Hybrid Threat Detection Network With Local Consistency Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat detection systems face challenges in achieving reliable threat detection while keeping resource consumption at a reasonable level, particularly due to the limitations of on-sensor machine learning models, which struggle with performance overhead and limited capabilities.

Innovation Solution

A hybrid system is implemented, utilizing local threat detection models and a local consistency model at network nodes, with a backend threat detection model, where the confidence level between models determines decision-making autonomy and connectivity-dependent actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dynamic analysis techniques are used for malware detection, then detection quality is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection qualityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments detection tasks between endpoint and cloud, with simple static analysis performed locally and sophisticated dynamic analysis performed in the cloud, resolving the contradiction by distributing computational burden

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hybrid detection system acts as an intermediary between simple static analysis and complex dynamic analysis, combining both approaches to achieve high detection quality while managing resource consumption at the endpoint

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If on-sensor machine learning models are deployed for proactive detection, then detection speed is improved, but model capabilities are limited

Engineering Contradiction:
Improvedetection speedVSAvoidmodel capabilities
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The detection system is segmented into lightweight endpoint models for rapid initial detection and sophisticated cloud-based models for comprehensive analysis, allowing speed at the endpoint while maintaining high capabilities in the cloud

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Simple static analysis and lightweight ML models perform preliminary detection at the endpoint to quickly filter obvious threats, while more complex analysis is performed in the cloud, achieving both speed and capability

Inventive Principle:
Principle #10Preliminary action

3Reliability

If hybrid detection systems are implemented, then detection reliability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hybrid system is segmented into distinct endpoint and cloud components with clear division of labor, reducing overall system complexity while maintaining detection reliability through coordinated operation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses universal data formats and communication protocols between endpoint and cloud components, allowing the hybrid architecture to function as a unified system despite its distributed nature

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12506761B2Method of threat detection in a threat detection network and threat detection network utilizing threat detection model and local consistency model
Publication Date: 2025.12.23 F SECURE CORP
  • US12506761B2 patent drawing
  • US12506761B2 patent drawing
  • US12506761B2 patent drawing

AI summary

A network node of a threat detection network, a backend system of a threat detection network including interconnected network nodes and a backend system, a threat detection network and a threat detection method for such network detect network threats. The backend system utilizes a backend threat detection model, and at least part of f the network nodes include security agent modules collecting data related to the respective network node. The network nodes utilize a local threat detection model and a local consistency model. The local consistency model provides confidence level information between the local and backend detection models. The method includes collecting data related to the network node by the security agent module at the network node, applying local threat detection model to the collected data, and making a decision at the endpoint based on the results of the local threat detection model and consistency models.