Security Incident Signature Correlation for Endpoint Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise organizations often fail to implement endpoint security products on all client computing resources due to cost and resource constraints, leaving these devices inadequately protected against security threats.
Innovation Solution
A system and method that maintains a database of statistical correlations between security incident signatures from different security products, allowing a security vendor to deduce and respond to security incidents even if a specific product is not installed on a client device by generating a predictive signature report and performing protective actions based on those correlations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple endpoint security products are deployed on client devices, then security detection capability is improved, but cost and resource allocation increase
Solution Approach 1:
The patent introduces an association database as an intermediary component that stores statistical correlations between multiple security products. This database enables the system to infer what additional security products would have detected, without actually deploying those products on every client device. The intermediary translates partial security coverage into comprehensive security intelligence.
Solution Approach 2:
The system creates a virtual representation of multiple security product detections through the association database. Instead of physically installing multiple security products on each device, the system copies the detection capabilities by querying statistical correlations that represent what other security products would have found, providing a cost-effective simulation of comprehensive security coverage.
2Quantity of substance
If a subset of endpoint security products is deployed due to resource constraints, then cost is reduced, but security protection coverage deteriorates
Solution Approach 1:
The system performs preliminary action by pre-computing and storing statistical correlations between security products in the association database before actual security incidents occur. This advance preparation enables the system to quickly infer missing detection capabilities during security events without requiring additional real-time computational resources or product deployments.
Solution Approach 2:
The system implements feedback by using detection results from deployed security products to query the association database, which then provides inferred detections from undeployed products. This feedback loop transforms limited actual detections into comprehensive security intelligence, allowing the system to learn and adapt what additional threats would have been detected.
3Measurement precision
If statistical correlation databases are constructed using association rule mining algorithms, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the complex security analysis task into distinct components: (1) collecting detection data from deployed security products, (2) constructing the association database using association rule mining algorithms, and (3) querying the database during security incidents. This segmentation allows each component to be optimized independently, managing overall system complexity while maintaining high detection accuracy.
Data Source
AI summary
The disclosed computer-implemented method for detecting security threats may include (1) detecting, by a software security program, a security incident at a client device such that the software security program generates a signature report to identify the security incident, (2) querying an association database with the signature report to deduce another signature report that a different software security program would have predictably generated at the client device, the different software security program having been unavailable at the client device at a time of detecting the security incident, and (3) performing at least one protective action to protect the client device from a security threat associated with the security incident based on the other signature report deduced by querying the association database. Various other methods, systems, and computer-readable media are also disclosed.


