different entities. The entities may be users, computing devices, IP addresses, etc. The profiler engine may be configured to utilize the state-of-the-art data to generate one or more statistical profiles for each of the one or more entities. In some embodiments, each profile may include trend data and / or other entity data rather than or in addition to statistical data.

[0027] The normalizer engine may be configured to normalize the state-of-storage data and / or telemetry data prior to or after receipt by the profiler engine and / or detector engine (e.g., in some embodiments, one or more detectors). The state-of-storage data and / or telemetry data may include data in a format specific to an entity and / or organization or company (e.g., an organization or company including multiple entities). Accordingly, the normalizer engine may reformat or format the state-of-storage data and / or telemetry data so that the state-of-storage data and / or telemetry data can be processed by the profiler engine and / or detector engine.

[0028] The detector engine may utilize one or more subsequences and / or threat chains organized within the multiple threat chains to generate multiple or one or more detectors. The detectors may be configured to detect defined conditions, statistics, behaviors, or other data (e.g., based on the subsequences defined and / or organized in each of the multiple threat chains). Once one or more subsequences are detected, the detector engine may aggregate each of the detected subsequences and correlate the subsequence with one of the statistical profiles. The correlation may be utilized by the detector engine to generate a score. In another embodiment, correlating the aggregated detected subsequences with one of the statistical profiles may generate a score. If the score exceeds a threshold, the detector engine may generate and transmit an alert or a high-severity alert.

[0029] Thus, the systems and methods disclosed herein are adapted to enable and / or provide a single alert regarding a high-severity threat that is comprised of a low-fidelity sequence or subsequence that may, by itself, be deemed to constitute a largely or completely inoperable activity or event. Thus, a user is notified of the actual threat, rather than of many low-fidelity sequences or subsequences that may or may not be threatening. Furthermore, such systems and methods may enable a security professional or analyst to analyze potential high-severity threats that occur less frequently than many low-fidelity sequences or subsequences, thus increasing efficiency and reducing costs and time.

[0030] As shown in Figures 1-5, the present disclosure includes systems and methods for detecting security threats. The systems and methods disclosed herein are adapted to enable the generation or generation of a curated set of malicious sequence detection rules and / or automated monitoring of malicious events or threat activity based on the curated set of malicious sequence detection rules.

[0031] 1 schematically illustrates an exemplary data center 10 that may be in communication with, or incorporated as part of, systems and methods for detecting security threats. As shown in FIG. 1, data center 10 may include a network 12 that may provide communication between a plurality of information handling systems 14, which may include workstations, personal computers, smartphones, personal digital assistants, laptop computers, servers, computing devices, other suitable devices, and / or combinations thereof. Information handling systems 14 may be further coupled to network 12 through wired connections 16, wireless connections 18, or any other suitable communication or connection line.

[0032] As further shown in FIG. 1 , in an embodiment, the data center 10 and / or one or more of its information handling systems 14 may be communicatively coupled to a network, including a cloud-based or other network such as shown at 12 or 20 in FIG. 1 , for example, through a wired connection 16 or through any other suitable connection, such as a wireless connection 18 (e.g., Wi-Fi, cellular, etc.). The network 12 may further be accessible to / by one or more users or client management information handling systems or devices 22 and may facilitate communication between the client management information handling systems 22 and the data center 10 for which rules may be generated and / or enforced. While the network 12 may include an API interface of the event management center, the network may include any suitable network, such as the Internet or other wide area network, a local area network, or a combination of networks, that may provide communication, e.g., data communication, between the event management center and the client management information handling systems 22.

[0033] The client management information handling system 22 may be connected to a network 20 (FIG. 1) through a wired connection, e.g., an Ethernet cable or other suitable wired or wireless connection 18, e.g., Wi-Fi, Bluetooth, a cellular connection (e.g., 3G, 4G, LTE, 5G, etc.), other suitable wireless connection, or a combination thereof, to enable clients or operators of the information handling system 22 to communicate with the event management center, e.g., to access one or more services provided thereby. For example, the event management center may be or include a web service.

[0034] For purposes of this disclosure, an information handling system 14 / 22 may include any means or aggregation of means operable to calculate, compute, determine, classify, process, transmit, receive, retrieve, emit, switch, store, display, communicate, reveal, detect, record, reproduce, handle, or utilize any form of information, sensitive information, or data for business, scientific, control, or other purposes. In one embodiment, an information handling system may include storage devices such as random access memory (RAM) or ROM, one or more processing resources such as a central processing unit (CPU) or hardware or software control logic, ROM, and / or other types of non-volatile memory. Additional components of an information handling system may include one or more disk drives, one or more network ports for communicating with external devices, and various input / output (I / O) devices such as a keyboard, mouse, touchscreen, and / or video display. An information handling system may also include one or more buses operable to transmit communications between various hardware components.

