Entity Behavior Catalog for Security Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods to catalog and analyze entity behavior for security operations, particularly in identifying malicious or anomalous behavior resulting from internal or external influences on users, which poses a risk to security.

Innovation Solution

A method and system for cataloging entity behavior by identifying security-related activities from electronic data sources, analyzing these activities for analytic utility, and generating entity behavior catalog data to create an inventory for security operations, utilizing a processor, data bus, and non-transitory computer-readable storage medium with executable code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security monitoring methods are used, then system simplicity is maintained, but the ability to identify malicious or anomalous behavior is insufficient

Engineering Contradiction:
Improvebehavior detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments entity behavior into discrete catalogable units with specific attributes (entity identifier, behavior type, timestamp, severity level). This segmentation allows complex behavior patterns to be broken down into manageable data elements that can be systematically analyzed without overwhelming system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary behavior catalog layer between raw security events and analysis systems. This catalog serves as a structured intermediary that organizes behavior data according to predefined schemas, enabling precise detection while maintaining system modularity and manageable complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive behavior cataloging is implemented, then security analysis capability is improved, but data processing complexity increases

Engineering Contradiction:
Improvesecurity operation reliabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming raw behavior data into standardized catalog entries with specific parameters (behavior type classification, severity levels, entity identifiers). This parameterization enables reliable security analysis through consistent data structures while simplifying processing through uniform attribution schemes

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If detailed entity behavior data is collected, then security risk identification is enhanced, but information management burden increases

Engineering Contradiction:
Improvebehavior information completenessVSAvoidinformation management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent creates a universal behavior catalog structure that can accommodate multiple types of entity behaviors (user actions, system events, network activities) through a unified schema. This multi-functional catalog design enables comprehensive information collection while managing complexity through a single standardized framework applicable to diverse data sources

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12001563B2Generating an entity behavior profile based upon sessions
Publication Date: 2024.06.04 FORCEPOINT LLC
  • US12001563B2 patent drawing
  • US12001563B2 patent drawing
  • US12001563B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a security related activity, the security related activity being based upon an observable from an electronic data source; analyzing the security related activity, the analyzing identifying an event of analytic utility associated with the security related activity; generating entity behavior catalog data based upon the event of analytic utility associated with the security related activity; and, storing the entity behavior catalog data within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.