Threat control method and system
The distribution of threat detection model components across network nodes with adaptive security agent modules addresses the inefficiencies of centralized EDR systems, enabling effective and efficient threat detection in diverse environments by leveraging localized learning and collaboration.
Patent Information
- Application Number
- JP2021104988
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-06-26
- Filing Date
- 2021-06-24
- Publication Date
- 2025-12-17
- Estimated Expiration
- 2041-06-24
AI Technical Summary
Existing computer network security systems, such as EDR solutions, struggle to adapt to diverse environments and contexts, leading to inefficiencies in threat detection due to reliance on centralized processing and traditional signatures, which fail to address tailored and evolving cyber threats effectively.
A method and system for distributing components of a threat detection model across interconnected network nodes, utilizing security agent modules to collect data, share information, and generate adaptive threat detection models independently, incorporating detection logic, parameters, and core data primitives, enabling localized adaptation and collaboration among nodes.
Enhances threat detection reliability and efficiency by allowing systems to adapt to various environments and contexts, improving detection of threat agents through localized learning and collaboration, reducing reliance on centralized processing and enhancing privacy and scalability.
Smart Images

Figure 0007787656000003 
Figure 0007787656000004 
Figure 0007787656000005
Abstract
Description
[Technical Field]
[0001] The present invention relates to a threat control method in a computer network security system and a computer network security system. [Background technology]
[0002] Computer network security systems are becoming more prevalent. Examples of such systems are known as endpoint detection and response (EDR) products and services. EDR focuses on detecting and monitoring breaches as they occur, and helps determine how to best respond and / or take automated actions after a breach has occurred. The growth of EDR has been made possible in part by the emergence of machine learning, big data, and cloud computing.
[0003] In a traditional EDR or other similar system, a data collector is placed on selected network endpoints (which can be any element of your IT infrastructure). The data collector monitors activity occurring on the endpoints and sends the collected data to a central back-end system (the "EDR back-end"), which is often located in the cloud. Once the EDR back-end receives the data, it is analyzed and processed (e.g., aggregated and enhanced) before being scanned by the EDR provider for signs of compromise or anomalies.
[0004] Data volumes and threat surfaces are expanding at an enormous rate. Threats to computer systems can be tailored at high speeds, so threat security models must also evolve. Using current "simple" endpoint protection methods or simply enhancing cloud and back-end capabilities is insufficient to address the growing number of cyber threats, both file-based and fileless. However, smart endpoints also bring multiple challenges regarding increased vulnerabilities and capabilities and data privacy requirements. Therefore, traditional measures simply cannot cope with the rapid change and variety of situations encountered.
[0005] Existing solutions, such as F-Secure's (RTM) Real-Time Protection Network (ORSP) and Immunet (RTM), aim to solve these problems with a cloud-based approach. These solutions rely on traditional signatures stored in the cloud that are queried by endpoints. Therefore, when a threat is detected and blocked for one user, all other users receive the same protection. However, these solutions do not provide the best possible protection for each device as threats evolve, for example, in situations where attacks are targeted and new to each system. Furthermore, as data volumes continue to grow, a fully centralized processing approach is also less effective. Therefore, a solution that provides better and more effective protection is needed.
[0006] Furthermore, prior art solutions are unable to effectively detect threat agents in a wide variety of environments and situations, nor are they able to adapt to different situations in an efficient manner. For these reasons, there is a need for an improved computer network security system that can address attacks that are difficult to detect using conventional methods. Summary of the Invention [Problem to be solved by the invention]
[0007] The following presents a simplified summary in order to provide a basic understanding of some aspects of various invention embodiments. This summary is not an extensive overview of the invention. It is not intended to identify key or critical elements of the invention or to delineate the scope of the invention. The following summary merely presents some concepts of the invention in a simplified form as a prelude to a more detailed description of example embodiments of the invention.
[0008] For example, to reliably detect threat agents using EDR solutions, variations must be expected when processing behavior in different contexts. For example, misuse detection can be too narrow, resulting in low precision and recall, while anomaly detection systems overgenerate and suffer from a lack of visibility. Therefore, the above-mentioned techniques cannot be used equally in all environments or contexts, but instead require careful customization (i.e., parameterization) based on specific knowledge of the context in which they need to operate. [Means for solving the problem]
[0009] The present invention solves the above-mentioned problems and provides a method for optimizing how detection is reliably and efficiently specialized for various factors, e.g., endpoint and / or backend(s), in various types of environments and contexts.
