Endpoint Security Logic Engine with Custom Detection Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current endpoint security systems are limited by proprietary logic, preventing security experts from customizing detection and response logic, making them inadequate for specific organizational security needs.

Innovation Solution

An adaptive endpoint security agent architecture with a programmable Logic Engine that exposes a public interface using Event Filtering Language (EFL), allowing users to define and execute custom logic for detecting and responding to threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If proprietary logic is used in endpoint security software, then the system is easier to manufacture and maintain, but the adaptability to specific organizational security needs deteriorates

Engineering Contradiction:
Improveease of manufactureVSAvoidadaptability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The endpoint security software is divided into two distinct parts: a proprietary core engine that handles security functions, and an open logic layer that allows custom detection and response rules. This segmentation enables the core to remain easier to manufacture while the open layer provides organizational adaptability through user-defined logic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An open interface or mediator layer is introduced between the proprietary core and the user's security requirements. This intermediary allows organizations to define custom logic without modifying the core software, resolving the contradiction by enabling adaptability while preserving the ease of manufacture of the proprietary core.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If custom detection and response logic is allowed, then the adaptability to organizational needs improves, but the device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The complexity of custom logic definition is extracted from the core software and placed in a separate, user-friendly interface layer. Users can define custom detection and response logic through simplified means (such as rule-based interfaces or scripting environments) without increasing the complexity of the core endpoint security engine itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system provides dynamic adaptability through a modular architecture where detection and response logic can be independently defined, modified, and deployed. This allows the system to adapt to organizational needs without permanently increasing device complexity, as the complexity is managed through dynamic configuration rather than structural complexity.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If more data is collected from endpoints, then the detection capability improves, but the loss of information increases due to data volume management challenges

Engineering Contradiction:
Improvedetection capabilityVSAvoidinformation loss
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

Custom detection logic is executed preliminarily at the endpoint before data is transmitted or processed further. By defining detection rules in advance, the system can identify and filter out relevant information early, improving detection capability while preventing information loss through targeted data collection rather than comprehensive data gathering.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies local quality filtering by allowing organizations to define detection logic specific to their local security needs and data characteristics. This enables precise, context-aware data collection that improves detection capability for relevant threats while avoiding the information overload and loss associated with collecting all possible data uniformly.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250184338A1Endpoint security architecture with programmable logic engine
Publication Date: 2025.06.05 NUIX
  • US20250184338A1 patent drawing
  • US20250184338A1 patent drawing
  • US20250184338A1 patent drawing

AI summary

The present invention provides an integrated, context-aware, security system that provides an adaptive endpoint security agent architecture model for a continuously monitoring and recording activity across an enterprise, specifically monitoring activity on endpoints, and subsequently detecting and blocking any malicious processes that may otherwise invade the enterprise and cause issues. The endpoint security agent architecture exposes a well-defined, public interface to the event data generated by the endpoint security agent in the form of a custom programming language by which a user can define the logic that the endpoint security agent executes in response to event data to perform detection of and response to suspicious activity.