[0035] 2A and 2B are schematic diagrams of a system 200 for detecting security threats in accordance with one or more aspects of the present disclosure. Turning to FIG. 2A, system 200 may include a threat intelligence system 202. Threat intelligence system 202 may include one or more processors 204 and, in an embodiment, a memory or a pool of memory. In another embodiment, each engine of threat intelligence system 202 (e.g., profiler engine 210, detector engine 212, and / or normalization engine 214) may have separate or dedicated memory and / or may include memory that, in an embodiment, may have access to a pool of memory. In yet another embodiment, each engine may comprise instructions. The memory may store instructions executable by processor 204. Additionally, threat intelligence system 202 or each engine may include input / output modules configured to facilitate or enable communication between threat intelligence system 202 and external devices or components (e.g., data repository 218, entities 216A, 216B, up to 216N, and / or security computing devices 220A, 220B, up to 220N).

[0036] In an embodiment, threat intelligence system 202 may comprise a cluster (e.g., a group or set) of computing devices configured to be capable of processing large amounts of data or big data (e.g., large, complex sets of data) in substantially real time. In such an embodiment, each engine of the threat intelligence system (e.g., profiler engine 210, detector engine 212, and / or normalization engine 214) may be contained within or on and / or distributed across multiple computing devices in the cluster. Thus, the functionality of each engine may be executed and / or performed multiple times in parallel and / or on multiple computing devices with respect to different data or data sets.

[0037] Each memory included with or accessible by each engine may contain instructions, and in some embodiments, threat intelligence system 202 may further include other circuitry specific to or dedicated to performing the functionality described in connection with the instructions. In an embodiment, the instructions may be distributed across one or more memories corresponding to multiple devices (e.g., each of the instructions may be stored in multiple different memories, and / or the same instructions may be stored in multiple different memories). Such instructions (or, in an embodiment, circuitry) may include profiler engine 210, detector engine 212, and normalization engine 214. Profiler engine 210 may be configured to retrieve or request data (e.g., in an embodiment, security logs, other security data, statistical data, and / or other data) from data repository 218, or may be configured to do so when executed by a processor. Data repository 218 may be a database, a data lake, and / or other type of data storage device. The data repository 218 may store data from one or more of the entities 216A, 216B, through 216N. The data from one or more of the entities 216A, 216B, through 216N may include historical telemetry data. The historical telemetry data may be from a time period of about one day ago, about one week ago, about one month ago, about one year ago, or even a longer time period. In other words, the historical telemetry data may include historical and / or saved state data associated with one or more of the entities 216A, 216B, through 216N. In an embodiment, the profiler engine 210 may obtain data via an input / output module.

[0038] In response to receiving data from the data repository 218, the profiler engine 210 may generate one or more statistical profiles. The statistical profiles may be generated via algorithms and / or machine learning models or classifiers. A statistical profile may include the amount or totals that an entity (e.g., one or more entities 216A, 216B, up to 216N) performed an action, selected a service or application, used a service or application, visited a website, sent emails, received emails, used a cloud-based application, and / or accessed or communicated with a particular computing device or IP address, among other actions. Each statistical profile may be associated with or correspond to one or more of the entities 216A, 216B, up to 216N. A statistical profile may include an indicator that indicates which of the one or more entities 216A, 216B, up to 216N is associated with or corresponds to the statistical profile.

[0039] The instructions may include a detector engine 212. The detector engine 212 may generate one or more detectors. The one or more detectors may be based on one or more sequences or subsequences organized within a threat chain (e.g., one or more low-fidelity security threats). The one or more detectors may scan and / or analyze telemetry data from one or more entities 216A, 216B, through 216N in real time. In other words, as one or more entities 216A, 216B, through 216N access functionality or perform actions, such access and / or performance may be analyzed or scrutinized by one or more detectors. The one or more detectors may scan or analyze specific accesses to functionality and / or performance of actions (e.g., one detector may scan for use of a cloud service, receipt of emails from a specific user or set of users, etc.).

[0040] Once one or more sequences or subsequences, or a selected number of sequences or subsequences, of a threat chain have been detected, the detector engine 212 may aggregate the detected sequences or subsequences and correlate a statistical profile with the aggregated sequences or subsequences. In an embodiment, the detector engine 212 may aggregate sequences or subsequences from one or more detectors associated with the threat chain after a selected time (e.g., within about 1 minute after the first detection of the sequence or subsequence, within about 5 minutes after the first detection of the sequence or subsequence, within about 10 minutes after the first detection of the sequence or subsequence, after about 5 minutes, after about 10 minutes, after about 20 minutes, or after a longer time).

[0041] As described, after aggregation of sequences or subsequences, the detector engine 212 may correlate the aggregated sequences or subsequences with the statistical profile or corresponding statistical profiles. Such correlation may include, for example, generating a score based on a comparison between the aggregated sequences or subsequences and one or more of the statistical profiles. For example, different organizations (e.g., cloud providers) may provide data or commands in a variety of different formats. The detector engine 212 and / or normalization engine 214 may, in such an example, normalize issued commands to groups; for example, listing resources may be normalized to a reconnaissance command, while requesting an authorization token may be normalized to an authorization command. Each organization may have defined terminology for such commands; however, the detector engine 212 and / or normalization engine 214 may abstract such commands into one or more groups through normalization.

