Anomaly Detection via Configuration Activity Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to accurately detect distributed attacks and previously unknown threats in computer networks, as they require resource-intensive correlation of events from multiple sources and lack universal detection rules to achieve acceptable error levels.

Innovation Solution

An extended threat database is used that includes signatures, behavior patterns, and configuration change characteristics to identify suspicious activity, eliminating the need for event correlation by analyzing configuration profiles and system events at endpoints and shared network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If event correlation from multiple network sources is performed to detect distributed attacks, then detection accuracy improves, but resource consumption increases significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts and analyzes configuration parameters from individual endpoints independently, rather than correlating all events from multiple network sources. By focusing on local configuration changes at each endpoint, the system achieves effective threat detection without the resource-intensive process of collecting and correlating events across the entire network, thus resolving the contradiction between detection accuracy and resource consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the detection process by analyzing configuration parameters at each endpoint independently rather than performing centralized event correlation. Each endpoint's configuration changes are evaluated separately against threat intelligence data, allowing distributed attack detection to proceed with minimal resource consumption while maintaining detection effectiveness

Inventive Principle:
Principle #1Segmentation

2Device complexity

If universal detection rules are used to detect previously unknown threats, then system simplicity is maintained, but detection accuracy decreases

Engineering Contradiction:
Improvesystem simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system dynamically adapts detection rules based on configuration parameter analysis. Instead of using static universal rules, the system generates and applies customized detection rules specific to each endpoint's configuration state and observed changes, enabling accurate detection of previously unknown threats while maintaining operational simplicity through automated rule generation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection approach from using fixed universal rules to analyzing specific configuration parameter changes at each endpoint. By monitoring how configuration parameters change over time and comparing them against threat intelligence, the system achieves high detection accuracy for unknown threats without requiring complex manual rule configuration

Inventive Principle:
Principle #35Parameter changes

3Use of energy by moving object

If configuration changes are monitored at each endpoint independently, then resource consumption is reduced, but ability to detect distributed attacks diminishes

Engineering Contradiction:
Improveresource consumptionVSAvoiddistributed attack detection capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system achieves universality by using the same configuration analysis methodology across all endpoints in the network. Each endpoint's configuration changes are analyzed using identical processes and threat intelligence data, enabling the system to detect distributed attacks effectively while consuming minimal resources. The universal approach allows consistent detection capabilities across the entire network without requiring resource-intensive centralized correlation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12341801B2System and method of anomaly detection with configuration-related activity profiles
Publication Date: 2025.06.24 ACRONIS INT
  • US12341801B2 patent drawing
  • US12341801B2 patent drawing
  • US12341801B2 patent drawing

AI summary

An anomaly detection system uses configuration-related activity profiles, generated in course of threat samples analysis in a secure testing environment, consisting of features of system events and system configurations of endpoints and shared network assets. Backup archives and activity monitors are used to collect system events and system configurations from corporate networks to analyze them with threat pattern databases including configuration-related activity profiles.