Entity Behavior Catalog Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting anomalous endpoint events rely on statistical baselines that require a learning period, making initial detection challenging, especially for new endpoints, and are not effective in preventing illegitimate access to confidential information.
Innovation Solution
A system and method that monitor electronically-observable actions, convert them into electronic information, and perform anomaly detection operations based on generated representations of events, determining when these exceed a predetermined threshold, utilizing a protected endpoint and integrating with a security analytics system for real-time identity resolution and risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If statistical baselines are used for anomaly detection, then detection accuracy is improved, but a learning period is required which delays initial detection capability
Solution Approach 1:
The system performs preliminary actions by collecting and analyzing event data from multiple sources (endpoint events, network events, cloud events) before actual anomaly detection is needed. Entity behavior profiles are created in advance using this pre-collected data, establishing detection capabilities before they are formally required, thus eliminating the learning period delay.
Solution Approach 2:
The anomaly detection system is segmented into multiple independent components: endpoint event sources, network event sources, cloud event sources, entity behavior catalog, and anomaly detection engine. This segmentation allows each component to operate and contribute data independently, enabling immediate detection without requiring a centralized learning period.
2Reliability
If comprehensive event monitoring is implemented, then detection capability is improved, but system complexity increases
Solution Approach 1:
The entity behavior profile acts as an intermediary layer between the multiple event sources (endpoint, network, cloud) and the anomaly detection engine. This profile aggregates and structures data from diverse sources into a unified format, simplifying the detection process while maintaining comprehensive monitoring capabilities across all event types.
Solution Approach 2:
The entity behavior profile serves multiple functions simultaneously: it stores historical behavior data, establishes baseline patterns, enables anomaly detection, and supports identity resolution. This multi-functionality reduces the need for separate systems for each task, thereby reducing overall system complexity while maintaining comprehensive detection capability.
3Reliability
If real-time identity resolution is performed, then security effectiveness is improved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary identity resolution by creating entity behavior profiles that consolidate identity information from multiple sources before security incidents occur. These pre-resolved identities are stored and readily available, enabling immediate security responses without real-time processing delays when incidents are detected.
Solution Approach 2:
The system creates copies of identity and behavior information in the entity behavior profile, allowing multiple security operations to reference the same resolved identity data simultaneously without requiring repeated processing. This copying mechanism enables real-time security effectiveness while avoiding repeated computational overhead.
Data Source
AI summary
A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; generating a representation of occurrences of a particular event from the plurality of events enacted by the entity; and performing an anomaly detection operation based upon the representation of occurrences of the particular event from the plurality of events enacted by the entity, the anomaly detection operation determining when the representation of occurrences of the particular event exceeds a predetermined threshold.


