Parametric Behavioral Pattern Definitions for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions require frequent updates and advanced expertise to recognize and handle new security threats, which can destabilize systems and are time-consuming, especially in addressing cyber threats that evolve rapidly.

Innovation Solution

A security agent on monitored computing devices uses parametric behavioral pattern definitions and canonical patterns to recognize and handle behavior, allowing for rapid deployment of updates without changing the agent's configuration, enabling real-time adaptation to new threats through a remote security service that disseminates new definitions and actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based scanning is used to detect security exploits, then known threats can be identified and removed, but new threats cannot be recognized and the system requires frequent updates that destabilize the host system

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidhost system stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent segments the threat detection system into two independent components: a stable signature-based scanner for known threats and a dynamic behavioral analysis module for new threats. The behavioral module observes system calls, file operations, and process activities separately from the main security suite, allowing updates to one component without destabilizing the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces behavioral descriptors as an intermediary layer between raw system activities and threat detection. These descriptors abstract complex behaviors into standardized patterns that can be analyzed without directly modifying the host system's core configuration, thus maintaining stability while enabling new threat recognition.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If configuration files and virus definitions are updated frequently to recognize new threats, then detection capability improves, but system stability deteriorates and expertise requirements increase

Engineering Contradiction:
Improvethreat recognition capabilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates behavioral descriptors that copy and abstract the essential characteristics of malicious behaviors without requiring direct updates to core virus definitions. These descriptors serve as lightweight, updateable representations of threat patterns that can be deployed independently of the main security configuration files.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent enables dynamic adjustment of behavioral analysis parameters such as observation thresholds, time windows, and activity weights without requiring full configuration file updates. These parameter changes allow the system to adapt to new threats by modifying analysis sensitivity and focus areas while maintaining the stability of the core security architecture.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If advanced operating system analysis and software testing expertise are required for updates, then detection accuracy improves, but the complexity and time required for updates increase significantly

Engineering Contradiction:
Improvethreat detection precisionVSAvoidupdate complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements automated behavioral analysis that performs its own observation, pattern recognition, and descriptor generation without requiring manual expert analysis. The system automatically monitors system calls, file operations, and process behaviors, then generates behavioral descriptors through algorithmic analysis rather than human expertise.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback loops where the behavioral analysis module continuously monitors system activities, compares observed behaviors against known patterns, and automatically refines its detection rules based on new observations. This automated feedback mechanism replaces the need for expert-driven update cycles while maintaining high detection precision.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11907370B2Malicious/benign computational behavior detection using parametric behavioral pattern definition
Publication Date: 2024.02.20 CROWDSTRIKE
  • US11907370B2 patent drawing
  • US11907370B2 patent drawing
  • US11907370B2 patent drawing

AI summary

A security agent implemented on a monitored computing device is described herein. The security agent has access to parametric behavioral pattern definitions that, in combination with canonical patterns of behavior, configure the security agent to match observed behavior with known computing behavior that is benign or malignant. This arrangement of the definitions and the pattern of behavior allow the security agent's behavior to be updated by a remote security service without updating a configuration of the security agent. The remote security service can create, modify, and disseminate these definitions and patterns of behavior, giving the security agent real-time ability to respond to new behaviors exhibited by the monitored computing device.