Context-Sensitive Labeling for Endpoint Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus and advanced persistent threat (APT) protection systems rely on platform-dependent attributes and detailed information, leading to a need for more sensitive malware detection techniques that do not increase data storage and communication overhead between endpoints and remote threat management facilities.
Innovation Solution
Implementing a context-sensitive labeling scheme for computing objects to track and correlate data, allowing for platform-independent threat detection by applying rules based on object interactions and label changes, which are pre-processed on endpoints without significant communication with a remote threat management facility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If detailed information and platform-dependent attributes are collected for threat detection, then detection sensitivity is improved, but data storage and communication overhead increase
Solution Approach 1:
The patent extracts only the essential behavioral attributes and interaction patterns needed for threat detection, discarding redundant detailed information. By focusing on specific behavioral metrics rather than comprehensive system states, the solution achieves effective malware detection while minimizing data storage requirements at endpoints and communication overhead with remote facilities.
Solution Approach 2:
The patent segments threat detection into local behavioral monitoring at endpoints and remote analysis of aggregated behavior patterns. This segmentation allows endpoints to collect only relevant behavioral data locally, process it independently, and communicate only essential findings remotely, thereby reducing both storage overhead and communication bandwidth requirements while maintaining detection sensitivity.
2Measurement precision
If detailed information and platform-dependent attributes are collected for threat detection, then detection sensitivity is improved, but communication overhead increases
Solution Approach 1:
The patent extracts and transmits only the essential behavioral indicators and threat-relevant information from endpoint activities, filtering out redundant detailed data before communication. This extraction approach maintains detection sensitivity by preserving critical behavioral patterns while significantly reducing the volume of data communicated between endpoints and remote threat management facilities.
3Reliability
If complex interactions of computing objects are tracked, then threat detection capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces behavioral models and interaction patterns as intermediary representations that simplify the tracking of complex computing object interactions. Instead of monitoring every detailed interaction, the system uses predefined behavioral models to represent typical malware and legitimate software patterns, making the tracking system more manageable while maintaining effective threat detection capability.
Data Source
AI summary
Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.


