Anomaly Detection via Configuration Activity Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to accurately detect distributed attacks and previously unknown threats in computer networks, as they require resource-intensive correlation of events from multiple sources and lack universal detection rules to achieve acceptable error levels.
Innovation Solution
An extended threat database is used that includes signatures, behavior patterns, and configuration change characteristics to identify suspicious activity, eliminating the need for event correlation by analyzing configuration profiles and system events at endpoints and shared network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If event correlation from multiple network sources is performed to detect distributed attacks, then detection accuracy improves, but resource consumption increases significantly
Solution Approach 1:
The patent extracts and analyzes configuration parameters from individual endpoints independently, rather than correlating all events from multiple network sources. By focusing on local configuration changes at each endpoint, the system achieves effective threat detection without the resource-intensive process of collecting and correlating events across the entire network, thus resolving the contradiction between detection accuracy and resource consumption
Solution Approach 2:
The system segments the detection process by analyzing configuration parameters at each endpoint independently rather than performing centralized event correlation. Each endpoint's configuration changes are evaluated separately against threat intelligence data, allowing distributed attack detection to proceed with minimal resource consumption while maintaining detection effectiveness
2Device complexity
If universal detection rules are used to detect previously unknown threats, then system simplicity is maintained, but detection accuracy decreases
Solution Approach 1:
The system dynamically adapts detection rules based on configuration parameter analysis. Instead of using static universal rules, the system generates and applies customized detection rules specific to each endpoint's configuration state and observed changes, enabling accurate detection of previously unknown threats while maintaining operational simplicity through automated rule generation
Solution Approach 2:
The patent changes the detection approach from using fixed universal rules to analyzing specific configuration parameter changes at each endpoint. By monitoring how configuration parameters change over time and comparing them against threat intelligence, the system achieves high detection accuracy for unknown threats without requiring complex manual rule configuration
3Use of energy by moving object
If configuration changes are monitored at each endpoint independently, then resource consumption is reduced, but ability to detect distributed attacks diminishes
Solution Approach 1:
The system achieves universality by using the same configuration analysis methodology across all endpoints in the network. Each endpoint's configuration changes are analyzed using identical processes and threat intelligence data, enabling the system to detect distributed attacks effectively while consuming minimal resources. The universal approach allows consistent detection capabilities across the entire network without requiring resource-intensive centralized correlation
Data Source
AI summary
An anomaly detection system uses configuration-related activity profiles, generated in course of threat samples analysis in a secure testing environment, consisting of features of system events and system configurations of endpoints and shared network assets. Backup archives and activity monitors are used to collect system events and system configurations from corporate networks to analyze them with threat pattern databases including configuration-related activity profiles.


