Composite Event Detection for Multifaceted Security Threats
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security monitoring and anomaly detection systems struggle to effectively identify multifaceted security threats within complex compute environments, often missing subtle deviations from normal behavior due to the sheer volume and variability of data.
Innovation Solution
A data platform is configured to ingest and process data from a cloud environment, utilizing agents deployed on compute assets to collect and report information. The platform generates composite events and graphs, such as insider behavior graphs and privilege change graphs, to facilitate interactive analysis and detect anomalies in real-time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional anomaly detection systems process data from compute environments, then they can identify security threats, but they fail to detect subtle deviations due to the sheer volume and variability of data
Solution Approach 1:
The system segments the compute environment into distinct compute assets (virtual machines, containers, servers) and tracks their individual behaviors separately. By dividing the complex data into asset-level units with specific behavior patterns, the system can process large volumes of data while maintaining precision in detecting subtle deviations from normal behavior for each asset.
Solution Approach 2:
The patent introduces a temporal dimension by tracking behavior over time and establishing baselines of normal behavior patterns. It also adds a contextual dimension by considering relationships between assets and their environments. This dimensional expansion allows the system to detect subtle anomalies that would be invisible in raw data volume alone.
2Speed
If the system monitors all compute assets in real-time, then security threats can be detected promptly, but the complexity of processing and analyzing the data increases
Solution Approach 1:
The system performs preliminary actions by establishing baselines of normal behavior for each compute asset before security incidents occur. It continuously updates these baselines with expected behavior patterns, so when anomalies occur, the system already has the reference framework needed for rapid detection and response without complex real-time analysis.
Solution Approach 2:
Each compute asset essentially monitors itself by tracking its own behavior patterns, resource usage, and operational state. The assets provide their own behavioral data and context, reducing the complexity of centralized processing while enabling real-time security monitoring across the entire compute environment.
Data Source
AI summary
Data platforms described herein are configured to monitor a compute environment and to create and present composite events indicative of multifaceted security threats within the compute environment. Such a data platform may detect both a first event that occurs within the compute environment and is associated with a first alert score and a second event that occurs within the compute environment and is associated with a second alert score. The data platform may then identify an affiliation between the first event and the second event based on a predefined criteria of a multifaceted security threat. Based on the identifying of the affiliation, the data platform may present the first and second events as a composite event indicative of the multifaceted security threat and associated with a third alert score different from the first and second alert scores. Corresponding methods, systems, and products are also disclosed.


