Automated Endpoint Detection Process Tree Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current endpoint detection and response (EDR) systems require significant manual analysis by security analysts to respond to cyber attacks, often leading to destruction of infected devices due to lack of confidence in repair capabilities.

Innovation Solution

An automated method and system for endpoint detection and response that automatically traverses a process tree to display the full flow of a malware attack, highlighting key details and milestones, allowing for quicker detection and response, including automatic quarantine of compromised endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated query execution and process tree traversal are implemented, then detection speed and response time are improved, but system complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the security analysis process into distinct automated components: alert reception modules, query execution engines, process tree traversal algorithms, and visualization interfaces. Each component handles a specific aspect of the analysis, enabling parallel processing and reducing overall detection time while maintaining manageable system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-configuring query templates, process tree structures, and analysis protocols before security incidents occur. These pre-prepared frameworks enable rapid automated response when alerts are generated, eliminating the need for manual analysis setup and significantly accelerating detection and response times.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive attack flow analysis is performed, then detection accuracy is improved, but time required for investigation increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidinvestigation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces manual mechanical analysis processes with automated computational algorithms. Machine learning models and automated query execution engines analyze process trees and attack flows at speeds impossible for human analysts, achieving comprehensive detection accuracy while reducing investigation time from hours to minutes or seconds.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates detailed digital copies and representations of attack processes through process tree visualizations and structured data models. These copies enable thorough analysis of attack flows without requiring analysts to manually trace each process step, maintaining high detection accuracy while dramatically reducing the time required for investigation.

Inventive Principle:
Principle #26Copying

3Productivity

If manual analysis by security analysts is reduced, then response time is improved, but expertise requirements become more challenging

Engineering Contradiction:
Improveresponse timeVSAvoidautomation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system enables self-service security analysis by embedding intelligent automation capabilities that autonomously perform query execution, process tree traversal, and attack flow analysis without requiring human expertise for each incident. The automated system serves itself by generating, executing, and interpreting security analyses, achieving rapid response times while reducing dependency on specialized human expertise.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary automated analysis layer between security alerts and human analysts. This intermediary automatically processes alerts, executes queries, traverses process trees, and generates comprehensive attack flow reports, reducing the burden on analysts and enabling rapid response while maintaining high detection accuracy through sophisticated automated reasoning.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12093387B2Endpoint detection and response attack process tree auto-play
Publication Date: 2024.09.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12093387B2 patent drawing
  • US12093387B2 patent drawing
  • US12093387B2 patent drawing

AI summary

A computer receives one or more security alerts. The computer selects a subset of the one or more security alerts for processing. The computer executes one or more queries automatically, based on the subset of the one or more security alerts. The computer identifies one or more related processes, wherein the one or more related processes are related to information contained within the subset of the one or more security alerts. The computer displays a full flow of a malware attack, wherein the full flow includes the information contained within the subset of the one or more security alerts and the one or more related processes.