Context-Sensitive Labeling for Platform-Independent Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection techniques in antivirus and advanced persistent threat (APT) protection systems are limited by their reliance on platform-dependent attributes, requiring significant data storage and communication with remote threat management facilities, which can increase complexity and overhead.

Innovation Solution

Implementing a context-sensitive labeling scheme for computing objects to facilitate threat detection, allowing for the characterization of complex interactions in a platform-independent manner by processing and updating labels on endpoints, and transmitting relevant information to a threat management facility for further analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If platform-dependent attributes and detailed reputation information are used for malware detection, then detection sensitivity is improved, but data storage and communication overhead increase

Engineering Contradiction:
Improvedetection sensitivityVSAvoiddata storage and communication overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the detailed reputation information into discrete, standardized indicators of compromise (IOCs) that can be independently evaluated. Each IOC represents a specific aspect of object behavior or attribute, allowing the system to process and store only relevant security information rather than comprehensive platform-dependent data, thereby reducing overhead while maintaining detection sensitivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms platform-dependent attributes into platform-independent parameters by mapping various object characteristics to a standardized set of IOCs. This parameter transformation allows the same security indicators to be evaluated across different platforms without requiring platform-specific data storage, reducing communication overhead while preserving detection accuracy.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If complex interactions of computing objects are tracked for threat detection, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces standardized IOCs as intermediary elements that mediate between complex object interactions and threat detection rules. Rather than directly analyzing complex interactions, the system translates them into IOC evaluations, which then feed into simplified rule-based detection logic. This intermediary layer reduces system complexity while maintaining the ability to detect sophisticated threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments complex threat detection into modular rule sets that evaluate specific combinations of IOCs. Each rule represents a discrete detection logic unit that can be independently configured and executed, making the overall system more manageable and less complex while still capturing complex interaction patterns through coordinated rule application.

Inventive Principle:
Principle #1Segmentation

3Reliability

If extensive data is transmitted to remote threat management facility, then threat analysis capability is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improvethreat analysis capabilityVSAvoidcommunication and processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential security-relevant information in the form of standardized IOCs from complex object interactions and transmits only these extracted indicators to the remote threat management facility. This extraction process eliminates unnecessary data transmission while preserving the core information needed for effective threat analysis, thereby reducing communication overhead and processing time without sacrificing analytical capability.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If platform-independent labeling scheme is implemented, then adaptability across platforms is improved, but information granularity is reduced

Engineering Contradiction:
Improveplatform independenceVSAvoidinformation granularity
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent creates a universal IOC framework that can be applied across multiple platforms while maintaining rich information content. Each IOC is designed to be platform-agnostic yet capable of capturing detailed security-relevant information through standardized attribute representations. This universal framework allows the same IOC structure to function across different operating systems and environments without losing essential security information.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10778725B2Using indications of compromise for reputation based network security
Publication Date: 2020.09.15 SOPHOS LTD
  • US10778725B2 patent drawing
  • US10778725B2 patent drawing
  • US10778725B2 patent drawing

AI summary

Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.