Endpoint and Network Data Fusion for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current endpoint detection and response (EDR) systems only track events on individual computing devices, lacking a comprehensive view of network-level activities, which limits their ability to detect and identify computer-based threats and anomalies effectively.
Innovation Solution
A system that combines endpoint data from computing devices with network data to generate event data, allowing for the analysis of sequences of events at both the network and host levels to detect and identify anomalies, and compare them against a global database of anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If only endpoint data is collected from individual computing devices, then the system complexity is reduced and ease of operation is improved, but the detection capability and measurement precision of network-level threats are insufficient
Solution Approach 1:
The patent combines endpoint data from individual computing devices with network data from network devices to create a unified security monitoring system. This merging of data sources enables comprehensive threat detection at both endpoint and network levels, resolving the contradiction between detection capability and system complexity by integrating multiple data streams into a coordinated analysis framework
Solution Approach 2:
The system is designed to handle multiple types of data (endpoint data, network data, flow data) and perform multiple functions (anomaly detection, threat identification, security analysis) through a unified platform. This multi-functionality approach allows the system to maintain versatility while managing complexity through standardized data processing pipelines
2Reliability
If comprehensive data from multiple sources is collected, then the ability to detect and identify threats is improved, but the quantity of data to be processed increases
Solution Approach 1:
The patent extracts and separates different types of data into distinct categories (endpoint data, network data, flow data) that can be processed independently before being integrated for comprehensive analysis. This extraction approach allows the system to manage large data volumes by handling each data type through specialized processing routines, improving reliability without being overwhelmed by total data quantity
Solution Approach 2:
The system segments the security monitoring function into multiple independent components: endpoint monitoring, network monitoring, data collection, data processing, and anomaly detection. Each segment handles specific data types and processing tasks, enabling the system to manage comprehensive data volumes through distributed, modular processing that maintains high detection reliability
Data Source
AI summary
The present application describes a system that uses endpoint data and network data to detect an anomaly. Once an anomaly is detected, the system may determine a severity of the anomaly by comparing the anomaly to a global database of known anomalies. The system may then initiate preventative measures to address the anomaly.


