Application Behavior Control via Event Profile Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures struggle to effectively detect and manage malicious applications that mimic benign ones, as they often require complex configuration and deep knowledge of application behavior, making it challenging to balance security and usability.

Innovation Solution

The solution involves grouping applications into clusters based on predefined event profiles, monitoring their actions, and allowing or blocking specific events, with a centralized backend system managing decision logic to enhance application control and provide risk assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are made more restrictive to improve security detection, then security value is improved, but system usability deteriorates and the system may become locked

Engineering Contradiction:
Improvesecurity valueVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically learns and adapts to application behavior patterns without requiring manual configuration by administrators. The behavioral analysis engine autonomously monitors applications, identifies malicious patterns, and adjusts security policies dynamically, eliminating the need for complex manual rule-setting while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policies are made dynamic rather than static. The system continuously monitors application behavior and adjusts security restrictions in real-time based on detected patterns. This allows the system to be restrictive when threats are detected while remaining permissive during normal operation, thus maintaining both security and usability.

Inventive Principle:
Principle #15Dynamics

2Reliability

If manual configuration of security policies is performed to improve detection accuracy, then security value is improved, but configuration complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs automatic behavioral analysis and policy generation without requiring administrator intervention. The behavioral analysis engine autonomously collects data, identifies patterns, and configures security policies based on learned behavior, eliminating complex manual configuration while maintaining high detection accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where security outcomes are monitored and used to automatically refine detection algorithms and policies. This self-learning mechanism improves detection accuracy over time without requiring manual reconfiguration, as the system adapts based on observed security events and patterns.

Inventive Principle:
Principle #23Feedback

3Reliability

If behavioral analysis is implemented to improve malicious application detection, then detection capability is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies behavioral analysis selectively rather than uniformly to all applications. Low-risk applications with established benign patterns receive minimal monitoring, while applications exhibiting suspicious or unknown behavior undergo more intensive analysis. This partial application of resources maintains high detection capability for threats while reducing overall resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11188644B2Application behaviour control
Publication Date: 2021.11.30 WITHSECURE CORP (A K A WITHSECURE OYJ)
  • US11188644B2 patent drawing
  • US11188644B2 patent drawing
  • US11188644B2 patent drawing

AI summary

There is provided a method for application behaviour control on a computer system. The method includes grouping applications into a set of clusters, wherein each application is grouped to a specific cluster on the basis of predefined event profiles for applications in the specific cluster; monitoring procedures that a specific cluster performs on one or more computer devices; and generating a list of expected events and prohibited events of the specific cluster based on monitoring for enabling the one or more client computer devices and/or an administrator of the one or more client computer devices to take further action related to the applications installed on the one or more client computer devices.