Endpoint Protection Platform Integrating Security Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies operate in silos, failing to share information that could be mutually beneficial for enhanced incident classification and enrichment, leading to limited effectiveness in detecting and responding to security incidents across endpoints and networks.

Innovation Solution

A system and method that synergistically combine endpoint detection and response (EDR), event management, and user entity behavior analytics (UEBA) services through a super agent, enabling communication and data sharing between these security services to enrich alerts and improve incident classification and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If network security technologies (EDR, event management, analytics tools) operate independently in silos, then each technology can maintain its individual capabilities and simplicity, but information sharing and mutual benefit are lost, reducing overall incident classification and enrichment effectiveness

Engineering Contradiction:
Improveinformation sharing between security servicesVSAvoidintegration complexity of multiple security agents
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges multiple independent security agents (EDR agent, event management agent, analytics agent) into a unified endpoint protection platform that enables information sharing and collaborative incident classification. The agents communicate through standardized interfaces and share data about detected incidents, processes, and threats, transforming siloed operations into an integrated security ecosystem that preserves individual agent capabilities while enabling mutual benefit through data exchange.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If security services share information and collaborate synergistically, then incident classification accuracy and alert enrichment are improved, but system complexity and integration requirements increase

Engineering Contradiction:
Improveincident classification accuracyVSAvoidsystem integration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The endpoint protection platform implements universal communication protocols and standardized data formats that enable different security agents (EDR, event management, analytics) to exchange information effectively. Each agent maintains its specialized functionality while gaining access to data from other agents through the unified platform, achieving multi-functionality without requiring complete system redesign. This allows incident classification to leverage multiple data sources while keeping individual agent complexity manageable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary communication layer within the endpoint protection platform that mediates between different security agents. This intermediary layer standardizes data exchange formats, manages communication protocols, and coordinates information flow between agents, reducing the integration complexity that would otherwise arise from direct peer-to-peer connections between all agents. The mediator enables synergistic collaboration while shielding individual agents from the complexity of multi-agent coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple security agents communicate and share data, then alert enrichment and threat detection effectiveness are enhanced, but communication overhead and processing time may increase

Engineering Contradiction:
Improvethreat detection effectivenessVSAvoidcommunication and data processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The endpoint protection platform implements preliminary data normalization and pre-processing of security events as they are collected by individual agents. Data is standardized and prepared for sharing before exchange occurs, reducing the need for extensive processing during inter-agent communication. Incident data, process information, and threat indicators are pre-formatted according to platform standards, enabling faster data exchange and reducing communication overhead while maintaining comprehensive threat detection capabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11882128B2Improving incident classification and enrichment by leveraging context from multiple security agents
Publication Date: 2024.01.23 FORTINET INC
  • US11882128B2 patent drawing
  • US11882128B2 patent drawing
  • US11882128B2 patent drawing

AI summary

Systems and methods are described for synergistically combining network security technologies to improve incident classification and enrichment. According to one embodiment, an endpoint protection platform running on an endpoint device receives a request via an event management agent of the endpoint protection platform from an event management service for process information relating to an incident detected by the event management service. The request is caused to be processed by an endpoint detection and response (EDR) service by transmitting the request to an EDR agent of the endpoint protection platform corresponding to the EDR service. A response to the request is received from the EDR service via the EDR agent. The response includes the process information. Enrichment of an alert generated by the event management service based on the process information is facilitated by transmitting the response to the event management service via the event management agent.