[0042] Once a score is generated, the detector engine 212 may compare the score to a threshold score. If the threshold score is exceeded, the detector engine 212 may generate an alert or a high severity alert. The detector engine 212 may transmit the alert or high severity alert to one or more security computing devices 220A, 220B, up to 220N.

[0043] In another embodiment, threat intelligence system 202 may include normalization engine 214. In some embodiments, threat intelligence system 202 may be device-agnostic. In other words, threat intelligence system 202 may analyze data (e.g., state-of-the-art data and / or real-time data) from a variety of different devices, computing devices, and / or systems. In such embodiments, threat intelligence system 202 may normalize, format, or reformat data prior to analysis via profiler engine 210 and / or detector engine 212 (or one or more detectors). Data, in such examples, may be formatted via normalization engine 214 such that the data is transformed into a unified or similar format regardless of the device or system from which the data originates. In another embodiment, the score may be determined via an account-based statistical profile (e.g., a particular user has performed a particular action only a selected number of times, but the current number of performances is anomalous), via a tenant-based profile (e.g., the activity is anomalous for the user and for other users / accounts in the organization), and / or via an IA-based profile (e.g., utilizing multiple dimensions such as the account's usual action type, time of day, frequency of command execution, number of commands, and / or type of command, where some factors are more indicative of threat activity than others). In such an embodiment, each profile may construct a multi-dimensional space in which a machine learning algorithm may determine the degree of rarity and / or anomalousness of the activity and produce a score based on various factors described above and herein.

[0044] 2B , in an embodiment, system or apparatus 200 for detecting security threats may include processing circuitry 222, at least one memory 206 (in embodiments, a set of memories, each of which may be associated with one of profiler engine 210, detector engine 212, and normalization engine 214), communications circuitry 224, normalization circuitry 226, profiler circuitry 228, and detector circuitry 230, each of which will be described in more detail below. Although the various components are illustrated in FIG. 2B as being connected only with processing circuitry 228, it should be understood that system or apparatus 200 for detecting security threats may further include a bus (not explicitly shown in FIG. 2B ) for passing information among any combination of the various components of system or apparatus 200 for detecting security threats. The system or apparatus 200 for detecting security threats may further include programming or instructions configured to perform various operations described herein, such as those described above in connection with FIGS. 1 and 2A and below in connection with FIGS. 3-5.

[0045] Processing circuitry 222 (and / or coprocessors, or any other processors supporting or otherwise associated therewith) may communicate with memory 206 via a bus to pass information between components of system or apparatus 200 for detecting security threats. Processing circuitry 222 may be embodied in several different ways and, for example, may include one or more processing devices configured to perform independently. Furthermore, processing circuitry 222 may include one or more processors configured in conjunction via a bus to enable independent execution of software instructions, pipeline processing, and / or multithreading. Use of the term “processor” may be understood to include a single-core processor, a multi-core processor, multiple processors in system or apparatus 200 for detecting security threats, a remote or “cloud” processor, or any combination thereof.

[0046] Processing circuitry 222 may be configured to execute software instructions stored in memory 206 or otherwise accessible to processing circuitry 222. In some cases, processing circuitry 222 may be configured to execute hard-coded functionality. Thus, whether configured by hardware or software methods, or a combination of hardware and software, processing circuitry 222 represents an entity or device (e.g., an element that may be physically embodied in circuitry) that may be configured accordingly while performing operations in accordance with various embodiments of the present invention. Alternatively, as another example, when processing circuitry 222 is embodied as an executor of software instructions, the software instructions, when executed, may specifically configure processing circuitry 222 to perform the algorithms and / or operations described herein.

[0047] The memory 206 may be a non-transitory machine-readable storage medium, e.g., may include one or more volatile and / or non-volatile memories. In other words, for example, the memory 206 may be an electronic storage device (e.g., a computer-readable storage medium). The memory 206 may be configured to store information, data, content, applications, software instructions, or the like to enable the device to perform various functions in accordance with the exemplary embodiments contemplated herein.

[0048] Communications circuitry 224 may include at least one device or circuitry, embodied either in hardware or a combination of hardware and software, configured to receive data from and / or transmit data to a network and / or any other device, circuitry, or module in communication with system or apparatus for detecting security threats 200. In this regard, communications circuitry 224 may include a network interface, for example, to enable communication with a wired or wireless communications network. For example, communications circuitry 224 may include one or more network interface cards, antennas, buses, switches, routers, modems, and supporting hardware and / or software, or any other devices suitable for enabling communication over a network. Additionally, communications circuitry 224 may include processing circuitry for causing the transmission of such signals to the network or for processing the reception of signals received from the network.

