Entity Group Behavior Profiling for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems face challenges in detecting localized and targeted malware attacks due to their reliance on cloud-based threat intelligence, which can lead to false positives and inaccuracies, and individual entity behavior profiling is sensitive to dynamic changes, resulting in either false positives or false negatives.
Innovation Solution
A multi-tier security framework that includes network sensor engines, a data analysis engine, and a centralized controller, which collects and analyzes local and global data to model entity group behavior, providing collaborative and adaptive threat intelligence by profiling entities within groups to detect anomalous behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If cloud-based threat intelligence is used to detect threats, then global threat detection capability is improved, but sensitivity to localized attacks deteriorates
Solution Approach 1:
The system segments threat intelligence into two distinct components: cloud-based global threat intelligence and local-based localized threat intelligence. Each component serves a specific purpose - global intelligence provides broad threat patterns while local intelligence captures site-specific attack patterns. This segmentation allows the system to maintain both global awareness and local sensitivity simultaneously.
Solution Approach 2:
The patent merges cloud-based and local-based threat intelligence systems into a unified hybrid architecture. The local sensor receives both global blacklist data from the cloud and local attack data from local sensors, combining them to make comprehensive threat detection decisions. This merging resolves the contradiction by allowing both global and local intelligence to work together rather than in opposition.
2Measurement precision
If individual entity behavior profiling is used, then entity-specific monitoring is improved, but false positives and false negatives increase
Solution Approach 1:
The system transitions from one-dimensional individual entity profiling to multi-dimensional entity group profiling. Instead of monitoring entities in isolation, the system profiles entities within their organizational groups, adding the dimension of group context. This allows behavior to be evaluated relative to group norms rather than individual baselines, reducing false positives caused by legitimate individual variations while maintaining detection sensitivity.
3Area of stationary object
If cloud-based threat intelligence is used, then global intelligence coverage is improved, but response to localized threats deteriorates
Solution Approach 1:
The system implements local quality by enabling different parts of the threat intelligence system to have different characteristics. The cloud component provides global coverage with broad threat patterns, while the local component provides localized responsiveness with site-specific attack patterns. Each component is optimized for its specific function, allowing the overall system to excel at both global coverage and local response.
4Measurement precision
If traditional behavior profiling is used, then individual entity monitoring is improved, but sensitivity to group-based attacks deteriorates
Solution Approach 1:
The patent merges individual entity monitoring with group-based profiling into a unified approach. Entities are monitored both as individuals and as members of organizational groups. This dual approach allows the system to detect both individual anomalies and group-based attack patterns, resolving the contradiction between individual monitoring precision and group attack detection capability.
Data Source
AI summary
Entity group behavior profiling. An entity group is created that includes multiple entities, where each entity represents one of a user, a machine, and a service. A behavior profile is created for each one of the entities of the entity group. The behavior of each of one of the entities of the entity group is monitored to detect behavior change. An indicator of compromise is detected based on multiple ones of the entities experiencing substantially a same behavior change.


