Execution Graph Security Middleware for Attack Progression Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security solutions are ineffective in detecting attack progressions in real-time across enterprise infrastructure due to their unimodal nature, reliance on artifact signatures, and high rates of false positives, making it difficult to identify and respond to infrastructure-wide attacks effectively.
Innovation Solution
A computer-implemented method using software agents deployed across operating systems to construct execution graphs from system-level activities, unify local trails into global trails, and determine risk scores, enabling real-time visualization and adaptive response to attack progressions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security solutions use artifact signatures and simple rules to detect isolated behavioral indicators, then detection capability for individual threats is improved, but false positive rates increase and attack progression detection fails
Solution Approach 1:
The patent segments the attack detection problem into multiple behavioral indicators that are monitored separately and then synthesized. Instead of relying on a single signature or rule, the system divides attack detection into discrete behavioral events (e.g., process creation, file access, network connection) that are individually tracked and collectively analyzed to form a comprehensive attack progression picture, thereby reducing false positives while maintaining detection precision.
Solution Approach 2:
The patent merges multiple weak signals from different security sensors and data sources into a unified attack progression model. By combining behavioral indicators from various system components (endpoint agents, network sensors, log sources) into a cohesive narrative of attack progression, the system achieves reliable detection without the high false positive rates associated with individual signature-based approaches.
2Reliability
If security solutions focus on entry prevention and ex post facto forensics, then asset protection and root cause identification are improved, but detection of ongoing attack progressions is lost
Solution Approach 1:
The patent implements preliminary action by establishing baseline behavioral patterns and attack progression models before attacks occur. The system pre-configures detection rules for sequences of behavioral indicators that represent common attack patterns, enabling real-time detection of ongoing attacks rather than waiting for entry prevention failure or conducting post-incident forensics.
Solution Approach 2:
The patent incorporates feedback mechanisms that continuously monitor behavioral indicators and adjust detection sensitivity based on observed patterns. The system provides real-time feedback on attack progression status, enabling security teams to respond to ongoing attacks while maintaining asset protection through adaptive detection thresholds that reduce false alarms.
3Area of stationary object
If multiple sensors monitor system activities individually, then detection coverage is improved, but the ability to connect dots across silo sources fails due to high volume of uncorrelated alerts
Solution Approach 1:
The patent implements a universal behavioral indicator framework that works across multiple sensor types and data sources. The same behavioral indicator model (sequence of events representing attack progression) applies universally to endpoint agents, network sensors, and log sources, enabling correlation across siloed security tools without requiring complex source-specific processing rules.
Solution Approach 2:
The patent introduces an intermediary layer that translates and normalizes alerts from multiple siloed security sources into a common behavioral indicator format. This intermediary processing layer correlates events across different sensor types by mapping them to standardized attack progression sequences, reducing the complexity of cross-source alert correlation while maintaining comprehensive detection coverage.
Data Source
AI summary
A novel enterprise security solution allows for precise interception and surgical response to attack progression, in real time, as it occurs across a distributed infrastructure. The solution includes a data monitoring and management framework that continually models system level host and network activities as mutually exclusive infrastructure wide execution sequences and bucketizes them into unique execution trails. A multimodal intelligent security middleware detects indicators of compromise in real-time on top of subsets of each unique execution trail using rule based behavioral analytics, machine learning based anomaly detection, and other sources. Each detection result dynamically contributes to aggregated risk scores at execution trail level granularities. These scores can be used to prioritize and identify highest risk attack trails to end users, along with steps that such end users can perform to mitigate further damage and progression of an attack.