[0010] According to a first aspect of the present invention, there is provided a method for distributing components of a threat detection model in a threat control network comprising interconnected network nodes as set forth in claim 1. The threat control network includes security agent modules that collect data related to each network node, share information based on the collected data within an established internal network, and generate and adapt a threat detection model related to each network node using the collected data and information received from the internal network. In the inventive solution, at least some of the nodes comprise at least the following components of the threat detection model: a detection logic portion comprising detection rules, a detection logic parameters portion comprising parameter values, and a core data primitives portion comprising a set of key primitives. The method includes distributing the components of the threat detection model to nodes independently of other components of the same node.
[0011] According to a second aspect of the present invention, there is provided a system as set forth in claim 13. The system includes a threat control network including interconnected network nodes. The threat control network includes security agent modules configured to collect data related to each network node from security agent modules, share information based on the collected data within an established internal network, and generate and adapt a threat detection model related to each network node using the collected data and information received from the internal network. At least some of the nodes include at least the following components of the threat detection model: a detection logic portion comprising detection rules, a detection logic parameters portion comprising parameter values, and a core data primitives portion comprising a set of key primitives. The system is configured to distribute the components of the threat detection model to nodes independently of other components of the same node.
[0012] According to a third aspect of the present invention there is provided a computer program product including a computer storage medium having computer code stored thereon which, when executed on a computer system, causes the system to operate as a server according to the second aspect of the present invention.
[0013] The solution of the present invention allows threat control in computer networks to be reliably and efficiently adapted to different situations and different contexts, and to effectively detect threat agents in different types of environments and contexts.
[0014] The solution of the present invention can be used, for example, in EDR solutions to facilitate operation in environments that are very different from each other and where the definition of anomalies is very context-dependent.
[0015] The solution of the present invention can be implemented on the endpoint and / or backend side.
[0016] Various exemplary and non-limiting embodiments of the present invention, both as to organization and method of operation, together with additional objects and advantages thereof, will best be understood from the following description of specific exemplary and non-limiting embodiments when read in connection with the accompanying drawings.
[0017] The verb "to comprise" is used in this specification as an open limitation which does not exclude or require the presence of unrecited features. Features recited in dependent claims may be freely combined with one another unless expressly stated otherwise.
[0018] Furthermore, throughout this specification, it will be understood that the use of the singular does not exclude a plurality.
[0019] Embodiments of the present invention are illustrated by way of example, and not by way of limitation, in the figures of the accompanying drawings. [Brief explanation of the drawings]
[0020] [Figure 1] 1 illustrates a schematic diagram of a network architecture according to an embodiment of the present invention; [Figure 2] 1 presents an exemplary distribution of threat detection model components according to an embodiment of the present invention. [Figure 3] An example solution involving two local computer networks and one security service network according to an embodiment of the present invention is presented. [Figure 4] 1 illustrates an exemplary modular organization of a security agent according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0021] FIG. 1 schematically illustrates an exemplary network architecture of an embodiment of the present invention, in which the solution of the present invention can be used. FIG. 1 schematically illustrates a portion of a first computer network 1 on which a computer system, e.g., an EDR system, is installed. Any other computer system capable of implementing embodiments of the present invention can be used instead of or in addition to the EDR system used in this example. The first computer network is connected to a security service network, here connected to a security backend / server 2 via a cloud 3. The backend / server 2 forms a node on the security service computer network for the first computer network. The security service computer network can be managed by an EDR system provider and can be separated from the cloud 3 by a gateway or other interface (not shown) or other network element appropriate to the backend 2. The first computer network 1 can also be separated from the cloud 3 by a gateway 4 or other interface. Other network structures are possible.
[0022] The first computer network 1 is formed from multiple interconnected network nodes 5a-5h, each representing an element within the computer network 1, such as a computer, smartphone, tablet, laptop, or other network-enabled hardware. Each network node 5a-5h shown in the computer network also represents an EDR endpoint on which a security agent module 6a-6h, which may include a data collector or "sensor," is installed. Security agent modules may also be installed on other elements of the computer network, such as gateways or other interfaces. In the example of FIG. 1, security agent module 4a is installed on gateway 4. Security agent modules 6a-6h, 4a, collect various types of data at nodes 5a-5h or gateway 4, including, for example, program or file hashes, files stored on nodes 5a-5h, network traffic logs, process logs, binaries or files extracted from memory (e.g., DLLs, EXEs, or memory forensic artifacts), and / or logs from monitoring actions (e.g., TCP dumps) performed by programs or scripts running on nodes 5a-5h or gateway 4.
[0023] The collected data may be stored in a database or similar model for information storage for further use. Any kind of behavioral profile / representation of the behavior of the application / service / process may further be constructed in the nodes 5a-5h by the security application, backend / server 2, and / or second server and stored in a database. The nodes 5a-5h and server 2 typically consist of a hard drive, a processor, and RAM.
