Secure Computing Environment with Behavioral Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing agent-based cyber security systems are inadequate in protecting against sophisticated zero-day attacks, are resource-intensive, and lack effective post-incident recovery mechanisms, making them susceptible to evasion and resource consumption issues in multi-virtual endpoint environments.

Innovation Solution

A secure computing environment is created by defining policies for node behavior, executing processes, determining discrepancies between prescribed and actual behavior, and performing remedial actions such as restarting nodes or modifying IP addresses, which includes a classification module to classify processes as malicious or non-malicious and relocate processes to mitigate attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If agent-based security systems are deployed to protect against known threats, then security protection is improved, but resource consumption increases and responsiveness decreases

Engineering Contradiction:
Improvesecurity protectionVSAvoidresponsiveness
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments security monitoring into two parts: a lightweight agent on each host that collects basic data, and a centralized analysis server that performs complex behavioral analysis. This segmentation reduces the resource burden on individual hosts while maintaining comprehensive security monitoring across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized security analysis server as an intermediary that receives data from multiple host agents and performs sophisticated threat detection. This intermediary handles the computationally intensive tasks of behavioral baseline creation and anomaly detection, freeing up host resources while maintaining high security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If signature-based detection methods are used to identify known threats, then detection accuracy is improved, but ability to detect zero-day attacks deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidzero-day attack detection
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system dynamically creates behavioral baselines for each host by continuously monitoring normal operations over time. These baselines adapt to changing legitimate behaviors while automatically flagging deviations that may indicate zero-day attacks, combining the precision of known threat detection with the adaptability needed for unknown threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where detected anomalies trigger enhanced monitoring and analysis. When unusual behavior is detected, the system adjusts its monitoring focus and creates updated behavioral baselines, enabling continuous improvement in detecting both known and unknown threats through iterative learning from observed system behavior.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If manual rule definition is required for intrusion detection, then detection specificity is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedetection specificityVSAvoidease of use
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The system performs self-service by automatically creating behavioral baselines and detection rules without requiring manual configuration. The security analysis server autonomously monitors host behavior, learns normal patterns, and generates detection rules dynamically, eliminating the need for security personnel to manually define detection parameters while maintaining high detection specificity.

Inventive Principle:
Principle #25Self-service

4Reliability

If agents run continuously as background processes to maintain security, then security coverage is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The host agents perform periodic status checks and data collection rather than continuous intensive processing. They gather security-relevant information at scheduled intervals and transmit it to the central analysis server, maintaining comprehensive security coverage while significantly reducing continuous resource consumption on individual hosts.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10230750B2Secure computing environment
Publication Date: 2019.03.12 IRIDIUM SECURITY LLC
  • US10230750B2 patent drawing
  • US10230750B2 patent drawing
  • US10230750B2 patent drawing

AI summary

Methods and systems for providing secure computing environments. Features of the present invention use a plurality of integrated security controls to ensure security of a computing environment. More specifically, features of the present invention detect discrepancies between a node's behavior and a defined policy to identify and remedy malicious behavior.