Early Malware Detection Using Sequential Endpoint Attack Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security tools struggle to detect sustained and targeted malware attacks across a large and complex network attack surface, failing to provide early warning of potential breaches despite successful defense of individual incidents.

Innovation Solution

A system that identifies patterns of sequential malware tool usage across multiple endpoints, grouping indicators of breach to detect progressive deployment of malware, particularly for ransomware attacks, and notifies customers of potential breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network security tools are used to detect individual malware incidents, then individual attack detection capability is improved, but ability to detect sustained targeted attacks across the entire network deteriorates

Engineering Contradiction:
Improveindividual attack detectionVSAvoidsustained attack detection
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple individual malware detection results into a unified analysis framework that evaluates sequential patterns across the entire network. By merging isolated detection events into a comprehensive attack narrative, the system detects sustained targeted attacks that individual tools would miss.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds a temporal and sequential dimension to malware detection by analyzing the order and progression of different malware tools across multiple endpoints. This transforms detection from a static, single-point analysis to a dynamic, multi-dimensional pattern recognition system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Area of stationary object

If security monitoring is implemented across the entire network, then comprehensive attack surface coverage is improved, but complexity of detection and analysis deteriorates

Engineering Contradiction:
Improveattack surface coverageVSAvoidattack pattern analysis
Core Design Contradiction:
Area of stationary objectVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the complex network attack surface into manageable components by analyzing malware detections at individual endpoints first, then progressively combining these segments into broader attack patterns. This hierarchical segmentation makes comprehensive monitoring tractable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary analysis layer that processes raw malware detection data from multiple endpoints and transforms it into meaningful attack patterns. This intermediary layer simplifies the complexity by providing structured intermediate representations that bridge raw data and final conclusions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If reactive security response is used after breach detection, then individual incident response is improved, but proactive prevention of sustained attacks deteriorates

Engineering Contradiction:
Improveincident responseVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis of malware detection patterns to identify early signs of sustained attacks before they result in successful breaches. By taking preliminary action on detected patterns, the system provides advance warning and enables proactive prevention rather than reactive response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12425445B2Early malware detection
Publication Date: 2025.09.23 SOPHOS LTD
  • US12425445B2 patent drawing
  • US12425445B2 patent drawing
  • US12425445B2 patent drawing

AI summary

Malware detections are received from a plurality of endpoints in one or more enterprise networks. A first and second set of indicators of breach may be identified from the malware detections and, where appropriate, grouped by specific customers. The pattern of progressive deployment of malware directed toward a customer can then be used as a basis for identifying generalized targeting of the customer, or extended staging for a specific attack on the customer such as a ransomware attack.