Context-Sensitive Labeling for Endpoint Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus and advanced persistent threat (APT) protection systems rely on platform-dependent attributes and detailed information, which limits their ability to detect malware without increasing data storage and communication overhead between endpoints and remote threat management facilities.
Innovation Solution
Implementing a context-sensitive labeling scheme for computing objects to facilitate threat detection, allowing for the characterization of complex interactions in a platform-independent manner by processing and updating labels on endpoints, and transmitting relevant information to a threat management facility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If platform-dependent attributes and detailed information are used for threat detection, then detection sensitivity is improved, but data storage and communication overhead increase
Solution Approach 1:
The patent extracts only the essential platform-independent attributes (labels) from computing objects that are relevant for threat detection, rather than transmitting all detailed information. This selective extraction maintains detection sensitivity while reducing data storage and communication overhead by filtering out unnecessary platform-specific details.
Solution Approach 2:
The patent applies different levels of labeling granularity to different computing objects based on their threat relevance. Critical objects receive more detailed labels while less critical objects receive simplified labels, optimizing the balance between detection sensitivity and data overhead by assigning quality characteristics locally to each object type.
2Measurement precision
If complex interactions of computing objects are tracked for threat detection, then threat detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent introduces labels as intermediary representations that simplify complex computing object interactions. Instead of directly analyzing complex object interactions, the system uses labels as mediators that capture essential interaction characteristics in a standardized, platform-independent format, reducing system complexity while maintaining detection accuracy.
Solution Approach 2:
The patent transforms complex computing object interaction data into simplified label parameters that can be easily processed and analyzed. By changing the representation parameters from detailed object attributes to condensed labels, the system reduces complexity while preserving the essential information needed for accurate threat detection.
Data Source
AI summary
Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.


