Context-Sensitive Labeling for Endpoint Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus and advanced persistent threat (APT) protection systems rely on platform-dependent attributes and detailed information, leading to a need for more sensitive malware detection techniques that do not increase data storage and communication overhead between endpoints and remote threat management facilities.

Innovation Solution

Implementing a context-sensitive labeling scheme for computing objects to track and correlate data, allowing for platform-independent threat detection by applying rules based on object interactions and label changes, which are pre-processed on endpoints without significant communication with a remote threat management facility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If detailed information and platform-dependent attributes are collected for threat detection, then detection sensitivity is improved, but data storage and communication overhead increase

Engineering Contradiction:
Improvedetection sensitivityVSAvoiddata storage overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential behavioral attributes and interaction patterns needed for threat detection, discarding redundant detailed information. By focusing on specific behavioral metrics rather than comprehensive system states, the solution achieves effective malware detection while minimizing data storage requirements at endpoints and communication overhead with remote facilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments threat detection into local behavioral monitoring at endpoints and remote analysis of aggregated behavior patterns. This segmentation allows endpoints to collect only relevant behavioral data locally, process it independently, and communicate only essential findings remotely, thereby reducing both storage overhead and communication bandwidth requirements while maintaining detection sensitivity.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If detailed information and platform-dependent attributes are collected for threat detection, then detection sensitivity is improved, but communication overhead increases

Engineering Contradiction:
Improvedetection sensitivityVSAvoidcommunication overhead
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts and transmits only the essential behavioral indicators and threat-relevant information from endpoint activities, filtering out redundant detailed data before communication. This extraction approach maintains detection sensitivity by preserving critical behavioral patterns while significantly reducing the volume of data communicated between endpoints and remote threat management facilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If complex interactions of computing objects are tracked, then threat detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces behavioral models and interaction patterns as intermediary representations that simplify the tracking of complex computing object interactions. Instead of monitoring every detailed interaction, the system uses predefined behavioral models to represent typical malware and legitimate software patterns, making the tracking system more manageable while maintaining effective threat detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10965711B2Data behavioral tracking
Publication Date: 2021.03.30 SOPHOS LTD
  • US10965711B2 patent drawing
  • US10965711B2 patent drawing
  • US10965711B2 patent drawing

AI summary

Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.