Context-Sensitive Labeling for Endpoint Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus and advanced persistent threat (APT) protection systems rely on platform-dependent attributes and detailed information, which limits their ability to detect malware without increasing data storage and communication overhead between endpoints and remote threat management facilities.

Innovation Solution

Implementing a context-sensitive labeling scheme for computing objects to facilitate threat detection, allowing for the characterization of complex interactions in a platform-independent manner by processing and updating labels on endpoints, and transmitting relevant information to a threat management facility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If platform-dependent attributes and detailed information are used for threat detection, then detection sensitivity is improved, but data storage and communication overhead increase

Engineering Contradiction:
Improvedetection sensitivityVSAvoiddata storage and communication overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential platform-independent attributes (labels) from computing objects that are relevant for threat detection, rather than transmitting all detailed information. This selective extraction maintains detection sensitivity while reducing data storage and communication overhead by filtering out unnecessary platform-specific details.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different levels of labeling granularity to different computing objects based on their threat relevance. Critical objects receive more detailed labels while less critical objects receive simplified labels, optimizing the balance between detection sensitivity and data overhead by assigning quality characteristics locally to each object type.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If complex interactions of computing objects are tracked for threat detection, then threat detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces labels as intermediary representations that simplify complex computing object interactions. Instead of directly analyzing complex object interactions, the system uses labels as mediators that capture essential interaction characteristics in a standardized, platform-independent format, reducing system complexity while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms complex computing object interaction data into simplified label parameters that can be easily processed and analyzed. By changing the representation parameters from detailed object attributes to condensed labels, the system reduces complexity while preserving the essential information needed for accurate threat detection.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10673902B2Labeling computing objects for improved threat detection
Publication Date: 2020.06.02 SOPHOS LTD
  • US10673902B2 patent drawing
  • US10673902B2 patent drawing
  • US10673902B2 patent drawing

AI summary

Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.