Known-Deployed File Metadata Repository for Endpoint Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity detection and response processes face challenges in differentiating between benign and malicious artifacts on a host endpoint, particularly in identifying artifacts introduced by adversaries or insiders, as existing methods rely on cryptographic hashes that are not specific to the environment and may not be updated frequently enough to account for legitimate changes, leading to false positives and negatives.

Innovation Solution

A known-deployed file metadata repository (KDFMR) and analysis engine that compares enumerated lists of files and metadata from a software delivery point to previously stored values, analyzes files to determine if they are atomic or container files, and updates metadata based on sandbox detonation, providing a consistent and scalable method to identify approved and centrally deployed artifacts while detecting potential adversary use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If cryptographic hashes are used to identify artifacts, then file identification is simplified, but false positives and negatives increase due to lack of environment specificity and infrequent updates

Engineering Contradiction:
Improvefile identification simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system changes the identification parameters from simple cryptographic hashes to comprehensive metadata attributes including file path, version information, digital signatures, and deployment source. This allows for environment-specific identification while maintaining automated processing, thereby improving detection accuracy without sacrificing identification simplicity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent combines multiple identification elements (metadata attributes, cryptographic hashes, version information, digital signatures) into a composite identification system. This composite approach enables more reliable artifact identification by considering multiple factors simultaneously, reducing false positives and negatives while maintaining system automation.

Inventive Principle:
Principle #40Composite materials

2Reliability

If metadata repository is updated frequently to account for legitimate changes, then detection accuracy improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing a trusted metadata repository in advance containing information about legitimate artifacts. This pre-populated repository allows for efficient comparison and detection without requiring frequent updates, as the baseline data is prepared beforehand. The repository is updated only when legitimate changes are identified through authorized channels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The metadata repository system implements self-service mechanisms through automated synchronization with software delivery points and configuration management databases. The system automatically detects, retrieves, and updates metadata for legitimate artifacts without requiring manual intervention, thereby maintaining high detection accuracy while minimizing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If all files on host endpoint are analyzed to differentiate benign from malicious, then detection completeness improves, but analysis time and computational resources increase

Engineering Contradiction:
Improvedetection completenessVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts and analyzes only the critical metadata attributes of files rather than performing comprehensive analysis of all file contents. By focusing on key identification elements such as digital signatures, version information, and deployment source, the system achieves sufficient detection completeness while dramatically reducing analysis time and computational resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by analyzing only the necessary metadata portions of files rather than complete file contents. This selective approach provides sufficient information to differentiate benign from malicious artifacts while avoiding the time and resource costs of full file analysis. The system performs exactly the amount of analysis needed to achieve detection objectives.

Inventive Principle:
Principle #16Partial or excessive action

4Measurement precision

If sandbox detonation is performed on all analyzed files, then metadata accuracy improves, but processing speed decreases

Engineering Contradiction:
Improvemetadata accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial action by performing sandbox detonation only on a selective subset of files rather than all analyzed files. Specifically, sandbox detonation is applied to files with suspicious metadata attributes, unknown sources, or those flagged by preliminary analysis. This approach maintains high metadata accuracy for critical files while preserving overall processing speed by avoiding unnecessary detonation of obviously benign artifacts.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20220366042A1Known-Deployed File Metadata Repository and Analysis Engine
Publication Date: 2022.11.17 BANK OF AMERICA CORP
  • US20220366042A1 patent drawing
  • US20220366042A1 patent drawing
  • US20220366042A1 patent drawing

AI summary

A known-deployed file metadata repository (KDFMR) and analysis engine enumerates reference lists of files stored on a software delivery point (SDP) and compares the enumerated list of files and associated metadata to previously stored values in the KDFMR. If newly stored or modified files are identified, the analysis engine acquires the files from the SDP. Each file is analyzed to determine whether the file is an atomic file or a container file and metadata is generated or extracted. Each file stored in a container file is recursively extracted and analyzed, where metadata is generated for each extracted file and each container file. The KDFMR periodically analyzes the files stored on the SDP for differences to maintain the currency of the KDFMR data with respect to files stored on the SDP. Storage or modification of files on the SDP triggers analysis of the associated file. KDFMR data is updated with metadata determined based on sandbox detonation of files and/or identified artifacts of known-deployed files.