[0024] Any type of data that can assist in the detection and monitoring of security threats, such as security breaches or system intrusions, can be collected by the security agent modules 6a-6h, 4a during their lifecycle. The types of data monitored and collected can be configured according to rules defined by the EDR system provider at the time of EDR system installation and / or when distributing components of the threat detection model according to the solution of the present invention. In one embodiment of the present invention, at least some of the security agent modules 6a-6h can also be capable of making decisions regarding the types of data monitored and collected. For example, the security agents 6a-6h, 4a can collect data regarding the behavior of programs running on the EDR endpoint and observe when new programs are started. If appropriate resources are available, the collected data can be permanently or temporarily stored by the security agent modules 6a-6h, 4a in an appropriate storage location on the respective network node or the first computer network 1 (not shown).
[0025] The security agent modules 6a-6h, 4a are configured to transmit information, such as the data they collect, and to send and receive instructions to and from the EDR backend 2 via the cloud 3. This allows the EDR system provider to remotely manage the EDR system without having to maintain a constant human presence at the organization managing the first computer network 1.
[0026] According to the present invention, the security agent modules 6a-6h, 4a can also be configured to establish an internal network, e.g., an internal swarm intelligence network, including the security agent modules of multiple interconnected network nodes 5a-5h of the local computer network 1. The security agent modules 6a-6h, 4a collect data related to their respective network nodes 5a-5h, and are further configured to share information based on the collected data within the established internal network. In one embodiment, the swarm intelligence network is comprised of multiple semi-independent security nodes (security agent modules) that can also function independently. Therefore, the number of instances within a swarm can vary significantly. Also, within a single local computer network, there may be multiple connected swarms that cooperate with each other.
[0027] The security agent modules 6a-6h, 4a are further configured to use the collected data and information received from the internal network to generate and adapt models associated with their respective network nodes 5a-5h. For example, if a known security threat is detected, the security agent modules 6a-6h, 4a are configured to generate and transmit security alerts to the internal network and a local center node (not shown) within the local computer network and to initiate security countermeasures to address the detected security threat. Furthermore, if an anomaly is identified that is highly likely to be a new threat, the security agent modules 6a-6h, 4a are configured to verify and contain the threat, generate a new threat model based on the collected data and received information, and share the generated new threat model with the internal network and the local center node, such as a swarm intelligence network.
[0028] One threat control method according to one embodiment of the present invention may include establishing an internal network, such as a swarm intelligence network, including security agent modules in multiple interconnected network nodes of a local computer network.
[0029] In this scenario, one or more security agent modules collect data related to their respective network nodes. The data may be collected from multiple network nodes by using various types of endpoint sensors. The collected data blocks may be referred to as events. In one embodiment, monitoring the behavior of a first suspicious event and any related events may include monitoring the behavior of a computer process and any of its child processes. In most cases, much of the collected data is not actually of suspicious origin, but the system must be vigilant to notice all malicious activity, so monitoring and data collection may remain active at all times. However, the granularity of data collection can be adjusted based on what is noticed that is of interest, either from a centralized location or by the sensors themselves.
[0030] Information based on the collected data can be shared within an established internal network. In one embodiment, the amount of information exchanged between any two security agent modules within an internal network may be greater between security agent modules located closer to each other than between security agent modules located farther away from each other. The information referenced may be, for example, aggregate information, identification of suspicious processes / users / hosts / events of interest, or the like.
[0031] The collected data and information received from the internal network can be used in the security agent module to generate and adapt models associated with each network node. The adaptive models can be configured, for example, to learn local behavior on each host, establishing a more granular understanding of normal behavior at that node and thus enabling easier detection of anomalies. When adaptation occurs locally, reacting to changes as needed can be much more efficient and rapid. In one embodiment, models used by security agent modules located near each other may behave more similarly compared to those located farther away as a result of stronger information sharing. The distance between modules need not necessarily be physical distance, but could be, for example, shared localization based on communication strength.
[0032] If a known security threat is detected, a security alert can be generated by the security agent and then sent to the internal network and a local center node in the local computer network, and any security measures can be initiated to respond to the detected security threat.
[0033] If a new threat is identified, it can be verified and included by the security agent module, which can generate a new threat model based on the collected data and received information. An example of such a model can automatically generate detection rules or probabilistic models trained on event / behavior data on that node to identify events similar to the newly observed threat. Furthermore, the generated new threat model can be shared with the internal network and local center nodes, allowing all nodes to detect similar threats in a privacy-sensitive manner.
