AI Filtering Endpoint Detection Response Data for Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems struggle to efficiently analyze large volumes of endpoint detect and response (EDR) data in real-time, making it difficult to detect advanced persistent threats (APTs) that use fileless or 'living off the land' exploits.

Innovation Solution

The implementation of an AI and/or machine learning (ML) model that analyzes EDR data to identify uncommon patterns, allowing for real-time or near real-time analysis and filtering out normal activity to focus on abnormal behavior specific to a particular enterprise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security systems analyze all EDR data manually, then detection accuracy is maintained, but analysis time and resource consumption increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

An AI/ML model is introduced as an intermediary between raw EDR data and human analysts. The model automatically processes and filters EDR data, identifying and prioritizing suspicious activities while removing normal background noise. This intermediary layer maintains detection accuracy by preserving true positives while dramatically reducing the time required for manual analysis of the remaining suspicious data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical analysis of EDR data with automated AI/ML-based analysis. The system uses machine learning algorithms to automatically detect patterns, anomalies, and threats in EDR data that would be time-consuming for human analysts to identify manually, thereby reducing analysis time while maintaining or improving detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If AI/ML models analyze all EDR data in real-time, then threat detection speed improves, but computational resources and processing complexity increase

Engineering Contradiction:
Improvethreat detection speedVSAvoidprocessing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The AI/ML model performs partial analysis by focusing only on the most critical aspects of EDR data. Rather than exhaustively analyzing every single data point in real-time, the system identifies and prioritizes the most suspicious activities and anomalies, achieving effective threat detection speed improvement while managing computational complexity through selective rather than comprehensive analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the threshold for identifying uncommon EDR records is lowered, then more security threats are detected, but more false positives are generated

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system employs feedback mechanisms where the AI/ML model continuously learns from analyst corrections and outcomes. When analysts mark certain EDR records as false positives or true positives, this feedback is used to refine the model's threshold and scoring algorithms, improving threat detection reliability while progressively reducing false positive rates through iterative optimization.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250168180A1Analysis of endpoint detect and response data
Publication Date: 2025.05.22 MUSARUBRA US LLC
  • US20250168180A1 patent drawing
  • US20250168180A1 patent drawing
  • US20250168180A1 patent drawing

AI summary

There is disclosed a system and method of detecting security threats for an enterprise, including: filtering a first set of endpoint metadata records to identify a subset of metadata records, wherein filtering includes identifying endpoint security metadata records that are uncommon in context of the enterprise; and designating the subset of metadata records as indicating a potential security threat including designating the subset of metadata records for human analysis.