[0049] System or apparatus for detecting security threats 200 will generally include normalization circuitry 226 configured to normalize or format data received via system or apparatus for detecting security threats 200. For example, as system or apparatus for detecting security threats 200 obtains state-of-the-art data (e.g., from a database, data lake, etc.) and / or real-time data (e.g., from one or more entities), system or apparatus for detecting security threats 200 may normalize or format such data via normalization circuitry 226. Thus, the normalized data may be in a format that is usable and / or readable by system or apparatus for detecting security threats 200 and the circuitry therein (e.g., profiler circuitry 228 and / or detector circuitry 230).

[0050] The system or apparatus for detecting security threats 200 may include profiler circuitry 228 configured to generate one or more statistical profiles based on state-at-rest data associated with one or more entities. The state-at-rest data may be stored in a database, data lake, or other storage location. The state-at-rest data may be historical data associated with one or more entities. The generated statistical profiles may be stored in a profile database or other storage location accessible by the system or apparatus for detecting security threats 200.

[0051] The system or apparatus 200 for detecting security threats may include detector circuitry 230 configured to generate one or more detectors based on sequences, subsequences, and / or low-fidelity threats for each of one or more threat chains, monitor and / or scan telemetry and / or real-time data associated with one or more entities (e.g., via one or more detectors), detect sequences, subsequences, and / or low-fidelity threats, aggregate the detected sequences, subsequences, and / or low-fidelity threats associated with the threat chains, correlate the aggregated sequences, subsequences, and / or low-fidelity threats for the threat chains with a statistical profile, and generate a score based on the correlation. The detector circuitry 230 may generate one or more detectors as described. Each of the one or more detectors may be based on and / or configured to detect sequences, subsequences, and / or low-fidelity threats for one of the one or more threat chains.

[0052] One or more detectors may utilize the normalized real-time data to detect sequences, subsequences, and / or low-fidelity threats. Once a selected amount of sequences, subsequences, and / or low-fidelity threats of a threat chain have been detected and / or after a selected amount of time, the detector circuitry 230 may aggregate the detected sequences, subsequences, and / or low-fidelity threats of the threat chain. The detector circuitry 230 may correlate the sequences, subsequences, and / or low-fidelity threats of the threat chain with a plurality of statistical profiles or statistical profiles, thereby generating a score. The detector circuitry 230 may then generate and transmit an alert or a high-severity alert if the score exceeds a threshold score. Thus, security professionals may receive fewer, more relevant alerts and be enabled to review the alerts and take corrective action.

[0053] FIG. 3 is a schematic diagram of a system 300 that operates to detect security threats according to one aspect of the present disclosure. The system 300 may include various devices, components, and / or interfaces. The system 300 may include or interface with a security computing device A 302 (or one or more security computing devices). The security computing device A 302 may transmit a mapping and / or assignment of classes and / or sets of raw telemetry events to selected low-fidelity detectors to a configuration engine 306 (see 304). In another embodiment, the security computing device A 302 may review and refine the mapping and / or assignment. In such an embodiment, the results (e.g., alerts or absence of alerts) of the current set of low-fidelity detectors (e.g., low-fidelity detectors 328A, 328B for phases A and B) may be reviewed by the security computing device and updated or refined based on such results. In another embodiment, the security computing device may be or include a machine learning model configured and / or trained to adjust the mapping and / or assignment based on updated and labeled data (e.g., results).

[0054] Configuration engine 306 may utilize such mapping and / or assignment to define a detector configuration (see 308A and 308A). The detector configuration may be transmitted to and / or define multiple different low-fidelity detectors for different phases (e.g., low-fidelity detectors 328A, 328B for phases A and B). Although two low-fidelity detectors are illustrated in FIG. 3, additional detectors may be included in system 300.

[0055] Prior to, during, or following the definition of multiple different low-fidelity detectors for different phases, the real-time telemetry data flow 310 may be stored in a data lake or database. The data stored in the database may be in an at-rest state; in other words, after storage, the data may be static, i.e., remain the same. Thus, the data lake may be a data lake with at-rest historical telemetry 314. A profile builder 316 may pull or retrieve the data stored in the data lake and generate statistics based on the data. The statistics may be used to generate or define profiles. The profiles may be stored in a storage device 320. The storage device 320 may be a database, memory, or other storage area.

[0056] When one or more profiles are available, a service layer (e.g., a service provisioning layer 324 for servicing profile statistics) may provide the profiles directly to the low fidelity detector and / or to a system, engine, and / or circuitry associated with the correlation. A low fidelity detector (e.g., low fidelity detectors 328A, 328B for phases A and B) may listen (312) to the real-time telemetry data flow 310. If the low fidelity detector detects a specified sequence or condition, the low fidelity detector may aggregate such detections and then perform sequence correlation 330 (e.g., the aggregated sequence is correlated with the profile). Such correlation may trigger or generate a score and compare the score to a threshold. If the score exceeds the threshold, a high-severity alert 332 may be generated. The high-severity alert 332 may be transmitted to security computing device B 334 or another computing device. A security expert 338 may investigate 336 the high severity alert on or through a security computing device.

