Application Profile Definitions for Behavioral Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional defense mechanisms are inadequate in detecting and thwarting behavioral anomalies in applications, as they lack context and fail to identify emerging threats, especially in environments with increased attack surfaces due to BYOD and IoT, where internal compromises and social engineering are common.
Innovation Solution
A system and method for defining and modeling application profile definitions (APDs) based on monitoring application behavior, using modular components like Application-Role definition, Telemetry Acquisition, Behavior learning, Anomaly detection, and Profile customization, which express behavioral metrics and generate alerts when deviations occur, allowing for real-time anomaly detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional defense mechanisms (malware detection, virus detection, perimeter fencing) are used, then implementation is simple, but detection capability for behavioral anomalies is insufficient
Solution Approach 1:
The system segments security monitoring into distinct functional modules: Application-Role definition module, Telemetry Acquisition module, Behavior learning module, Anomaly detection module, and Profile customization module. Each module handles a specific aspect of security monitoring, making the complex detection capability manageable and implementable through modular components rather than a monolithic system.
Solution Approach 2:
The patent introduces an intermediary layer of Application Profile Definitions (APDs) that mediates between raw telemetry data and security policies. APDs translate complex behavioral expectations into a standardized format that can be universally applied across different applications and roles, simplifying the matching process between observed behavior and expected behavior without requiring complex custom rules for each scenario.
2Reliability
If known anomalous patterns are matched, then detection is straightforward, but emerging anomalous behaviors are not identified
Solution Approach 1:
The system performs preliminary action by defining expected application behaviors through Application Profile Definitions before anomalies occur. By establishing baseline behavior profiles for applications in their normal state, the system can detect deviations from these pre-defined expectations, enabling detection of emerging threats that don't match known anomaly patterns but still represent abnormal behavior.
Solution Approach 2:
The patent implements dynamic behavior profiling where application profiles are continuously updated based on observed telemetry data. The behavior learning module adapts profiles over time to account for legitimate changes in application behavior, allowing the system to detect truly anomalous behaviors while adapting to evolving normal operations, thus maintaining high detection accuracy for emerging threats.
3Productivity
If application behavior monitoring is implemented, then real-time anomaly detection is enabled, but system complexity increases
Solution Approach 1:
The patent creates a universal monitoring framework where a single set of modules and APD format can be applied across all applications and roles in the enterprise. The Telemetry Acquisition module, Behavior learning module, and Anomaly detection module serve multiple functions for different applications, eliminating the need for separate monitoring systems for each application and reducing overall system complexity while maintaining real-time capability.
Solution Approach 2:
The system manages complexity by transforming diverse application-specific behavior parameters into a standardized set of telemetry metrics and APD format. By normalizing different application behaviors into a common parameter space, the system can process and compare behavior across applications efficiently, enabling real-time monitoring without requiring complex application-specific analysis logic for each scenario.
Data Source
AI summary
The invention relates to computer security, and specifically to a method and system for defining the profile of expected application behaviors. According to one aspect, multiple application behavioral metric definitions are expressed for expected application interactions and state on a temporal basis. At least some of the behavioral definition metrics are expressed based on an association with an application profile or common entity. The expressed application profile definitions (APDs) are utilized to evaluate whether actual behavioral conditions specified by application profile white lists, policies and or security policies associated with the common entity have been satisfied. APDs are a defined set of metrics that can be expressed using the APD creator wizard or express using XLM, Json or any other software definition format. Responsive to evaluating that a APD behavioral condition has been deviated, an alert is generated and communicated to one or more response devices associated with the common entity.


