Endpoint Network Sensor Local Data Linking for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in effectively monitoring and responding to cyber threats, especially in distributed and varied deployments, due to reliance on centralized monitoring components and inefficiencies in linking network and endpoint data for threat detection and remediation.

Innovation Solution

Deployment of an advanced endpoint network sensor (EPNS) that monitors and reports local network traffic, reducing reliance on centralized components by linking network and endpoint data locally for enhanced threat detection, analytics, and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized monitoring components (mirrors/TAPs) are used to monitor network traffic, then network-wide visibility is achieved, but system complexity and reliance on centralized infrastructure increases

Engineering Contradiction:
Improvenetwork monitoring coverageVSAvoidcentralized infrastructure dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized monitoring function by deploying endpoint network sensors (EPNS) on individual endpoint devices. Each EPNS independently monitors local network traffic, replacing the need for a single centralized monitoring point. This segmentation distributes the monitoring function across multiple autonomous units, reducing infrastructure complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The EPNS enables endpoint devices to self-monitor their own network traffic locally. Each endpoint device performs its own network traffic monitoring and threat detection without requiring external centralized components. This self-service approach eliminates dependency on mirrors/TAPs and centralized infrastructure, allowing endpoints to autonomously detect and respond to threats.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If network and endpoint data are linked centrally, then comprehensive threat analysis is achieved, but data processing time and system latency increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata processing latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The EPNS performs preliminary data linking and correlation actions locally at the endpoint device before data needs to be transmitted for central analysis. By pre-linking network traffic data with endpoint data locally, the system prepares processed, correlated information in advance, reducing the processing burden and time required at centralized systems while maintaining comprehensive threat analysis capability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized components monitor all network traffic, then complete network visibility is achieved, but false positives and overreporting increase

Engineering Contradiction:
Improvethreat detection coverageVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by enabling each endpoint device to perform context-aware threat detection using locally available information. The EPNS leverages local knowledge of the endpoint's normal behavior, applications, and network patterns to evaluate threats, producing more accurate assessments with fewer false positives compared to centralized monitoring that lacks local context.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If endpoint devices report all network traffic to centralized systems, then comprehensive threat analytics is achieved, but network bandwidth consumption and system overhead increase

Engineering Contradiction:
Improvethreat analytics qualityVSAvoidnetwork bandwidth utilization
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The EPNS extracts and processes only the essential and relevant features from network traffic data locally at the endpoint. Instead of transmitting complete raw network traffic data to centralized systems, the sensor extracts key indicators, metadata, and threat-relevant information, significantly reducing the data volume transmitted over the network while preserving the quality needed for comprehensive threat analytics.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11438357B2Endpoint network sensor and related cybersecurity infrastructure
Publication Date: 2022.09.06 SENSEON TECH LTD
  • US11438357B2 patent drawing
  • US11438357B2 patent drawing
  • US11438357B2 patent drawing

AI summary

In one or more examples, an advanced form of network endpoint sensor is deployed to an endpoint device to provide local monitoring and reporting of network traffic flowing to and/or from the endpoint device. For example, such network endpoint sensors may reduce reliance on other types of monitoring component (such as mirrors/TAPs) and/or complement functionality of other type(s) of monitoring component (e.g. in a deployment with “roaming” endpoints). In one or more examples, network data may be linked or otherwise associated with endpoint data locally at an endpoint device. In one or more examples, such linking may be performed locally prior to reporting, response and/or remediation.