Context-Sensitive Labeling for Endpoint Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection techniques rely on platform-dependent attributes and require significant data storage and communication with remote threat management facilities, limiting their sensitivity and efficiency in detecting threats without increasing storage and communication overhead.
Innovation Solution
Implementing a context-sensitive labeling scheme for computing objects to facilitate threat detection by processing and correlating labels on endpoints, allowing for platform-independent threat characterization and rule-based detection without extensive communication with remote facilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If platform-dependent attributes and detailed information are used for malware detection, then detection sensitivity is improved, but data storage and communication overhead increase
Solution Approach 1:
The patent extracts only the essential platform-independent attributes needed for threat detection while discarding redundant platform-specific details. The labeling scheme focuses on extracting critical behavioral characteristics and interaction patterns that indicate threats, rather than storing all available platform-dependent information about computing objects.
Solution Approach 2:
Instead of starting with detailed platform-dependent attributes and filtering them, the patent inverts the approach by directly creating platform-independent labels that capture threat-relevant information. The system generates simplified labels that represent complex object interactions in a universal format, eliminating the need to process and store extensive platform-specific data.
2Measurement precision
If complex interactions of computing objects are tracked for threat detection, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments complex object interactions into discrete, labelable events and attributes. By breaking down interactions into specific categories (creation, deletion, modification, access) and assigning standardized labels to each, the system manages complexity through structured decomposition rather than attempting to analyze all interactions as a monolithic problem.
Solution Approach 2:
The patent transforms complex interaction data into simplified parameter representations through standardized labeling. Each computing object and interaction is represented by a set of defined parameters (labels) that capture essential threat-relevant information while reducing the complexity of raw interaction data into manageable, comparable attributes.
Data Source
AI summary
Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.


