ML Snapshot Evaluation for Device Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing protection systems for electronic devices are ineffective against advanced malware and unauthorized access, as they can be circumvented by altering malware to evade detection, and lack real-time threat monitoring capabilities.

Innovation Solution

A protection system utilizing a machine learning engine (MLE) to generate snapshots of device operation, learn normal user behavior, and detect unusual behavior, which is then transmitted to a remote resource for evaluation by a user behavior classification engine (UBCE) to identify potential threats and provide corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional centralized protection software is used to monitor threats, then the system provides basic protection functionality, but it can be circumvented by advanced malware that operates at higher privilege levels or alters its appearance to evade detection

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidmalware evasion capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Instead of having a centralized protection system try to detect and block malware, the patent inverts the approach by having the device itself continuously monitor its own operations and report suspicious behavior to a centralized system. This inversion allows the protection mechanism to operate at the same privilege level as the monitored operations, making it impossible for malware to circumvent by operating at higher privilege levels.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary centralized analysis system that receives operation logs from multiple devices and performs sophisticated threat analysis. This intermediary system uses machine learning and behavioral analysis to detect advanced threats that local protection software cannot identify, effectively bridging the gap between simple local monitoring and complex threat detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive threat monitoring is implemented to detect all malware variations, then detection capability improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improvethreat detection precisionVSAvoidprotection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the protection system into two distinct parts: a lightweight local agent that collects operation logs and basic threat indicators, and a sophisticated centralized analysis system that performs complex machine learning and behavioral analysis. This segmentation allows high detection precision to be achieved through the centralized system while keeping local device complexity low.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The local protection agent operates autonomously, continuously monitoring device operations and generating threat assessments without requiring complex local processing. It self-manages the collection of operation logs and transmission of suspicious activity data to the centralized system, reducing the complexity burden on individual devices while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #25Self-service

3Loss of time

If real-time monitoring of all device operations is performed to detect unusual behavior, then threat detection timeliness improves, but energy consumption and processing overhead increase

Engineering Contradiction:
Improvethreat detection timeVSAvoiddevice energy consumption
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The local protection agent implements partial monitoring by focusing on capturing operation logs and basic behavioral indicators rather than analyzing every single device operation in real-time. It selectively monitors and reports suspicious or unusual operations to the centralized system, achieving timely threat detection while minimizing local energy consumption and processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The centralized analysis system acts as an intermediary that performs the computationally intensive real-time analysis of operation logs and behavioral patterns. By offloading this heavy processing to the centralized system rather than requiring it on each local device, the patent achieves comprehensive real-time monitoring capability without imposing excessive energy consumption or processing demands on individual devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3591552B1Protection system including machine learning snapshot evaluation
Publication Date: 2022.03.30 INTEL CORP
  • EP3591552B1 patent drawingFigure 1
  • EP3591552B1 patent drawingFigure 2
  • EP3591552B1 patent drawingFigure 3

AI summary

This disclosure is directed to a protection system including machine learning snapshot evaluation. A device may comprise a machine learning engine (MLE) to generate snapshots of device operation. The MLE may use active or planned operations in the snapshot to learn user behavior. Once normal user behavior is established for the device, the MLE may be able to determine when snapshots include unusual behavior that may signify a threat to the device. Snapshots determined to include unusual behavior may be transmitted to a remote resource for evaluation. The remote resource may include at least a user behavior classification engine (UBCE) to classify the user behavior by characterizing it as at least one type of use. The snapshot may be analyzed by the UBCE to determine if potential threats exist in the device, and the threat analysis may be provided to the device for evaluation and/or corrective action.