Context-Sensitive Labeling for Platform-Independent Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection techniques in antivirus and advanced persistent threat (APT) protection systems are limited by their reliance on platform-dependent attributes, requiring significant data storage and communication with remote threat management facilities, which can increase complexity and overhead.
Innovation Solution
Implementing a context-sensitive labeling scheme for computing objects to facilitate threat detection, allowing for the characterization of complex interactions in a platform-independent manner by processing and updating labels on endpoints, and transmitting relevant information to a threat management facility for further analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If platform-dependent attributes and detailed reputation information are used for malware detection, then detection sensitivity is improved, but data storage and communication overhead increase
Solution Approach 1:
The patent segments the detailed reputation information into discrete, standardized indicators of compromise (IOCs) that can be independently evaluated. Each IOC represents a specific aspect of object behavior or attribute, allowing the system to process and store only relevant security information rather than comprehensive platform-dependent data, thereby reducing overhead while maintaining detection sensitivity.
Solution Approach 2:
The patent transforms platform-dependent attributes into platform-independent parameters by mapping various object characteristics to a standardized set of IOCs. This parameter transformation allows the same security indicators to be evaluated across different platforms without requiring platform-specific data storage, reducing communication overhead while preserving detection accuracy.
2Measurement precision
If complex interactions of computing objects are tracked for threat detection, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent introduces standardized IOCs as intermediary elements that mediate between complex object interactions and threat detection rules. Rather than directly analyzing complex interactions, the system translates them into IOC evaluations, which then feed into simplified rule-based detection logic. This intermediary layer reduces system complexity while maintaining the ability to detect sophisticated threats.
Solution Approach 2:
The patent segments complex threat detection into modular rule sets that evaluate specific combinations of IOCs. Each rule represents a discrete detection logic unit that can be independently configured and executed, making the overall system more manageable and less complex while still capturing complex interaction patterns through coordinated rule application.
3Reliability
If extensive data is transmitted to remote threat management facility, then threat analysis capability is improved, but communication overhead and processing time increase
Solution Approach 1:
The patent extracts only the essential security-relevant information in the form of standardized IOCs from complex object interactions and transmits only these extracted indicators to the remote threat management facility. This extraction process eliminates unnecessary data transmission while preserving the core information needed for effective threat analysis, thereby reducing communication overhead and processing time without sacrificing analytical capability.
4Adaptability or versatility
If platform-independent labeling scheme is implemented, then adaptability across platforms is improved, but information granularity is reduced
Solution Approach 1:
The patent creates a universal IOC framework that can be applied across multiple platforms while maintaining rich information content. Each IOC is designed to be platform-agnostic yet capable of capturing detailed security-relevant information through standardized attribute representations. This universal framework allows the same IOC structure to function across different operating systems and environments without losing essential security information.
Data Source
AI summary
Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.


