Context-Sensitive Labeling for Endpoint Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection techniques rely on platform-dependent attributes and require significant data storage and communication with remote threat management facilities, limiting their sensitivity and efficiency in detecting threats without increasing storage and communication overhead.

Innovation Solution

Implementing a context-sensitive labeling scheme for computing objects to facilitate threat detection by processing and correlating labels on endpoints, allowing for platform-independent threat characterization and rule-based detection without extensive communication with remote facilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If platform-dependent attributes and detailed information are used for malware detection, then detection sensitivity is improved, but data storage and communication overhead increase

Engineering Contradiction:
Improvedetection sensitivityVSAvoiddata storage and communication overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential platform-independent attributes needed for threat detection while discarding redundant platform-specific details. The labeling scheme focuses on extracting critical behavioral characteristics and interaction patterns that indicate threats, rather than storing all available platform-dependent information about computing objects.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of starting with detailed platform-dependent attributes and filtering them, the patent inverts the approach by directly creating platform-independent labels that capture threat-relevant information. The system generates simplified labels that represent complex object interactions in a universal format, eliminating the need to process and store extensive platform-specific data.

Inventive Principle:
Principle #13The other way round (Inversion)

2Measurement precision

If complex interactions of computing objects are tracked for threat detection, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments complex object interactions into discrete, labelable events and attributes. By breaking down interactions into specific categories (creation, deletion, modification, access) and assigning standardized labels to each, the system manages complexity through structured decomposition rather than attempting to analyze all interactions as a monolithic problem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms complex interaction data into simplified parameter representations through standardized labeling. Each computing object and interaction is represented by a set of defined parameters (labels) that capture essential threat-relevant information while reducing the complexity of raw interaction data into manageable, comparable attributes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10516531B2Key management for compromised enterprise endpoints
Publication Date: 2019.12.24 SOPHOS LTD
  • US10516531B2 patent drawing
  • US10516531B2 patent drawing
  • US10516531B2 patent drawing

AI summary

Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.