[0034] In one embodiment, a security agent module can activate one or more components of its modular architecture and replicate itself. Additionally, if any of the security agent modules detects a need for additional resources to manage a detected security threat or a need to analyze a suspected security threat, the security agent module, in one embodiment of the present invention, can request resources from other security agent modules or even spawn a new virtual security agent module.
[0035] In one embodiment, the security agent module uses sandboxing techniques to determine a remedy for the detected security threat and / or to further analyze the behavior of the potentially malicious entity. Sandboxing may be utilized to execute suspicious code or actions in an environment where the results can be observed and the validity of the threat can be established.
[0036] In one embodiment, suspicious events among the monitored events may be detected by one or more detection mechanisms employed, hi one embodiment, the detection mechanisms used to detect suspicious events may include using at least one of a machine learning model, a scanning engine, a heuristic rule, a statistical anomaly detection, a fuzzy logic-based model, or any predetermined rule.
[0037] In one embodiment, the method may further include training the machine learning model used in detecting and / or in response to the threat by utilizing one or more of the following approaches used to train the machine learning model: distributed learning by combining local and global information and model parts; reinforcement learning by obtaining feedback on successful final results; meta-learning by utilizing external information in the learning process, and / or sharing information to bootstrap models and adjusting learning behavior.
[0038] In the inventive solution, decision-making capabilities and parameterization of the functions are independently distributed to network nodes, such as endpoints and / or backends. Functions in the context of the inventive solution may include at least one of detection rules (e.g., specific and / or heuristic), statistical logic and models, machine learning training and inference capabilities. Parameterization in the context of the inventive solution may include parameters, sets of information, data structures, and coefficients required by the above functions to operate correctly. A set of core functions may be available at the endpoints. Figure 2 illustrates an example embodiment of threat detection model distribution according to an embodiment of the present invention, where the context of the endpoints is taken into account when configuring and managing a threat control network.
[0039] In the inventive solution, this can be achieved by distributing components of a threat detection model to a node independently from other said components of the same node. The distribution of components of a threat detection model of a node can be performed independently of each other at different time instances, from different sources, and / or at different time intervals and / or update frequencies.
[0040] In the inventive solution, the threat control network may include interconnected network nodes, which may include security agent modules configured to collect data related to their respective network nodes, share information based on the collected data within an established internal network, and use the collected data and information received from the internal network to generate and adapt a threat detection model related to each network node, as described above, at least some of the nodes comprising at least the following independently distributed components of the threat detection model: a detection logic portion comprising detection rules, a detection logic parameters portion comprising parameter values, and a core data primitives portion comprising a set of key primitives.
[0041] In one embodiment of the present invention, the detection logic is updated multiple times per day, e.g., hourly or daily, and / or modified based on human input. Detection rules may contain specific detection logic that can change very frequently. In one embodiment of the present invention, the detection rules are evaluated and / or modified by a human before distribution to nodes.
[0042] In one embodiment of the present invention, the detection logic parameters include at least one of parameters that enable machine learning inference, such as membership checks and / or thresholds on the results of the machine learning model. The detection logic parameters can be kept continuously up to date, for example, by an automated system. In one embodiment of the present invention, the detection logic parameters are updated automatically by machine learning and / or multiple times per day, for example, multiple times per hour.
[0043] The core data primitives portion may include a set of key primitives that may rarely be changed. The set of key primitives may be, for example, modifiable by a human and / or may include several levels of interface to training functions, if relevant and / or necessary. In one embodiment of the present invention, the core data primitives portion is updated with software build updates and / or modified based on human input.
[0044] In the solution of the present invention, the detection logic part, the detection logic parameters part and the core data primitives part can be located and distributed independently of each other with the required flexibility.
[0045] The components of the threat detection model (detection logic portion, detection logic parameters portion, and core data primitives portion) are configured so that the components work together in a desired manner, e.g., so that the detection logic parameters are interpreted well, e.g., so that the detection logic parameters drive the detection rules. Independent updates to the components must be made in a way that does not break the consistency of the detection logic.
[0046] In one embodiment of the present invention, the detection rules, parameter values, set of key primitives, and / or detection mechanisms used to detect security threats include detection rules, parameter values, and / or key primitives related to machine learning and / or include the use of machine learning models, scanning engines, heuristic rules, statistical anomaly detection, fuzzy logic-based models, and / or predefined rules.
[0047] In one embodiment of the invention, at least some of the nodes that include the components of the threat detection model include security agent modules. In one embodiment of the invention, at least some of the nodes that include the components of the threat detection model may be part of a backend system.
[0048] In one embodiment of the present invention, each security agent module includes the components of the threat detection model and / or the components of the threat detection model are distributed across the security agents.
