Multi-Modal Threat Detection System Correlating Network and Endpoint Telemetry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting security incidents in computer networks operate in a narrow scope, capturing only fragments of malware evidence, leading to prolonged investigation times for domain experts and threat analysts, as they fail to combine multiple observations and detections effectively across different data sources.
Innovation Solution
A method that combines telemetry data from various modalities, such as network logs, email activity, and endpoint logs, using unimodal detectors and a multi-modal framework to detect abnormal events and correlate them to identify security incidents, reducing analysis time and detecting new threats that would otherwise be missed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing detection methods operate in a narrow scope, then device complexity is reduced, but detection completeness deteriorates
Solution Approach 1:
The patent combines multiple unimodal detection methods (static analysis, dynamic analysis, heuristic analysis) into a single multi-modal detection system. This merging allows the system to capture comprehensive malware evidence across different analysis dimensions, resolving the contradiction by achieving complete detection through integrated complexity rather than isolated simple detectors
Solution Approach 2:
The detection system is designed to perform multiple functions simultaneously: static analysis of malware binaries, dynamic execution monitoring, heuristic behavior detection, and correlation of findings across modalities. This multi-functionality enables a single system to achieve comprehensive detection completeness while maintaining organized modular structure
2Measurement precision
If multiple data sources are combined, then detection accuracy is improved, but analysis time increases
Solution Approach 1:
The system performs preliminary automated correlation and synthesis of findings from multiple data sources before presenting results to analysts. By pre-processing and integrating evidence from static analysis, dynamic analysis, and heuristic detection in advance, the system reduces the time analysts need to spend manually correlating findings, thus maintaining high detection accuracy while reducing overall analysis time
Solution Approach 2:
The patent introduces an intermediary correlation engine that automatically synthesizes findings from multiple unimodal detectors. This intermediary component correlates evidence across different data sources and modalities, providing integrated detection results without requiring analysts to manually process each data source separately, thereby maintaining accuracy while reducing time loss
3Productivity
If fragments of malware evidence are captured, then data processing load is reduced, but threat detection completeness deteriorates
Solution Approach 1:
The patent segments the malware detection task into multiple independent unimodal detectors, each specialized in a specific analysis type (static analysis detector, dynamic analysis detector, heuristic detector). Each segment processes specific aspects of malware evidence independently, maintaining processing efficiency while ensuring comprehensive coverage through subsequent correlation of all segments' findings
Data Source
AI summary
Techniques for combining threat-related events associated with different modalities to provide a complete insight into cyber attack life cycles. The techniques may include receiving telemetry data associated with one or more modalities and detecting, based at least in part on the telemetry data, one or more abnormal events associated with security incidents. The one or more abnormal events may include at least a first abnormal event associated with a first modality and a second abnormal event associated with a second modality. The techniques may also include determining that an entity associated with the abnormal events is a same entity and, based at least in part on the entity comprising the same entity, determining that a correlation between the abnormal events is indicative of a security incident. Based at least in part on the correlation, an indication associated with the security incident may be output.


