Entity-Model Event Detection for Adaptive Enterprise Threat Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved threat management systems to protect enterprise networks from a variety of cybersecurity threats, including malware, viruses, and unauthorized access, while adapting to dynamic network environments and new threats.

Innovation Solution

A threat management facility that utilizes entity models to analyze event streams from compute instances within an enterprise network, employing a Sensor, Events, Analytics, and Response (SEAR) approach to detect anomalous behavior, enforce policies, and provide dynamic protection across various control points and layers, integrating with cloud services and third-party providers for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional threat management systems are used to protect enterprise networks, then basic security coverage is provided, but the systems cannot effectively detect anomalous behavior or adapt to dynamic network environments and new threats

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidadaptation to dynamic network environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic entity models that continuously learn and adapt to changing network behaviors. The anomaly detection mechanism dynamically adjusts baselines based on observed network traffic patterns, enabling the system to adapt to dynamic network environments while maintaining reliable threat detection through continuous model updates and retraining

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where detection results and analyst confirmations are used to continuously refine entity models. The feedback mechanism updates baseline behaviors and retraining data based on confirmed anomalies and false positives, improving both detection accuracy and adaptability to new threats over time through iterative model optimization

Inventive Principle:
Principle #23Feedback

2Reliability

If centralized event detection with entity models is implemented to detect anomalous behavior, then threat detection accuracy is improved, but system complexity increases due to multiple control points and integration requirements

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs universal entity models that can be applied across multiple control points and network layers. The same entity model framework detects anomalies in diverse data sources including network traffic, endpoint events, and cloud services, reducing integration complexity through a unified detection approach while maintaining high anomaly detection capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces intermediary components that standardize data collection and event normalization across different control points. The entity model framework acts as an intermediary layer that translates diverse network events into unified anomaly detection queries, simplifying system integration while enabling comprehensive anomaly detection across multiple network layers

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time threat detection and response is implemented across all compute instances, then network protection is enhanced, but computational resources and processing time are consumed

Engineering Contradiction:
Improvenetwork protection coverageVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring strategies where entity models focus computational resources on detecting specific high-risk anomaly patterns rather than analyzing all events uniformly. The baseline comparison mechanism selectively flags only deviations from established norms for detailed analysis, reducing overall computational resource consumption while maintaining comprehensive network protection coverage through targeted detection

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12481777B2Centralized event detection
Publication Date: 2025.11.25 SOPHOS LTD
  • US12481777B2 patent drawing
  • US12481777B2 patent drawing
  • US12481777B2 patent drawing

AI summary

A threat management facility stores a number of entity models that characterize reportable events from one or more entities. A stream of events from compute instances within an enterprise network can then be analyzed using these entity models to detect behavior that is inconsistent or anomalous for one or more of the entities that are currently active within the enterprise network.