Endpoint Network Sensor Local Data Linking for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity systems face challenges in effectively monitoring and responding to cyber threats, especially in distributed and varied deployments, due to reliance on centralized monitoring components and inefficiencies in linking network and endpoint data for threat detection and remediation.
Innovation Solution
Deployment of an advanced endpoint network sensor (EPNS) that monitors and reports local network traffic, reducing reliance on centralized components by linking network and endpoint data locally for enhanced threat detection, analytics, and remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized monitoring components (mirrors/TAPs) are used to monitor network traffic, then network-wide visibility is achieved, but system complexity and reliance on centralized infrastructure increases
Solution Approach 1:
The patent segments the centralized monitoring function by deploying endpoint network sensors (EPNS) on individual endpoint devices. Each EPNS independently monitors local network traffic, replacing the need for a single centralized monitoring point. This segmentation distributes the monitoring function across multiple autonomous units, reducing infrastructure complexity while maintaining comprehensive coverage.
Solution Approach 2:
The EPNS enables endpoint devices to self-monitor their own network traffic locally. Each endpoint device performs its own network traffic monitoring and threat detection without requiring external centralized components. This self-service approach eliminates dependency on mirrors/TAPs and centralized infrastructure, allowing endpoints to autonomously detect and respond to threats.
2Measurement precision
If network and endpoint data are linked centrally, then comprehensive threat analysis is achieved, but data processing time and system latency increase
Solution Approach 1:
The EPNS performs preliminary data linking and correlation actions locally at the endpoint device before data needs to be transmitted for central analysis. By pre-linking network traffic data with endpoint data locally, the system prepares processed, correlated information in advance, reducing the processing burden and time required at centralized systems while maintaining comprehensive threat analysis capability.
3Reliability
If centralized components monitor all network traffic, then complete network visibility is achieved, but false positives and overreporting increase
Solution Approach 1:
The patent applies local quality by enabling each endpoint device to perform context-aware threat detection using locally available information. The EPNS leverages local knowledge of the endpoint's normal behavior, applications, and network patterns to evaluate threats, producing more accurate assessments with fewer false positives compared to centralized monitoring that lacks local context.
4Measurement precision
If endpoint devices report all network traffic to centralized systems, then comprehensive threat analytics is achieved, but network bandwidth consumption and system overhead increase
Solution Approach 1:
The EPNS extracts and processes only the essential and relevant features from network traffic data locally at the endpoint. Instead of transmitting complete raw network traffic data to centralized systems, the sensor extracts key indicators, metadata, and threat-relevant information, significantly reducing the data volume transmitted over the network while preserving the quality needed for comprehensive threat analytics.
Data Source
AI summary
In one or more examples, an advanced form of network endpoint sensor is deployed to an endpoint device to provide local monitoring and reporting of network traffic flowing to and/or from the endpoint device. For example, such network endpoint sensors may reduce reliance on other types of monitoring component (such as mirrors/TAPs) and/or complement functionality of other type(s) of monitoring component (e.g. in a deployment with “roaming” endpoints). In one or more examples, network data may be linked or otherwise associated with endpoint data locally at an endpoint device. In one or more examples, such linking may be performed locally prior to reporting, response and/or remediation.