[0049] In one embodiment of the present invention, the threat control network is a threat control swarm intelligence network and / or the threat control swarm intelligence network includes a plurality of interconnected network nodes of a local computer network.
[0050] In one embodiment of the present invention, the security agent module is configured to collect data associated with the security agent module's respective network nodes, share information based on the collected data within an established internal network, and generate and adapt threat detection models associated with the respective network nodes using the collected data and information received from the internal network.
[0051] In the following, some examples are given for the different components of the inventive solution.
[0052] In an example of inference based on logistic regression, it is defined as follows:
number
[0053] after that, The detection rule of the detection logic can be p(x)<threshold.
[0054] The parameter values of the detection logic parameter section can be (w, b, threshold).
[0055] The set of primary primitives in the Core Data Primitives section can be: Implementation of sigmoid function and dot product.
[0056] In the example of a Gaussian kernel density estimator, it is defined as follows:
number
[0057] after that, The detection rule of the detection logic can be p(x)<threshold.
[0058] The parameter values of the detection logic parameter section are (threshold, {x1,...,x N},h).
[0059] The set of primary primitives in the Core Data Primitives section can be: Implementation of Gaussian distribution probability density function.
[0060] Figure 3 illustrates a high-level concept of one embodiment of the present invention. The example in Figure 3 shows two local computer networks 1A, 1B and a security service network 2, each of which further comprises a local center node 7, 8 and a plurality of interconnected network nodes, with a security agent module in each of the plurality of network nodes. The security agent module can be configured to establish an internal swarm intelligence network in each local computer network.
[0061] In an example of a normal mode of operation, the agent deployment structure may consist of an average of one agent residing at one endpoint, along with a local communication node and an information aggregation center (local center nodes 7 and 8). In one embodiment, as shown in Figure 4, security agents may be constructed such that at least some of their functionality, if any, is inactive, thereby allowing new agents to be replicated in roles different from those held by the original host.
[0062] In the exemplary embodiments shown in Figures 3 and 4, the detection logic parameters portion and core data primitives portion of the threat detection model may be deployed and distributed independently of one another, e.g., as described above, and / or such that the detection logic portion, detection logic parameters portion, and core data primitives portion are different on the local computer network and / or in different portions of the local computer network.
[0063] Below are described further examples of environments and operations of threat detection systems in which a distribution of threat detection components may be utilized in accordance with the present invention.
[0064] In one embodiment, one or more meta-learning models are used to generate new threat detection, action, and / or response models, and only higher-level representations of the learned information are shared with the internal swarm intelligence network and local center nodes. Additionally, for example, event abstractions may be built from the collected data to enable use of the data across precise datasets, devices, and versions.
[0065] In one embodiment, information about alerts, conditions, and other related entities is shared through the use of at least one language model, allowing the information to be interpretable by both computer systems and human experts.
[0066] The security alerts and / or the generated new threat models are transmitted from the local center node to the security service network, allowing the security service network to share the received security alerts and / or new threat models with other local computer networks and take further action based on the received security alerts and new threat detection models. In an embodiment, a partial or complete set of information for cross-local network learning in a privacy-preserving manner is transmitted between the local center node and the security service network.
[0067] Additionally, the security agent module is configured to receive instructions and / or threat detection components from the security service network to advance the operation of the security agent module for detecting and / or responding to security threats. For example, guidance related to detection and / or response actions can be received by the security agent module from a language model expert that approximates a human language model to enable interaction between a human security expert and the security agent module.
[0068] In embodiments, further actions can be taken to secure the computer network and / or any associated network nodes when a threat is detected, such as taking immediate action by changing the network node's configuration so that the attacker is stopped and any traces of their movement are not destroyed. Configuration changes can include, for example, one or more nodes (which may be computers or other devices) being switched off to preserve information in RAM, firewalls being switched on at one or more nodes to immediately shut down the attacker, network connections at one or more network nodes being slowed or blocked, suspicious files being removed or quarantined, logs being collected from the network node, a set of commands being executed on the network node, users at one or more nodes being alerted that a breach has been detected and their workstations are under investigation, and / or system updates or software patches being sent from the EDR backend to the node in response to an indication of breach being detected. In one embodiment of the present invention, one or more of these actions can be automatically initiated by the model or algorithm described above. For example, using the methods described above, data is collected and shared with nodes in the computer network and the EDR backend, and a threat model or analysis algorithm determines that an indication of breach has been detected. As soon as the model / algorithm determines that an indication of a breach has been detected, it can generate and issue commands to the relevant network nodes, without human intervention, to automatically initiate one or more of the above-mentioned actions at the nodes. By doing this, the breach can be stopped and / or damage can be automatically minimized, very quickly, and without human intervention.
