Entity State Analysis Using PT Networks for Security Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In complex computing environments with numerous entities, it is difficult to effectively monitor and respond to security issues due to the high number and complexity of entities, often requiring technical expertise that may be lacking in users.
Innovation Solution
A state-based entity behavior analysis system using a place/transition (PT) network to model entity states, evaluate events with deterministic and stochastic factors, and apply machine learning, enabling actions such as remediation and relationship adjustments based on state changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual monitoring of each entity is performed, then security issue detection accuracy is improved, but monitoring efficiency and scalability deteriorate due to the high number and complexity of entities
Solution Approach 1:
The patent introduces an automated entity behavior analysis system as an intermediary between manual monitoring and security issue detection. The system uses machine learning models to automatically analyze entity behaviors, evaluate security risks, and generate alerts, thereby maintaining high detection accuracy while eliminating the need for manual review of each entity.
Solution Approach 2:
The patent replaces manual mechanical monitoring processes with automated computational systems. Machine learning algorithms and automated analysis tools substitute human operators, enabling the system to process and evaluate numerous entities simultaneously without the limitations of human capacity and expertise.
2Reliability
If comprehensive monitoring of all entities is implemented, then security coverage is improved, but system complexity and resource requirements worsen
Solution Approach 1:
The patent extracts and focuses monitoring resources on entities and behaviors that pose the highest security risks. By using machine learning to identify and prioritize critical entities, the system achieves comprehensive security coverage for high-risk targets without the need to monitor every entity in detail, thereby reducing overall system complexity.
Solution Approach 2:
The patent applies different monitoring intensities and analysis methods to different entities based on their risk profiles. High-risk entities receive more rigorous monitoring and analysis, while low-risk entities receive lighter monitoring, optimizing security coverage while minimizing the complexity and resources required for the overall system.
3Measurement precision
If detailed analysis of each security event is performed, then detection accuracy is improved, but response time and operational burden worsen
Solution Approach 1:
The patent performs preliminary analysis of entity behaviors and security events using machine learning models before full investigation is required. The system pre-evaluates events, identifies potential threats, and prioritizes them for further review, enabling faster response times while maintaining accurate detection through pre-computed risk assessments.
Solution Approach 2:
The patent applies partial analysis to low-risk events and excessive (detailed) analysis only to high-risk events. This differentiated approach allows the system to quickly process the majority of events with automated partial analysis while reserving detailed analysis for critical cases, thereby reducing overall response time without sacrificing detection accuracy for important threats.
Data Source
AI summary
Examples of the present disclosure describe systems and methods for state-based entity behavior analysis. In an example, entities of a computing environment may be represented using a hierarchical entity web. In some examples, an entity may have a state associated with it, which may be modeled using a place/transition (PT) network. Events within the computing environment may be evaluated by transitions of a PT network to determine whether an entity should change state. If an entity transitions from one state to another, one or more actions may be performed, including, but not limited to, taking a remedial action, generating a recommendation, and updating the state of one or more associated entities. Thus, aspects disclosed herein may provide a high-level overview of the state of entities of a computing environment, but may also be used to view in-depth information of entities at lower levels of the hierarchical entity web.