[0057] 4 is a flow diagram for detecting security threats according to one aspect of the present disclosure. FIG. 4 is a method / process for detecting malicious events according to one aspect of the present disclosure. It should also be understood that any of the diagrams described herein may implement, among other things, method 400 in FIGS. 1-3. Method 400 may be included in one or more programs, protocols, or instructions loaded into a memory of a computing device. The order in which the operations are described is not intended to be limiting, and any number of the described blocks may be combined in any order and / or in parallel to implement the disclosed method.

[0058] In block 402, a system or device (e.g., system 100 and / or system 200) may receive security data from one or more data sources. The data sources may include a database, a data lake, or some other storage device. Such data sources may receive data over time from telemetry sources. The data may include prior, past, and / or historical data associated with one or more entities.

[0059] In block 404, once the system or device receives or acquires security data, the system or device may normalize the data. In some embodiments, the system or device may be configured to be compatible with multiple various or different entities. The various or different entities may provide data in various formats. To ensure that the system or device can process data in various formats, the system or device may first normalize the data.

[0060] At block 406, the system or device may provide the normalized data to a profiler engine. At block 408, the profiler engine may generate one or more statistical profiles. The statistical profiles may include one or more statistics or other data associated with one or more entities. At block 410, the system or device may generate one or more detectors based on each sequence, subsequence, or low-fidelity security threat of one or more threat chains. A threat chain may include a series of sequences, subsequences, or low-fidelity security threats. One or more of the occurring sequences, subsequences, or low-fidelity security threats may indicate a high-severity threat. In another embodiment, the order of the sequences, subsequences, or low-fidelity security threats may or may not indicate a high-severity threat.

[0061] In block 412, the system or device may monitor telemetry data. The data may be real-time data associated with one or more entities. In block 414, the system or device may determine whether one or more of the detectors are detecting sequence, subsequence, or low-fidelity security threats. The amount or number of detections that may determine whether the system or device moves to block 416 may depend on the threat chain with which the one or more detectors are associated. If one or more detections have not occurred, or if a specified amount of detections have not occurred, the system or device may continue to monitor telemetry data. If one or more detections have occurred, or if a specified amount of detections have occurred, in block 416, the system or device may aggregate the detected one or more sequence, subsequence, or low-fidelity security threats.

[0062] In block 418, the system or device may correlate the aggregated sequences, subsequences, or low-fidelity security threats with the statistical profile and generate a score. In block 420, the system or device may determine whether the score or threat score exceeds a threshold score. If the system or device determines that the threshold score has been exceeded, the system or device may generate an alert or a high-severity alert. The system or device may continue to monitor telemetry data in real time during execution of the blocks described above.

[0063] FIG. 5 is a schematic diagram of an exemplary embodiment of an information handling system capable of implementing each of the illustrative embodiments according to an aspect of the present disclosure. FIG. 5 is a schematic diagram of an information handling system capable of implementing each of the illustrative embodiments according to an aspect of the present disclosure. Information handling system 500 may represent the systems and methods of FIGS. 1-4. Information handling system 500 may include a computer system or processor 502, such as a central processing unit (CPU), a graphics processing unit (GPU), or both. Information handling system 500 may also include a main memory 504 and a static memory 507, which may communicate with each other via a bus 508. Information handling system 500 includes an antenna and a near field communication (NFC) device and interface 518, such as an NFC subsystem.

[0064] Information handling system 500 may also include a disk drive unit 516 and a network interface device 520. As shown, information handling system 500 may further include a video display unit 510, such as a liquid crystal display (LCD), organic light-emitting diode (OLED), flat panel display, solid-state display, or cathode ray tube (CRT), or other suitable display. Video display unit 510 may also serve as an input for receiving touchscreen input. Additionally, information handling system 500 may include input devices 512, such as a keyboard, cursor control device such as a mouse or touchpad, or a selectable interface on the display unit. Information handling system 500 may also include a battery system 514. Information handling system 500 may represent a device capable of telecommunications and capable of sharing resources, voice communications, and data communications among multiple devices. Information handling system 500 may also represent a server device whose resources may be shared by multiple client devices, or it may represent an individual client device, such as a laptop or tablet personal computer.

[0065] The information handling system 500 may include a set of instructions that may be executed to cause a processor to perform any one or more of the methods or computer-based functions disclosed herein. The processor 502 may operate as a stand-alone device or may be connected to other computer systems or peripheral devices using a network, etc.

[0066] In a networked deployment, information handling system 500 may operate in a server capacity or as a client user computer in a server-client user network environment, or as a peer computer system in a peer-to-peer (or distributed) network environment. Information handling system 500 can also be implemented as or incorporated into a variety of devices, such as a personal computer (PC), tablet PC, set-top box (STB), smartphone, PDA, mobile device, palmtop computer, laptop computer, desktop computer, communication device, wireless telephone, landline telephone, control system, camera, scanning device, facsimile machine, printer, pager, personal trusted device, web appliance, network router, switch or bridge, or any other machine capable of executing (sequentially or otherwise) a set of instructions that define actions to be taken by the machine. In particular embodiments, computer system 500 can be implemented using electronic devices that provide voice, video, or data communications. Furthermore, although a single information handling system 500 is illustrated, the term "system" is also intended to include any collection of systems or subsystems that individually or collectively execute a set or sets of instructions to perform one or more computer functions.