[0069] Further embodiments of the threat detection model are described below as practical examples.
[0070] While it has been common in prior art solutions to assume that a large amount of intelligence is centralized or that it is necessary to have "powerful" agents, a more effective solution may be individual agents that are well-equipped but somewhat less holistic in their own capabilities and can benefit from interoperation between agents. The lack of trying to encode everything into a perfectly replicated model allows for having a model that is protected against generic model theft and evasion-type attacks, since responses from all nodes in a swarm will not be the same and therefore successful evasion techniques on one node cannot be expected to generalize across all nodes.
[0071] However, nodes should be highly connected and share information, both with nodes outside the customer premises for a central host (to enable cross-customer learning) and within a swarm located within one customer premises (where information sharing is essentially completely open). This information sharing may include data, but may also include learning about, for example, incremental model additions or specific submodels facing specific subsets of possible threats, communicated in the proposed language model used for communication.
[0072] This includes much deeper collaboration between nodes of the network that are closer to each other, or between agents that work "close" to each other (e.g., as measured by the amount of information shared between their locations), or between agents that are more similar than agents that are more distantly located, in terms of agent output and learning, allowing not only node-specific agent adaptation, but also organization-specific, and possibly team-, office-, etc.-specific, local variation of parameters and behaviors without the need to explicitly define everything. Thus, the solution of the present invention can use a swarm-type approach of multiple connected, interacting network nodes that can have the ability to replicate themselves as needed.
[0073] Prior art reinforcement learning models typically lack significant prior knowledge and thus suffer from the severe challenge of requiring vast amounts of data to learn. Here, we propose using a meta-learning model (learning how to learn), encoding information about the surrounding world (perhaps via a probabilistic state model or similar approach), and an appropriate method for information sharing among nodes. This can also be viewed as a federated transfer learning-type scenario, but the key is not to share the complete model but merely increments of the learning model, both of which are inefficient and prone to attack, but also higher-level representations of the learning information that can be applied locally. In this example of reinforcement learning, the implementation technique may or may not be based on deep learning. It could equally well be almost any other type of machine learning model found appropriate. However, the core of the concept lies in the concepts of how to learn and how to share learning. Thus, our solution can use distributed reinforcement learning with meta-learning, a world model, and information sharing.
[0074] The solution of the present invention can use a language model shared by both the AI and the human expert for information sharing. In one embodiment, coded information can be used to train the model in a language-like format. However, this can be taken a step further and used as a means for communication and guidance sharing between the AI and the expert. Instead of learning solely by receiving code or data, or learning from actions, the AI can share information in the form of sentence-like statements that can be interpreted by both the AI and the expert alike. An example of using a method for sharing guidance might be an expert making a decision to instruct an AI-driven agent to contain a node exhibiting anomalous behavior, even if no verified threat detection has yet occurred.
[0075] Another major challenge to having a model that learns appropriately in various situations, especially even in reinforcement learning-type scenarios, is the formulation of the reward function and the undesirable behavior that can result from an overly simplistic but effective reward model. In one embodiment, this is proposed to be avoided by a high-level, goal-driven reward model with smaller subcomponents that model the intended state (no intrusions), benefit from positive actions, and abstract to a level that is applicable across the system. Furthermore, rules of engagement can dictate what actions each agent can take and in what situations to neutralize potential conflicts. For these reasons, the solution of the present invention can use goal-based learning with rules of engagement to avoid undesirable behavior.
[0076] An additional component that hinders the use of such systems has been the complexity and variability of the data. Therefore, the solution of the present invention can encode multiple domains of information into event abstractions for transferability. The proposed solution, according to one embodiment, can revolve around building event abstractions of information so that the information can be used across precise data sets, devices, and versions. The abstractions can also be built from the data and can learn and update to remain current and usable, including human-interpretable components.
[0077] Next, specific examples of steps of the operation according to the embodiment will be described.
[0078] The deployment and distribution of components of the threat detection model will now be described. As described above, the solution of the present invention allows the detection logic portion, the detection logic parameters portion, and the agent's core data primitives portion to be deployed and distributed independently of one another with the necessary flexibility. In one embodiment of the present invention, all agents essentially have the same code base and / or the ability to adapt to their roles by activating different components within a modular architecture and replicating themselves, and only one initial agent needs to be deployed within a customer network with sufficient access rights to discover servers, install copies of itself in the appropriate locations, and establish internal communication networks, such as an internal cluster communication network, as well as back-end update, reporting, and communication channels. Furthermore, authentication and other necessary issues may need to be considered, and in initial implementations, agents may be deployed to individual hosts.
