Endpoint Security Threat Detection via Third-Party Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security services struggle to determine the trustworthiness of suspicious files when databases do not contain information about them, leading to potential security threats going undetected.

Innovation Solution

The system detects attempts to access suspicious files and retrieves information about their origin and potential malicious behaviors from third-party resources not associated with the security service, determining whether the file represents a security threat based on this information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security services rely only on their own databases to detect security threats, then the security service can quickly determine trustworthiness of known files, but the security service cannot detect threats from unknown files that are not in the database

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcapability to detect unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces third-party resources as intermediaries between the security service and unknown files. When a file's trustworthiness cannot be determined from internal databases, the security service queries external third-party resources (such as other security vendors, cloud-based threat intelligence platforms, or distributed security networks) to obtain information about the file's origin, creator, publisher, distributor, and associated behaviors. This intermediary mechanism enables the security service to detect threats from unknown files by leveraging external knowledge sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the security service queries multiple third-party resources to obtain file information, then the security service can improve detection accuracy for unknown files, but the security service increases information retrieval time and system complexity

Engineering Contradiction:
Improvetrustworthiness determination accuracyVSAvoidfile access decision time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing connections and information exchange protocols with multiple third-party resources before actual security threats are detected. The security service maintains pre-configured access channels to third-party databases, threat intelligence platforms, and collaborative security networks. When a suspicious file is detected, the service can immediately query these pre-established channels without needing to set up connections in real-time, thereby reducing the time penalty associated with consulting multiple external sources.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If the security service uses only internal databases for file analysis, then the system complexity remains low, but the security service cannot obtain comprehensive information about file origin and behaviors

Engineering Contradiction:
Improvesystem architecture simplicityVSAvoidfile origin and behavior information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent applies universality by designing a multi-functional security service architecture that can operate effectively with both internal databases and external third-party resources. The security service maintains its core internal database functions for quick lookup of known threats while simultaneously incorporating universal interfaces and protocols that enable it to query and integrate information from diverse third-party sources. This multi-functional design allows the system to comprehensively analyze file origin, creator, publisher, distributor, and behavioral information without requiring complete redesign of the internal system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10262131B2Systems and methods for obtaining information about security threats on endpoint devices
Publication Date: 2019.04.16 CA TECH INC
  • US10262131B2 patent drawing
  • US10262131B2 patent drawing
  • US10262131B2 patent drawing

AI summary

The disclosed computer-implemented method for obtaining information about security threats on endpoint devices may include (1) detecting, by a security program on a computing device, an attempt to access at least one suspicious file, (2) before permitting the computing device to access the suspicious file, identifying, by the security program, at least one third-party resource not associated with the security program that contains information potentially indicative of the trustworthiness of the suspicious file, (3) obtaining, by the security program from the third-party resource, the information potentially indicative of the trustworthiness of the suspicious file, and then (4) determining, by the security program based at least in part on the information potentially indicative of the trustworthiness of the suspicious file, whether the suspicious file represents a security threat to the computing device. Various other methods, systems, and computer-readable media are also disclosed.