[0067] Disk drive unit 516 or static memory 507 may include computer-readable media 522 on which one or more sets of instructions 524, such as software, may be embedded. In embodiments, disk drive unit 516 or static memory 507 also contains space for data storage. Furthermore, instructions 524 may embody one or more of the methods or logic as described herein. In particular embodiments, instructions 524 may reside, completely or at least partially, within main memory 504, static memory 506, and / or processor 502 during execution by information handling system 500. Main memory 504 and processor 502 may also include computer-readable media. Network interface device 520 may provide connectivity to a network 526, such as a wide area network (WAN), a local area network (LAN), a wireless network (IEEE 802), or other network. The network interface device 520 may also interface with a macrocellular network, including wireless telecommunications networks such as those characterized as 2G, 3G, 4G, 5G, LTE, or similar wireless telecommunications networks similar to those described above. The network interface device 520 may be a wireless adapter having an antenna system 532 for various wireless connectivity and a radio frequency subsystem 530 for signal reception, transmission, or related processing.

[0068] In alternative embodiments, dedicated hardware implementations such as application-specific integrated circuits, programmable logic arrays, and other hardware devices can be constructed to implement one or more of the methodologies described herein. Applications that may include the apparatus and systems of various embodiments can broadly include various electronic and computer systems. One or more embodiments described herein may implement functionality using two or more tangible interconnected hardware modules or devices with associated control and data signals that may be communicated between and through the modules, or as part of an application-specific integrated circuit. Thus, the system encompasses software, firmware, and hardware implementations. According to various embodiments of the present disclosure, the methods described herein may be implemented by a software program executable by a computer system. Furthermore, in exemplary, non-limiting embodiments, implementations may include distributed processing, component / object distributed processing, and parallel processing. Alternatively, a virtual computer system process can be constructed to implement one or more of the methodologies or functionality as described herein.

[0069] This disclosure contemplates computer-readable media containing instructions 524 or receiving and executing instructions 524 in response to propagated signals such that devices connected to network 528 may communicate audio, video, or data over network 528. Additionally, instructions 524 may be transmitted or received over network 528 via network interface device 520. In one exemplary embodiment, BIOS / FW code resides in memory 504 and includes machine-executable code that is executed by processor 502 to implement various functions of information handling system 500.

[0070] Information handling system 500 includes one or more application programs and basic input / output system and firmware (BIOS / FW) code that functions to initialize information handling system 500 upon power-on, launch the operating system, and manage input / output interaction between the operating system and other elements of information handling system 500.

[0071] In another embodiment (not shown), the application program and BIOS / FW code reside in another storage medium of information handling system 500. For example, the application program and BIOS / FW code may reside in disk drive unit 516, in a ROM (not shown) associated with information handling system 500, in option ROM (not shown) associated with various devices of information handling system 500, in a storage system such as static memory 507, in a storage system (not shown) associated with network channel or network interface device 520, in another storage medium of information handling system 500, or a combination thereof. The application program and BIOS / FW code may each be implemented as a single program or as separate programs that perform various features as described herein.

[0072] Although the computer-readable medium is shown to be a single medium, the term "computer-readable medium" includes a single medium or multiple media, such as a centralized or distributed database and / or associated caches and servers that store one or more sets of instructions. The term "computer-readable medium" is also intended to include any medium capable of storing, encoding, or carrying a set of instructions for execution by a processor, or causing a computer system to perform any one or more of the methods or operations disclosed herein.

[0073] In certain non-limiting exemplary embodiments, the computer-readable medium may include solid-state memory, such as a memory card or other package that stores one or more non-volatile read-only memories. Furthermore, the computer-readable medium may be random access memory or other volatile rewritable memory. Additionally, the computer-readable medium may include optical or magnetic media, such as disks or tapes or other storage devices for storing information received via carrier signals, such as signals communicated via transmission media. Furthermore, the computer-readable medium may store information received from distributed network resources, such as from a cloud-based environment. A digital file attachment to an email or other self-contained information archive or set of archives may be considered a distribution medium equivalent to a tangible storage medium. Thus, the present disclosure is considered to include any one or more of computer-readable or distribution media and other equivalent and successor media on which data or instructions may be stored.

[0074] In embodiments described herein, an information handling system includes any means or aggregation of means operable to calculate, classify, process, transmit, receive, retrieve, emit, switch, store, display, reveal, detect, record, reproduce, handle, or use any form of information, sensitive information, or data for business, scientific, control, entertainment, or other purposes. For example, an information handling system may be a personal computer, a consumer electronic device, a network server or storage device, a switch router, a wireless router, or other network communication device, a network-connected device (such as a mobile phone, tablet device, etc.), or any other suitable device, and may vary in size, shape, performance, price, and functionality.

