Security Incident Signature Correlation for Endpoint Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations often fail to implement endpoint security products on all client computing resources due to cost and resource constraints, leaving these devices inadequately protected against security threats.

Innovation Solution

A system and method that maintains a database of statistical correlations between security incident signatures from different security products, allowing a security vendor to deduce and respond to security incidents even if a specific product is not installed on a client device by generating a predictive signature report and performing protective actions based on those correlations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple endpoint security products are deployed on client devices, then security detection capability is improved, but cost and resource allocation increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidcost and resource allocation
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces an association database as an intermediary component that stores statistical correlations between multiple security products. This database enables the system to infer what additional security products would have detected, without actually deploying those products on every client device. The intermediary translates partial security coverage into comprehensive security intelligence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual representation of multiple security product detections through the association database. Instead of physically installing multiple security products on each device, the system copies the detection capabilities by querying statistical correlations that represent what other security products would have found, providing a cost-effective simulation of comprehensive security coverage.

Inventive Principle:
Principle #26Copying

2Quantity of substance

If a subset of endpoint security products is deployed due to resource constraints, then cost is reduced, but security protection coverage deteriorates

Engineering Contradiction:
Improveresource allocationVSAvoidsecurity protection coverage
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system performs preliminary action by pre-computing and storing statistical correlations between security products in the association database before actual security incidents occur. This advance preparation enables the system to quickly infer missing detection capabilities during security events without requiring additional real-time computational resources or product deployments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by using detection results from deployed security products to query the association database, which then provides inferred detections from undeployed products. This feedback loop transforms limited actual detections into comprehensive security intelligence, allowing the system to learn and adapt what additional threats would have been detected.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If statistical correlation databases are constructed using association rule mining algorithms, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex security analysis task into distinct components: (1) collecting detection data from deployed security products, (2) constructing the association database using association rule mining algorithms, and (3) querying the database during security incidents. This segmentation allows each component to be optimized independently, managing overall system complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10003606B2Systems and methods for detecting security threats
Publication Date: 2018.06.19 GEN DIGITAL INC
  • US10003606B2 patent drawing
  • US10003606B2 patent drawing
  • US10003606B2 patent drawing

AI summary

The disclosed computer-implemented method for detecting security threats may include (1) detecting, by a software security program, a security incident at a client device such that the software security program generates a signature report to identify the security incident, (2) querying an association database with the signature report to deduce another signature report that a different software security program would have predictably generated at the client device, the different software security program having been unavailable at the client device at a time of detecting the security incident, and (3) performing at least one protective action to protect the client device from a security threat associated with the security incident based on the other signature report deduced by querying the association database. Various other methods, systems, and computer-readable media are also disclosed.