Endpoint Counter Anomaly Detection for Real-Time Identity Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting anomalous endpoint events in computer systems rely on statistical baselines that require a learning period, making initial detection challenging, especially for new endpoints or entities, and are not effective in real-time identity resolution.
Innovation Solution
A system and method that monitor electronically-observable actions, convert them into electronic information, and perform anomaly detection operations based on predefined thresholds, utilizing a protected endpoint and endpoint agents to provide real-time identity resolution and detect anomalies before access to sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If statistical baselines are used for anomaly detection, then detection accuracy is improved, but a learning period is required which delays initial detection capability
Solution Approach 1:
The system performs preliminary actions by collecting endpoint counter data during a learning period and generating baseline anomaly scores in advance. This allows the statistical model to be pre-trained and ready for immediate use, eliminating the delay that would otherwise occur when anomaly detection is first needed. The baseline anomaly scores are stored and can be quickly compared against new endpoint counter data without requiring real-time learning.
Solution Approach 2:
The system prepares compensatory measures in advance by establishing statistical baselines during a learning period before actual anomaly detection is needed. These pre-established baselines act as a cushion that allows immediate anomaly detection without requiring the system to learn from scratch when first deployed. The pre-computed baseline anomaly scores provide a reference framework that is ready to immediately evaluate new endpoint behavior.
2Reliability
If statistical baselines requiring learning periods are used, then detection reliability is improved, but real-time detection capability deteriorates
Solution Approach 1:
The system performs the computationally intensive baseline learning in advance, generating statistical models and baseline anomaly scores before real-time detection is needed. This preliminary action separates the learning phase from the detection phase, allowing reliable statistical analysis to be completed beforehand and then applied instantly to new endpoint counter data without delaying real-time detection responses.
Solution Approach 2:
The system creates copies of the learned statistical baselines and stores them for rapid retrieval during real-time detection. Instead of re-computing statistical models during real-time operation, the system uses pre-computed baseline anomaly scores that can be quickly compared against new endpoint behavior, maintaining both reliability and real-time performance.
3Measurement precision
If comprehensive monitoring of electronically-observable actions is implemented, then identity resolution accuracy is improved, but system complexity increases
Solution Approach 1:
The system extracts only the most relevant electronically-observable actions and endpoint counter data needed for identity resolution, rather than monitoring all possible system events. By selectively extracting key behavioral indicators such as file access patterns, registry modifications, and network connections, the system achieves accurate identity resolution without the complexity of comprehensive monitoring of every system action.
Solution Approach 2:
The system pre-identifies and monitors only those endpoint counter events that are most indicative of identity and behavior patterns. By determining in advance which electronically-observable actions are most useful for anomaly detection and identity resolution, the system avoids the complexity of processing all possible events while maintaining high accuracy in identifying entity behavior.
Data Source
AI summary
A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; generating a representation of occurrences of a particular event from the plurality of events enacted by the entity; and performing an anomaly detection operation based upon the representation of occurrences of the particular event from the plurality of events enacted by the entity, the anomaly detection operation determining when the representation of occurrences of the particular event exceeds a predetermined threshold.