[0075] An information handling system may include one or more processing resources, such as memory (volatile (such as random access memory), non-volatile (such as read-only memory, flash memory), or any combination thereof), a central processing unit (CPU), a graphics processing unit (GPU), hardware or software control logic, or any combination thereof. Additional components of an information handling system may include one or more storage devices, one or more communication ports for communicating with external devices, and various input / output (I / O) devices, such as a keyboard, a mouse, a video / graphics display, or any combination thereof. An information handling system may also include one or more buses operable to carry communications between the various hardware components. A portion of an information handling system may itself be considered an information handling system.

[0076] When referred to as a "device," "module," or the like, embodiments described herein may be configured as hardware. For example, part of an information handling system device may be hardware such as an integrated circuit (such as an application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), structured ASIC, or device embedded on a larger chip), a card (such as a Peripheral Component Interface (PCI) card, PCI Express card, Personal Computer Memory Card International Association (PCMCIA) card, or other such expansion card), or a system (such as a motherboard, system-on-chip (SoC), or standalone device).

[0077] This device or module is a Pentium class or PowerPC TMThe information handling system may include software, including firmware, embedded in a device such as a brand processor or other such device, or software capable of operating the relevant environment of the information handling system. The device or module may also include a combination of the foregoing embodiments of hardware or software. It is noted that the information handling system may include a board-level product having an integrated circuit or portion thereof, which may also be any combination of hardware and software.

[0078] Devices, modules, resources, or programs that communicate with each other need not be in continuous communication with each other unless explicitly specified otherwise. In addition, devices, modules, resources, or programs that communicate with each other may communicate directly or indirectly through one or more intermediaries.

[0079] The terms "computing device" or "system device" are used herein to refer to any one or all of programmable logic controllers (PLCs), programmable automation controllers (PACs), industrial computers, desktop computers, servers, clusters, virtual computers, computing nodes, nodes, personal digital assistants (PDAs), laptop computers, tablet computers, smartbooks, palmtop computers, personal computers, smartphones, wearable devices, and similar electronic devices that necessarily include at least a processor and any other physical components to perform the various operations described herein. Devices such as smartphones, laptop computers, tablet computers, and wearable devices are generally collectively referred to as mobile devices.

[0080] The terms “server” or “server device” are used herein to refer to any computing device capable of functioning as a server, such as a master exchange server, web server, mail server, document server, or any other type of server. A server may be a dedicated computing device or a server module (e.g., an application) hosted by a computing device that causes the computing device to operate as a server. A server module (e.g., a server application) may be a full-featured server module or a lite or secondary server module (e.g., a lite or secondary server application) configured to provide synchronization services between dynamic databases on the computing device. A lite or secondary server may be a slimmed-down version of server-type functionality implemented on a computing device such as a smartphone, thereby enabling it to function as an Internet server (e.g., a corporate email server) only insofar as necessary to provide the functionality described herein.

[0081] The term "non-transitory machine-readable storage medium" is used herein to refer to any electronic, magnetic, optical, or other physical storage device for containing or storing information such as executable instructions, data, and the like. For example, any machine-readable storage medium described herein may be any of random access memory (RAM), volatile memory, non-volatile memory, flash memory, a storage drive (e.g., a hard drive), a solid-state drive, any type of storage disk, and the like, or a combination thereof. The memory may store or include instructions executable by a processor.

[0082] The terms "processor" or "processing circuitry" are used herein to refer to any processor or processors contained within a single device or distributed across multiple computing devices. A processor may be at least one of a central processing unit (CPU), a semiconductor-based microprocessor, a graphics processing unit (GPU), a field programmable gate array (FPGA) for reading and executing instructions, a real-time processor (RTP), other electronic circuitry suitable for reading and executing instructions stored on a machine-readable storage medium, or a combination thereof.

[0083] The foregoing description generally illustrates and describes various embodiments of the present disclosure. However, it will be understood by those skilled in the art that various changes and modifications may be made to the above-discussed structures of the present disclosure without departing from the spirit and scope of the disclosure as disclosed herein, and that all matter contained in the above description or shown in the accompanying drawings is intended to be interpreted as illustrative and not limiting. Furthermore, the scope of the present disclosure shall be interpreted to cover various modifications, combinations, additions, alterations, etc. to the above and above-described embodiments, which shall be considered to be within the scope of the present disclosure. Thus, the various features and characteristics of the present disclosure as discussed herein may be selectively substituted and applied to other illustrated and non-illustrated embodiments of the present disclosure, and numerous variations, modifications, and additions may further be made thereto without departing from the spirit and scope of the present invention as set forth in the appended claims.

