Endpoint Protection Platform Integrating Security Agents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies operate in silos, failing to share information that could be mutually beneficial for enhanced incident classification and enrichment, leading to limited effectiveness in detecting and responding to security incidents across endpoints and networks.
Innovation Solution
A system and method that synergistically combine endpoint detection and response (EDR), event management, and user entity behavior analytics (UEBA) services through a super agent, enabling communication and data sharing between these security services to enrich alerts and improve incident classification and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If network security technologies (EDR, event management, analytics tools) operate independently in silos, then each technology can maintain its individual capabilities and simplicity, but information sharing and mutual benefit are lost, reducing overall incident classification and enrichment effectiveness
Solution Approach 1:
The patent merges multiple independent security agents (EDR agent, event management agent, analytics agent) into a unified endpoint protection platform that enables information sharing and collaborative incident classification. The agents communicate through standardized interfaces and share data about detected incidents, processes, and threats, transforming siloed operations into an integrated security ecosystem that preserves individual agent capabilities while enabling mutual benefit through data exchange.
2Measurement precision
If security services share information and collaborate synergistically, then incident classification accuracy and alert enrichment are improved, but system complexity and integration requirements increase
Solution Approach 1:
The endpoint protection platform implements universal communication protocols and standardized data formats that enable different security agents (EDR, event management, analytics) to exchange information effectively. Each agent maintains its specialized functionality while gaining access to data from other agents through the unified platform, achieving multi-functionality without requiring complete system redesign. This allows incident classification to leverage multiple data sources while keeping individual agent complexity manageable.
Solution Approach 2:
The patent introduces an intermediary communication layer within the endpoint protection platform that mediates between different security agents. This intermediary layer standardizes data exchange formats, manages communication protocols, and coordinates information flow between agents, reducing the integration complexity that would otherwise arise from direct peer-to-peer connections between all agents. The mediator enables synergistic collaboration while shielding individual agents from the complexity of multi-agent coordination.
3Reliability
If multiple security agents communicate and share data, then alert enrichment and threat detection effectiveness are enhanced, but communication overhead and processing time may increase
Solution Approach 1:
The endpoint protection platform implements preliminary data normalization and pre-processing of security events as they are collected by individual agents. Data is standardized and prepared for sharing before exchange occurs, reducing the need for extensive processing during inter-agent communication. Incident data, process information, and threat indicators are pre-formatted according to platform standards, enabling faster data exchange and reducing communication overhead while maintaining comprehensive threat detection capabilities.
Data Source
AI summary
Systems and methods are described for synergistically combining network security technologies to improve incident classification and enrichment. According to one embodiment, an endpoint protection platform running on an endpoint device receives a request via an event management agent of the endpoint protection platform from an event management service for process information relating to an incident detected by the event management service. The request is caused to be processed by an endpoint detection and response (EDR) service by transmitting the request to an EDR agent of the endpoint protection platform corresponding to the EDR service. A response to the request is received from the EDR service via the EDR agent. The response includes the process information. Enrichment of an alert generated by the event management service based on the process information is facilitated by transmitting the response to the event management service via the event management agent.


