Endpoint Counter Anomaly Detection for Real-Time Identity Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting anomalous endpoint events in computer systems rely on statistical baselines that require a learning period, making initial detection challenging, especially for new endpoints or entities, and are not effective in real-time identity resolution.

Innovation Solution

A system and method that monitor electronically-observable actions, convert them into electronic information, and perform anomaly detection operations based on predefined thresholds, utilizing a protected endpoint and endpoint agents to provide real-time identity resolution and detect anomalies before access to sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If statistical baselines are used for anomaly detection, then detection accuracy is improved, but a learning period is required which delays initial detection capability

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidlearning period duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting endpoint counter data during a learning period and generating baseline anomaly scores in advance. This allows the statistical model to be pre-trained and ready for immediate use, eliminating the delay that would otherwise occur when anomaly detection is first needed. The baseline anomaly scores are stored and can be quickly compared against new endpoint counter data without requiring real-time learning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system prepares compensatory measures in advance by establishing statistical baselines during a learning period before actual anomaly detection is needed. These pre-established baselines act as a cushion that allows immediate anomaly detection without requiring the system to learn from scratch when first deployed. The pre-computed baseline anomaly scores provide a reference framework that is ready to immediately evaluate new endpoint behavior.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If statistical baselines requiring learning periods are used, then detection reliability is improved, but real-time detection capability deteriorates

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoidreal-time detection speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs the computationally intensive baseline learning in advance, generating statistical models and baseline anomaly scores before real-time detection is needed. This preliminary action separates the learning phase from the detection phase, allowing reliable statistical analysis to be completed beforehand and then applied instantly to new endpoint counter data without delaying real-time detection responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of the learned statistical baselines and stores them for rapid retrieval during real-time detection. Instead of re-computing statistical models during real-time operation, the system uses pre-computed baseline anomaly scores that can be quickly compared against new endpoint behavior, maintaining both reliability and real-time performance.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive monitoring of electronically-observable actions is implemented, then identity resolution accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveidentity resolution accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant electronically-observable actions and endpoint counter data needed for identity resolution, rather than monitoring all possible system events. By selectively extracting key behavioral indicators such as file access patterns, registry modifications, and network connections, the system achieves accurate identity resolution without the complexity of comprehensive monitoring of every system action.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system pre-identifies and monitors only those endpoint counter events that are most indicative of identity and behavior patterns. By determining in advance which electronically-observable actions are most useful for anomaly detection and identity resolution, the system avoids the complexity of processing all possible events while maintaining high accuracy in identifying entity behavior.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11632382B2Anomaly detection using endpoint counters
Publication Date: 2023.04.18 FORCEPOINT LLC
  • US11632382B2 patent drawing
  • US11632382B2 patent drawing
  • US11632382B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; generating a representation of occurrences of a particular event from the plurality of events enacted by the entity; and performing an anomaly detection operation based upon the representation of occurrences of the particular event from the plurality of events enacted by the entity, the anomaly detection operation determining when the representation of occurrences of the particular event exceeds a predetermined threshold.