Claims

1. 1. A system for detecting security threats, comprising: Memory and at least one processor; Equipped with The at least one processor A profiler engine, the profiler engine comprising: Retrieving saved-state data corresponding to a plurality of entities from a repository; mining selected statistical information from the retrieved state-of-save data and generating a plurality of statistical profiles based on the state-of-save data, the profiles including the selected statistical information associated with each entity of the plurality of entities; storing said plurality of statistical profiles in a profile database; a profiler engine configured to: A detector engine, the detector engine comprising: generating one or more low-fidelity detectors based on the statistical profile of each entity of the plurality of entities organized into one or more threat chains, the one or more detectors configured to detect different low-security threats within the one or more threat chains; monitoring real-time data corresponding to the plurality of entities regarding the plurality of low fidelity security threats via each of the one or more detectors; generating a score based on a correlation of the detected aggregation of the plurality of low fidelity security threats with the plurality of statistical profiles; generating an alert if the score exceeds a threshold; a detector engine configured to: A system comprising:

2. The system of claim 1 , wherein the state-of-life data includes historical data and the repository comprises a data lake.

3. The system of claim 1 , wherein the plurality of entities includes one or more of users or computing devices.

4. 2. The system of claim 1, wherein each of the one or more threat chains includes a sequence of events that defines a security threat, and the score is based on an occurrence of low-level security threats in one of the one or more threat chains.

5. The system of claim 1 , wherein the score is further based on an order in which low-level security threats occur.

6. The system of claim 1 , wherein each of the plurality of statistical profiles includes a statistical analysis regarding a corresponding entity.

7. The system of claim 6 , wherein some of the plurality of profiles include statistics corresponding to services accessed by the corresponding entities.

8. receiving data from a plurality of different data sources; normalizing the data received prior to generating the plurality of profiles and storing them in the profile database; The system of claim 1 , further comprising a normalization engine configured to:

9. 1. A method for detecting security threats, the method comprising: receiving security data associated with one or more entities from a plurality of data sources; normalizing the security data to generate normalized data; providing the normalized data to a profiler engine; generating, via the profiler engine, one or more statistical profiles for the one or more entities based on the normalized data; generating one or more detectors based on one or more subsequences organized into a plurality of threat chains; monitoring telemetry data in real time for the one or more subsequences for each of the plurality of threat chains via the one or more detectors; responsive to detection by the one or more detectors of one of the plurality of threat chains of one or more subsequences, aggregating each detected one or more subsequences; generating a score based on correlation of the aggregated detected one or more subsequences with the one or more statistical profiles; generating a high severity alert if the score exceeds a threshold score; A method comprising:

10. The method of claim 9 , further comprising retrieving the state-at-rest data from a data lake prior to generating the one or more statistical profiles, the state-at-rest data comprising historical data.

11. The method of claim 9 , wherein the one or more subsequences include one or more of an event, a file associated with the event, a timestamp, or identifying data.

12. The method of claim 11 , wherein the identifying data includes one or more of a username or an IP address.

13. The method of claim 9 , further comprising storing the one or more statistical profiles in a profile database.

14. The method of claim 9 , wherein the one or more entities include one or more of a user, a server, an IP address, or other computing device.

15. The method of claim 9 , wherein at least one of the one or more entities includes a cloud-based platform user.

16. A non-transitory machine-readable storage medium storing processor-executable instructions that, when executed by at least one processor, cause the at least one processor to: responsive to receiving security data associated with one or more entities from a plurality of data sources, normalizing and storing the security data; generating one or more statistical profiles regarding the one or more entities based on the stored security data; generating one or more detectors based on one or more subsequences organized into a plurality of threat chains; monitoring telemetry data from a cloud-based platform regarding the one or more subsequences for each of the plurality of threat chains in real time via the one or more detectors; responsive to detection by the one or more detectors of one of the plurality of threat chains of one or more subsequences, aggregating each detected one or more subsequences; generating a score based on correlations of the aggregated detected one or more subsequences with the one or more entity profiles; generating a high severity alert if the score exceeds a threshold score; A non-transitory machine-readable storage medium that causes

17. 20. The non-transitory machine-readable storage medium of claim 16, wherein the one or more entities include one or more users.

18. 20. The non-transitory machine-readable storage medium of claim 17, wherein generating the one or more statistical profiles for the one or more entities comprises performing a statistical analysis of the stored security data, the statistical data comprising a number of times each of the one or more users accessed a cloud-based service on the cloud-based platform.

19. 1. A method for detecting security threats, the method comprising: storing the archived historical telemetry data in a data lake; constructing a statistical profile based on the historical storage state telemetry data in the data lake; receiving one or more definitions for one or more low fidelity detectors; generating the one or more low fidelity detectors based on the one or more definitions; listening to real-time telemetry data via the one or more low fidelity detectors; in response to detecting a low fidelity threat by the one or more low fidelity detectors, correlating the low fidelity threat with the statistical profile to generate a score; generating a high severity alert in response to the score exceeding a threshold; and A method comprising:

20. probing and refining the one or more low fidelity detectors with a security computing device; transmitting the high severity alert to the security computing device or another security computing device; 20. The method of claim 19, further comprising: