Multi-Modal Threat Detection System Correlating Network and Endpoint Telemetry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting security incidents in computer networks operate in a narrow scope, capturing only fragments of malware evidence, leading to prolonged investigation times for domain experts and threat analysts, as they fail to combine multiple observations and detections effectively across different data sources.

Innovation Solution

A method that combines telemetry data from various modalities, such as network logs, email activity, and endpoint logs, using unimodal detectors and a multi-modal framework to detect abnormal events and correlate them to identify security incidents, reducing analysis time and detecting new threats that would otherwise be missed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing detection methods operate in a narrow scope, then device complexity is reduced, but detection completeness deteriorates

Engineering Contradiction:
Improvedetection completenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple unimodal detection methods (static analysis, dynamic analysis, heuristic analysis) into a single multi-modal detection system. This merging allows the system to capture comprehensive malware evidence across different analysis dimensions, resolving the contradiction by achieving complete detection through integrated complexity rather than isolated simple detectors

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection system is designed to perform multiple functions simultaneously: static analysis of malware binaries, dynamic execution monitoring, heuristic behavior detection, and correlation of findings across modalities. This multi-functionality enables a single system to achieve comprehensive detection completeness while maintaining organized modular structure

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple data sources are combined, then detection accuracy is improved, but analysis time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary automated correlation and synthesis of findings from multiple data sources before presenting results to analysts. By pre-processing and integrating evidence from static analysis, dynamic analysis, and heuristic detection in advance, the system reduces the time analysts need to spend manually correlating findings, thus maintaining high detection accuracy while reducing overall analysis time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary correlation engine that automatically synthesizes findings from multiple unimodal detectors. This intermediary component correlates evidence across different data sources and modalities, providing integrated detection results without requiring analysts to manually process each data source separately, thereby maintaining accuracy while reducing time loss

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If fragments of malware evidence are captured, then data processing load is reduced, but threat detection completeness deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidthreat detection completeness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the malware detection task into multiple independent unimodal detectors, each specialized in a specific analysis type (static analysis detector, dynamic analysis detector, heuristic detector). Each segment processes specific aspects of malware evidence independently, maintaining processing efficiency while ensuring comprehensive coverage through subsequent correlation of all segments' findings

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240259414A1Comprehensible threat detection
Publication Date: 2024.08.01 CISCO TECHNOLOGY INC
  • US20240259414A1 patent drawing
  • US20240259414A1 patent drawing
  • US20240259414A1 patent drawing

AI summary

Techniques for combining threat-related events associated with different modalities to provide a complete insight into cyber attack life cycles. The techniques may include receiving telemetry data associated with one or more modalities and detecting, based at least in part on the telemetry data, one or more abnormal events associated with security incidents. The one or more abnormal events may include at least a first abnormal event associated with a first modality and a second abnormal event associated with a second modality. The techniques may also include determining that an entity associated with the abnormal events is a same entity and, based at least in part on the entity comprising the same entity, determining that a correlation between the abnormal events is indicative of a security incident. Based at least in part on the correlation, an indication associated with the security incident may be output.