Endpoint Security Logic Engine with Custom Detection Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current endpoint security systems are limited by proprietary logic, preventing security experts from customizing detection and response logic, making them inadequate for specific organizational security needs.
Innovation Solution
An adaptive endpoint security agent architecture with a programmable Logic Engine that exposes a public interface using Event Filtering Language (EFL), allowing users to define and execute custom logic for detecting and responding to threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If proprietary logic is used in endpoint security software, then the system is easier to manufacture and maintain, but the adaptability to specific organizational security needs deteriorates
Solution Approach 1:
The endpoint security software is divided into two distinct parts: a proprietary core engine that handles security functions, and an open logic layer that allows custom detection and response rules. This segmentation enables the core to remain easier to manufacture while the open layer provides organizational adaptability through user-defined logic.
Solution Approach 2:
An open interface or mediator layer is introduced between the proprietary core and the user's security requirements. This intermediary allows organizations to define custom logic without modifying the core software, resolving the contradiction by enabling adaptability while preserving the ease of manufacture of the proprietary core.
2Adaptability or versatility
If custom detection and response logic is allowed, then the adaptability to organizational needs improves, but the device complexity increases
Solution Approach 1:
The complexity of custom logic definition is extracted from the core software and placed in a separate, user-friendly interface layer. Users can define custom detection and response logic through simplified means (such as rule-based interfaces or scripting environments) without increasing the complexity of the core endpoint security engine itself.
Solution Approach 2:
The system provides dynamic adaptability through a modular architecture where detection and response logic can be independently defined, modified, and deployed. This allows the system to adapt to organizational needs without permanently increasing device complexity, as the complexity is managed through dynamic configuration rather than structural complexity.
3Measurement precision
If more data is collected from endpoints, then the detection capability improves, but the loss of information increases due to data volume management challenges
Solution Approach 1:
Custom detection logic is executed preliminarily at the endpoint before data is transmitted or processed further. By defining detection rules in advance, the system can identify and filter out relevant information early, improving detection capability while preventing information loss through targeted data collection rather than comprehensive data gathering.
Solution Approach 2:
The system applies local quality filtering by allowing organizations to define detection logic specific to their local security needs and data characteristics. This enables precise, context-aware data collection that improves detection capability for relevant threats while avoiding the information overload and loss associated with collecting all possible data uniformly.
Data Source
AI summary
The present invention provides an integrated, context-aware, security system that provides an adaptive endpoint security agent architecture model for a continuously monitoring and recording activity across an enterprise, specifically monitoring activity on endpoints, and subsequently detecting and blocking any malicious processes that may otherwise invade the enterprise and cause issues. The endpoint security agent architecture exposes a well-defined, public interface to the event data generated by the endpoint security agent in the form of a custom programming language by which a user can define the logic that the endpoint security agent executes in response to event data to perform detection of and response to suspicious activity.


