Endpoint Security System Using Behavioral Profiling for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems are ineffective in detecting modern cyber threats, leading to increased frequency and severity of cyber-attacks, with endpoint security being a significant challenge due to reliance on pre-determined threat indicators and the inability to differentiate between legitimate and malicious user behavior.

Innovation Solution

A behavioral-based endpoint security solution that collects and analyzes user-specific behavioral data to create profiles, comparing real-time activity to historical patterns to detect anomalies and potential breaches, reducing false positives and improving detection times from 146 days to minutes or hours.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security systems use pre-determined threat indicators to block and detect specific threats, then they can identify known threats, but they fail to identify legitimate threats and produce large volumes of false positives

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent transforms the detection approach from using pre-determined threat indicators to using behavioral parameters and statistical analysis. By changing the detection parameters from static signatures to dynamic behavioral patterns, the system achieves better differentiation between legitimate and malicious activities, reducing false positives while improving detection accuracy.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical rule-based detection system with a statistical and behavioral analysis system. Instead of relying on predetermined indicators and manual rules, the system uses automated behavioral profiling and statistical deviation analysis to detect threats, thereby reducing false positives and improving detection precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional security systems generate large volumes of alerts to detect threats, then they increase detection coverage, but IT administrators lack the resources to assess all alerts leading to legitimate threats going undetected

Engineering Contradiction:
Improvethreat detection coverageVSAvoidadministrative workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service detection system that automatically profiles user behavior and generates alerts only for significant deviations. The system serves itself by autonomously learning normal behavioral patterns and independently identifying anomalies, eliminating the need for manual assessment of numerous alerts while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously learns from observed behavioral patterns and refines its detection algorithms. By using feedback from historical data and confirmed incidents, the system improves its ability to distinguish true threats from normal variations, reducing alert volume while maintaining reliability.

Inventive Principle:
Principle #23Feedback

3Loss of time

If organizations take an average of 146 days to detect a data breach using traditional systems, then they can process alerts manually, but the longer a breach remains undetected the higher the chance of a major data breach

Engineering Contradiction:
Improvedetection timeVSAvoiddata breach severity
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by continuously profiling user behavior and establishing baseline patterns before breaches occur. The system is proactively monitoring and learning normal behaviors in advance, enabling it to immediately detect deviations that indicate a breach, thereby dramatically reducing detection time from 146 days to much shorter periods.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuous monitoring and analysis of user behavior without interruption. The system operates continuously to collect behavioral data, update profiles, and detect anomalies in real-time, eliminating the gaps and delays inherent in manual alert assessment processes and reducing overall detection time.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10728261B2System and method for cyber security threat detection
Publication Date: 2020.07.28 RESPONSIGHT PTY LTD
  • US10728261B2 patent drawing
  • US10728261B2 patent drawing
  • US10728261B2 patent drawing

AI summary

A cyber security threat detection system for one or more endpoints within a computing environment is disclosed. The system includes one or more collector engines. Each of the collector engines includes a service and an agent operating on a corresponding system endpoint of the system endpoints. The service is configured to take a first snapshot of the corresponding system endpoint. The first snapshot includes event activity information associated with the system endpoint. The agent is configured to take a second snapshot of the corresponding system endpoint. The second snapshot includes behavioral activity information associated with the corresponding system endpoint. The system further includes an aggregator engine configured to aggregate the first snapshot and the second snapshot from each of the system endpoints into an aggregated snapshot. The system further includes one or more analytics engines configured to: generate and store baseline profiles associated with the system endpoints based on a previously received aggregated snapshot, receive the aggregated snapshot from the aggregator engine, determine deviation values for each of the system endpoints based on the received aggregated snapshot and the stored baseline profiles, and generate, for each of the system endpoints, a cumulative risk value based on the deviation values. The system further includes one or more alerting engines configured to determine whether to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the cumulative risk value.