[0079] Let's describe typical operations: Agents continuously monitor their environment, collect data, learn from what they see, and build models of their host and its surroundings. These models are shared among swarm nodes and used, for example, to learn the behavior of users on one computer versus another in the network. Additionally, abstract information may be sent to the backend in a privacy-preserving way. Agents utilize the learning models described above to be prepared to know what is normal.
[0080] Dealing with known threats: An agent that detects either a known threat or an anomaly indicative of a known threat can immediately alert its swarm mates to the situation, prepare a threat that can deactivate them, and request additional resources if necessary (spin up new virtual agents or have them deployed from another host if there is a risk of compromise). If the agent already has the means to respond, it can take that action.
[0081] Addressing Novel Threats: Agents are constantly learning what is normal, and because of their uniqueness with their own node's data, they are also equipped to detect novel threats. Their ability to interact with users is used to verify threats, and if a threat is verified, they take action to contain it and build novel threat models that are circulated, in known language, to both swarm mates and other customers via central links. In some embodiments, if the risk of a threat is deemed too great, autonomous containment measures may be taken before a final decision is made. The degree of autonomous operation can be constantly adjusted as needed. The connectivity model also allows for the enlistment of human experts when needed.
[0082] Neutralizing Novel Threats: Agents may also include sandbox capabilities that can be utilized for safe environments and containment, allowing for the use of evolutionary approaches to discover how to neutralize novel threats (try-evaluate-mutate-try again), as well as a much more detailed understanding of the behavior of such threats and the further propagation of that information.
[0083] Sharing Novel Threat Knowledge: As novel threats are identified, they are encoded into an internal language representation for sharing centrally across agents and from there to other customers, ensuring optimal protection for all customers in a privacy-preserving manner.
[0084] Backend preparation: During operation, information about both events and threats can be abstracted and sent to the backend. This allows the backend "laboratory" to continue experimenting with more effective defense tools in a secure (sandbox-like) environment, and provides further correlation and analysis of data coming from many individual intelligent sensors.
[0085] Thus, the described model is essentially a new way to implement cybersecurity solutions across platforms, threats, and scenarios in a distributed, adaptive, yet still collaborative manner. Therefore, next-generation cybersecurity solutions may consist of swarms of autonomous, interactive, and localized AI agents, and this is one example of an approach to get there.
[0086] One embodiment of the present invention not only enables a solution for how to create and deploy large numbers of adaptive network nodes, but also allows nodes to share information and instructions among themselves and with a backend, allowing human experts to add insights and interpret findings in a way that is more locally accurate but still includes global aspects.
[0087] In one embodiment of the present invention, a swarm-type approach of multiple connected, interacting nodes that may have the ability to replicate themselves as needed is used.
[0088] In one embodiment, distributed reinforcement learning with meta-learning, world models, and information sharing is used. Additionally, a language model shared by both AI and human experts can be utilized for information sharing. In one embodiment, goal-based learning with rules of engagement is used to avoid undesirable behaviors.
[0089] In one embodiment, multiple domains of information can be encoded into the event abstraction to allow for transferability.
[0090] In general, the proposed approach introduces numerous improvements over traditional solution methods, including, for example, enabling shared learning with minimal data transfer, as well as a human-understandable means of communicating with the AI (language model). This enables learning not only from observed data, but also learning between AI agents and from human experts in a conversational model that essentially generates true next-generation dynamic adaptive swarm artificial intelligence-based EPP and / or EDR solutions.
[0091] Another improvement according to one embodiment is that by performing more actions on the client endpoint, the cost of performing purely back-end processing on ever-increasing data volumes is reduced. Furthermore, by transmitting only the data needed, often in an abstracted format, privacy concerns can be reduced. Furthermore, the use of personalized, local models can avoid the important security issues of model plagiarism and model misleading at scale; the same mistakes are not learned, and all models are not the same. Furthermore, sharing abstractions and bootstrap information instead of incremental or full models helps reduce challenges in sharing learning information caused by the complexity of the learning process.
[0092] A further improvement according to one embodiment is that the accuracy of the generated model can be optimized for local performance by using local learning of patterns specific to the customer / host. Furthermore, the local learning can be shared in a more general way across customers while maintaining the confidentiality of the customer system due to the learning abstraction used. A further improvement is also the ability to find the most appropriate preventative measures by using an evolutionary approach to prevention.
[0093] Another improvement of embodiments is that by using language model-based abstractions in addition to data sharing, human expert guidance can be incorporated into AI-driven processes. Furthermore, by using rules of engagement to control actions, AI processes can be ensured not to learn in undesirable directions when not under control. A further improvement is that constantly changing threat situations can be adapted to through dynamic learning and global use of information.
