Endpoint Threat Identification via File Spread Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-virus solutions are ineffective in detecting advanced persistent threats (APT) across multiple end-point devices connected by a network, as they rely on signature-based detection methods that fail to identify sophisticated, evolving malware, leading to undetected malicious activity and increased management burdens for security teams.

Innovation Solution

A method and apparatus for logical identification of malicious threats that collect and analyze file identifiers across end-point devices, determining file prevalence and spread patterns using predetermined investigation rules to identify suspicious files and generate risk scores, enabling continuous monitoring and root cause analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection methods are used, then known viruses can be identified, but advanced persistent threats and sophisticated malware cannot be detected

Engineering Contradiction:
Improvedetection effectivenessVSAvoidability to detect evolving malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from static signature-based detection to dynamic behavior-based monitoring. The system continuously collects file installation times, modification times, and spread patterns across multiple endpoints, then analyzes these changing parameters over time to detect malicious behavior patterns that evolve with APT attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection parameters from fixed virus signatures to variable behavioral parameters including file prevalence across endpoints, installation time sequences, modification time patterns, and spread velocity. These parameter changes enable detection of previously undetectable APT threats.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional anti-virus applications are deployed across thousands of endpoints, then security coverage is improved, but the management burden and response time increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidmanagement burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges data collection from thousands of individual endpoints into a centralized analysis system. By combining file metadata, installation patterns, and spread information across all endpoints into a unified dataset, the system reduces management complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal analysis platform that handles multiple detection functions simultaneously - identifying suspicious files, tracking spread patterns, determining prevalence across endpoints, and generating alerts. This multi-functional system reduces the need for separate tools and simplifies security operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If security teams respond to each alert individually, then detailed analysis is possible, but response time extends to days, weeks or months

Engineering Contradiction:
Improveanalysis depthVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary automated analysis of file behavior patterns, spread velocity, and endpoint prevalence before human intervention is needed. By pre-processing and filtering data to identify high-risk patterns, the system enables security teams to focus on confirmed threats rather than investigating every individual alert.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements automated feedback loops where the system continuously monitors file behavior, compares it against established patterns, and automatically generates alerts only when suspicious patterns are detected. This feedback mechanism reduces false positives and enables faster response times while maintaining analysis depth.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12086247B2Logical identification of malicious threats across a plurality of end-point devices
Publication Date: 2024.09.10 PALO ALTO NETWORKS INC
  • US12086247B2 patent drawing
  • US12086247B2 patent drawing
  • US12086247B2 patent drawing

AI summary

A computerized method for logical identification of malicious threats across a plurality of end-point devices (EPD) communicatively connected by a network, comprising collecting over the network an identifier associated with each file of a plurality of files, wherein each file of the plurality of files is installed on at least one of the plurality of EPDs and wherein the identifier is the same for each like file of the plurality of file. Information associated with an identified subset of files is collected, wherein the information indicates at least a time at which the at least one file was installed on one or more of the plurality of EPDs and the way the at least one file spread within the network. The collected information is analyzed according to a set of predetermined computerized investigation rules. The analysis is used to determine whether at least a file of the identified subset files is a suspicious file.