Entity Behavior Catalog Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting anomalous endpoint events rely on statistical baselines that require a learning period, making initial detection challenging, especially for new endpoints, and are not effective in preventing illegitimate access to confidential information.

Innovation Solution

A system and method that monitor electronically-observable actions, convert them into electronic information, and perform anomaly detection operations based on generated representations of events, determining when these exceed a predetermined threshold, utilizing a protected endpoint and integrating with a security analytics system for real-time identity resolution and risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If statistical baselines are used for anomaly detection, then detection accuracy is improved, but a learning period is required which delays initial detection capability

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidlearning period duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing event data from multiple sources (endpoint events, network events, cloud events) before actual anomaly detection is needed. Entity behavior profiles are created in advance using this pre-collected data, establishing detection capabilities before they are formally required, thus eliminating the learning period delay.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The anomaly detection system is segmented into multiple independent components: endpoint event sources, network event sources, cloud event sources, entity behavior catalog, and anomaly detection engine. This segmentation allows each component to operate and contribute data independently, enabling immediate detection without requiring a centralized learning period.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive event monitoring is implemented, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The entity behavior profile acts as an intermediary layer between the multiple event sources (endpoint, network, cloud) and the anomaly detection engine. This profile aggregates and structures data from diverse sources into a unified format, simplifying the detection process while maintaining comprehensive monitoring capabilities across all event types.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The entity behavior profile serves multiple functions simultaneously: it stores historical behavior data, establishes baseline patterns, enables anomaly detection, and supports identity resolution. This multi-functionality reduces the need for separate systems for each task, thereby reducing overall system complexity while maintaining comprehensive detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If real-time identity resolution is performed, then security effectiveness is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary identity resolution by creating entity behavior profiles that consolidate identity information from multiple sources before security incidents occur. These pre-resolved identities are stored and readily available, enabling immediate security responses without real-time processing delays when incidents are detected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of identity and behavior information in the entity behavior profile, allowing multiple security operations to reference the same resolved identity data simultaneously without requiring repeated processing. This copying mechanism enables real-time security effectiveness while avoiding repeated computational overhead.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11949700B2Using content stored in an entity behavior catalog in combination with an entity risk score
Publication Date: 2024.04.02 FORCEPOINT LLC
  • US11949700B2 patent drawing
  • US11949700B2 patent drawing
  • US11949700B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; generating a representation of occurrences of a particular event from the plurality of events enacted by the entity; and performing an anomaly detection operation based upon the representation of occurrences of the particular event from the plurality of events enacted by the entity, the anomaly detection operation determining when the representation of occurrences of the particular event exceeds a predetermined threshold.