[0094] As discussed above, the nature of the model used by the system (e.g., EDR) may be or incorporate elements from one or more of: neural networks trained using a training data set, exact or heuristic rules (e.g., hard-coded logic), fuzzy logic-based modeling, and statistical inference-based modeling. Models may be defined taking into account specific patterns, files, processes, connections, and dependencies between processes.
[0095] Although the present invention has been described with reference to the preferred embodiments as described above, it should be understood that these embodiments are merely illustrative and that the claims are not limited to these embodiments. Those skilled in the art will be able to make modifications and alternatives in light of the disclosure that are believed to be within the scope of the appended claims. Each feature disclosed or exemplified herein may be incorporated into the present invention, whether alone or in any suitable combination with any other feature disclosed or exemplified herein. The lists and groups of examples provided in the above description are not exhaustive unless otherwise specified.
Claims
1. 1. A method of distributing components of a threat detection model for a threat control network including nodes that are interconnected network nodes, comprising: The threat control network comprises security agent modules that collect data related to their respective network nodes, share information based on the collected data within an established internal network, and use the collected data and information received from the internal network to generate and adapt threat detection models related to their respective network nodes; the threat detection model generated by the security agent module includes, as components, at least a detection logic section including detection rules, a detection logic parameter section including parameter values, and a core data primitive section constituting a set of key primitives; and for the security agent module, each of the components of the threat detection model is distributed independently of each other, and the threat detection model is updated to an individualized threat detection model for each node; the distribution of the components of the threat detection model is performed independently from each other at different time instances and / or at different time intervals and / or update frequencies from different sources; method.
2. 10. The method of claim 1, wherein the detection rules, the parameter values, the set of key primitives, and / or the detection mechanism used to detect security threats include machine learning, parameter values, and / or key primitives associated with the detection rules, and / or include using machine learning models, scanning engines, heuristic rules, statistical anomaly detection, fuzzy logic-based models, and / or predetermined rules.
3. The method of claim 1 or 2, wherein at least some of the nodes that include the components of the threat detection model include security agent modules.
4. The method of any one of claims 1 to 3, wherein at least some of the nodes that include the components of the threat detection model are part of a backend system.
5. The method of any one of claims 1 to 4, wherein each security agent module includes the components of the threat detection model and / or the components of the threat detection model are distributed to security agents.
6. The method of any one of claims 1 to 5, wherein the detection logic is updated multiple times per day, for example hourly or daily, and / or modified based on human input.
7. The method according to any one of claims 1 to 6, wherein the detection logic parameters are updated automatically by machine learning and / or multiple times per day, for example multiple times per hour.
8. The method according to any one of claims 1 to 7, wherein the detection logic parameter portion includes at least one of parameters that enable machine learning inference, such as membership checks, thresholds for results of machine learning models, etc.
9. The method of any one of claims 1 to 8, wherein the core data primitives portion is updated with software build updates and / or modified based on human input.
10. 10. The method of claim 1, wherein the threat control network is a threat control swarm intelligence network, and / or the threat control swarm intelligence network comprises a plurality of interconnected network nodes of a local computer network.
11. A method as claimed in any one of claims 1 to 9, wherein a security agent module is configured to collect data relating to each network node of the security agent module, share information based on the collected data within the established internal network, and use the collected data and information received from the internal network to generate and adapt a threat detection model relating to each network node.
12. 1. A system comprising a threat control network including nodes that are interconnected network nodes, the threat control network includes security agent modules configured to collect data associated with respective network nodes of the security agent modules, share information based on the collected data within an established internal network, and use the collected data and information received from the internal network to generate and adapt threat detection models associated with the respective network nodes; the threat detection model generated by the security agent module includes, as components, at least a detection logic section including detection rules, a detection logic parameter section including parameter values, and a core data primitive section constituting a set of key primitives; each of the components of the threat detection model is distributed independently of one another, and the threat detection model is updated to an individualized threat detection model for each node; the distribution of the components of the threat detection model is configured to be performed independently from each other at different time instances and / or at different time intervals and / or update frequencies from different sources; system.
13. The system of claim 12, further configured to perform a method according to any one of claims 2 to 11.
14. A computer program comprising computer readable code which, when executed on a computer system or server, causes said computer system or server to operate as the system of claim 12.
15. A computer program product having the computer program of claim 14 stored on a computer-readable medium.
Citation Information
Patent Citations
Fraud detecting and risk assessing method and system, equipment and storage medium
CN108596434A
Inspection method for cargo and its system
JP2017097853A
Collaborative and Adaptive Threat Intelligence for Computer Security
US20150373043A1
Implementing network security measures in response to a detected cyber attack
US20180367550A1
Malware detection using local computational models
US20190026466A1