Endpoint Compromise Detection via Log Entropy Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems lack an effective aggregate view to detect compromised endpoints, as they primarily focus on discrete components rather than analyzing the collective log data from sensors like McAfee ePO or SIEM, which can miss unusual activity patterns indicative of malware attacks.

Innovation Solution

The solution involves analyzing log entropy changes across endpoints by calculating internal and external entropy scores based on unique log entries within a time window, allowing for the detection of compromised endpoints without reviewing log content, and using machine learning algorithms to enhance detection accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If discrete security sensors (VSE, NSP, etc.) are used to monitor endpoints, then specific security events can be detected, but an aggregate view of compromised endpoints is missing

Engineering Contradiction:
Improvedetection accuracyVSAvoidaggregate view
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent consolidates log data from multiple discrete security sensors (VSE, NSP, and other components of McAfee ePO or SIEM systems) into a unified analysis framework. By merging these previously separate log streams and analyzing them collectively through entropy calculations, the system recovers the aggregate view that was previously lost, enabling detection of compromised endpoints through patterns that span across multiple sensor types.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If log content is reviewed manually to identify compromised endpoints, then detection accuracy improves, but processing time and resource requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent transforms the analysis approach by changing the parameter from content-based manual review to entropy-based automated calculation. Instead of examining log entry contents semantically, the system calculates entropy scores (internal and external) from log frequency patterns, enabling rapid automated detection that maintains high accuracy while dramatically reducing processing time and resource requirements.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the manual mechanical process of reviewing log content with an automated computational system that calculates entropy metrics. This substitution eliminates the need for human analysts to manually examine log entries, automating the detection process while preserving detection accuracy through mathematical entropy analysis of log frequency patterns.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If traditional security monitoring analyzes log content semantically, then specific threats can be identified, but unusual activity patterns are missed

Engineering Contradiction:
Improvethreat identificationVSAvoidpattern detection
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional approach by not analyzing what log entries say (semantic content) but rather how frequently they occur (temporal patterns). This inversion enables the detection of unusual activity patterns that deviate from normal entropy expectations, identifying compromised endpoints through anomalies in log frequency rather than through semantic threat indicators.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11916934B2Identifying malware-suspect end points through entropy changes in consolidated logs
Publication Date: 2024.02.27 MAGENTA SECURITY HOLDINGS LLC
  • US11916934B2 patent drawing
  • US11916934B2 patent drawing
  • US11916934B2 patent drawing

AI summary

Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.