Endpoint Security BTP Engine Real-Time Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current endpoint security solutions are inefficient in detecting and mitigating new forms of malware due to the time-consuming process of updating detection logic, which can take several months, and often require binary updates that necessitate recertification and upgrades, making it difficult to quickly respond to new security threats.
Innovation Solution
The implementation of a Behavioral Threat Protection (BTP) engine that monitors endpoints for malicious activity in real-time, using a cross-platform architecture and content updates to detect new threats without requiring binary updates, allowing for timely and efficient deployment of new detection rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional endpoint security solutions are used to detect malware, then detection capability is provided, but the time to update detection logic is several months and binary updates requiring recertification are needed
Solution Approach 1:
The patent segments the detection logic from the binary executable, allowing detection rules to be updated independently as separate content updates. This enables the binary to remain certified while detection capabilities are refreshed through lightweight rule updates, resolving the contradiction between maintaining reliable detection and reducing update time.
Solution Approach 2:
The patent implements dynamic detection logic that can be modified and updated without requiring binary recertification. The system transitions from static, compiled detection rules to dynamic, updatable rules that can adapt to new threats quickly, thereby reducing the time loss while maintaining detection reliability.
2Measurement precision
If binary updates are required for deploying new detection logic, then detection accuracy is maintained, but deployment complexity increases and frequent upgrades are necessary
Solution Approach 1:
By separating detection logic into independent, updatable rules distinct from the binary, the patent reduces deployment complexity. Detection accuracy is maintained through careful rule management while avoiding the complexity of full binary updates, including recertification processes.
Solution Approach 2:
The patent uses copying of detection rules from a centralized source to multiple endpoints without requiring binary updates. This simplifies deployment by allowing rapid replication of detection logic across the network while maintaining consistency and accuracy.
3Stability of the object's composition
If traditional security update processes are used, then system stability is maintained, but response speed to new threats is slow
Solution Approach 1:
The patent enables dynamic updates of detection rules without requiring system reconfiguration or recertification. This allows rapid response to new threats by quickly deploying updated rules while maintaining system stability through the proven binary foundation.
Solution Approach 2:
The patent prepares detection rules in advance and stores them for rapid deployment. When new threats are identified, pre-prepared rules can be quickly activated without lengthy update processes, improving response speed while maintaining system stability.
Data Source
AI summary
Techniques for detecting malicious activity on an endpoint based on real-time system events are disclosed. In some embodiments, a system/process/computer program product for detecting malicious activity on an endpoint based on real-time system events includes monitoring an endpoint for malicious activity using an endpoint agent, in which the endpoint comprises a local device; detecting malicious activity associated with an application on the endpoint based on real-time system events using the endpoint agent based on a set of rules; and in response to detecting malicious activity on the endpoint based on real-time system events using the endpoint agent, performing a security response based on a security policy.


