Application Profile Definitions for Behavioral Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional defense mechanisms are inadequate in detecting and thwarting behavioral anomalies in applications, as they lack context and fail to identify emerging threats, especially in environments with increased attack surfaces due to BYOD and IoT, where internal compromises and social engineering are common.

Innovation Solution

A system and method for defining and modeling application profile definitions (APDs) based on monitoring application behavior, using modular components like Application-Role definition, Telemetry Acquisition, Behavior learning, Anomaly detection, and Profile customization, which express behavioral metrics and generate alerts when deviations occur, allowing for real-time anomaly detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional defense mechanisms (malware detection, virus detection, perimeter fencing) are used, then implementation is simple, but detection capability for behavioral anomalies is insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security monitoring into distinct functional modules: Application-Role definition module, Telemetry Acquisition module, Behavior learning module, Anomaly detection module, and Profile customization module. Each module handles a specific aspect of security monitoring, making the complex detection capability manageable and implementable through modular components rather than a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of Application Profile Definitions (APDs) that mediates between raw telemetry data and security policies. APDs translate complex behavioral expectations into a standardized format that can be universally applied across different applications and roles, simplifying the matching process between observed behavior and expected behavior without requiring complex custom rules for each scenario.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If known anomalous patterns are matched, then detection is straightforward, but emerging anomalous behaviors are not identified

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddetection of emerging threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by defining expected application behaviors through Application Profile Definitions before anomalies occur. By establishing baseline behavior profiles for applications in their normal state, the system can detect deviations from these pre-defined expectations, enabling detection of emerging threats that don't match known anomaly patterns but still represent abnormal behavior.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic behavior profiling where application profiles are continuously updated based on observed telemetry data. The behavior learning module adapts profiles over time to account for legitimate changes in application behavior, allowing the system to detect truly anomalous behaviors while adapting to evolving normal operations, thus maintaining high detection accuracy for emerging threats.

Inventive Principle:
Principle #15Dynamics

3Productivity

If application behavior monitoring is implemented, then real-time anomaly detection is enabled, but system complexity increases

Engineering Contradiction:
Improvereal-time response capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal monitoring framework where a single set of modules and APD format can be applied across all applications and roles in the enterprise. The Telemetry Acquisition module, Behavior learning module, and Anomaly detection module serve multiple functions for different applications, eliminating the need for separate monitoring systems for each application and reducing overall system complexity while maintaining real-time capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by transforming diverse application-specific behavior parameters into a standardized set of telemetry metrics and APD format. By normalizing different application behaviors into a common parameter space, the system can process and compare behavior across applications efficiently, enabling real-time monitoring without requiring complex application-specific analysis logic for each scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230421592A1Application profile definition for cyber behaviors
Publication Date: 2023.12.28 TRUEFORT INC
  • US20230421592A1 patent drawing
  • US20230421592A1 patent drawing
  • US20230421592A1 patent drawing

AI summary

The invention relates to computer security, and specifically to a method and system for defining the profile of expected application behaviors. According to one aspect, multiple application behavioral metric definitions are expressed for expected application interactions and state on a temporal basis. At least some of the behavioral definition metrics are expressed based on an association with an application profile or common entity. The expressed application profile definitions (APDs) are utilized to evaluate whether actual behavioral conditions specified by application profile white lists, policies and or security policies associated with the common entity have been satisfied. APDs are a defined set of metrics that can be expressed using the APD creator wizard or express using XLM, Json or any other software definition format. Responsive to evaluating that a APD behavioral condition has been deviated, an alert is generated and communicated to one or more response devices associated with the common entity.