Spoofed Entity Detection Through Event Distribution Complexity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity tools are vulnerable to spoofing attacks where malicious entities tamper with agents or centralized server components to report false information, leading to alert fatigue and delayed threat response.

Innovation Solution

Detect spoofed entities by analyzing the complexity of event distributions initiated by these entities, using machine learning and neural networks to identify patterns that deviate from normal behavior, and perform security actions to mitigate the threat.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cybersecurity tools monitor behavior of machines and users to detect malicious activity, then security detection capability is improved, but the system becomes vulnerable to spoofing attacks where malicious entities report false information

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidspoofing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback loops where telemetry data from entities is continuously monitored, analyzed, and used to update entity profiles and detection models. The centralized server component receives telemetry, analyzes patterns, and adjusts security responses based on the complexity analysis results, creating a closed-loop feedback system that improves detection over time while maintaining reliability against spoofing attacks

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary analysis layer that sits between raw telemetry data and security decisions. The centralized server component acts as a mediator that processes telemetry through complexity analysis before triggering security responses, filtering out spoofed information while preserving legitimate alerts, thus resolving the contradiction between detection sensitivity and vulnerability to false information

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If agents gather data from machines and centralized server processes the data, then detection coverage is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is segmented into distinct functional components: lightweight agents deployed on machines for data collection, a centralized server for processing, and distributed analysis capabilities. This segmentation allows each component to have specialized, optimized functionality, reducing overall system complexity while maintaining comprehensive detection coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The centralized server component performs multiple functions including receiving telemetry from various agents, analyzing complexity patterns, maintaining entity profiles, and coordinating security responses. This multi-functionality consolidates capabilities into a single platform, improving detection coverage without proportionally increasing system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If spoofed machines report false information to create false flags, then alert volume increases, but security operations center efficiency deteriorates due to alert fatigue

Engineering Contradiction:
Improvefalse information volumeVSAvoidsecurity operations center efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system applies partial action by not responding to every alert with the same level of scrutiny. Instead, it uses complexity analysis to differentiate between high-value alerts requiring immediate attention and low-value spoofed alerts that can be filtered or aggregated, reducing alert fatigue while maintaining security effectiveness

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the parameter used for alert evaluation from simple match criteria to complexity-based scoring. By analyzing the distribution and complexity of telemetry parameters, the system transforms raw alert volume into prioritized security intelligence, improving operations center efficiency by focusing resources on high-complexity, high-probability threats

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If the system analyzes complexity of event distributions to detect spoofed entities, then detection accuracy is improved, but computational requirements increase

Engineering Contradiction:
Improvespoof detection accuracyVSAvoidcomputational processing energy
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by establishing baseline entity profiles and expected telemetry patterns before analyzing new data. This pre-computation of normal behavior patterns allows the system to quickly compare incoming telemetry against established baselines, improving detection accuracy while reducing real-time computational energy requirements

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12425448B2Detecting a spoofed entity based on complexity of a distribution of events initiated by the spoofed entity
Publication Date: 2025.09.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12425448B2 patent drawing
  • US12425448B2 patent drawing
  • US12425448B2 patent drawing

AI summary

Techniques are described herein that are capable of detecting a spoofed entity based on complexity of a distribution of events initiated by the spoofed entity. Frequencies with which events of event types are initiated are determined by an entity during a designated period of time. Complexity of a distribution of the events among the event types is determined based at least on the frequencies with which the events of the event types are initiated by the entity during the designated period of time. Based at least on the complexity of the distribution of the events among the event types being less than or equal to a complexity threshold, the entity is identified as a spoofed entity associated with a spoofing attack. A security action is performed with regard to the entity based at least on the entity being identified as the spoofed entity associated with the spoofing attack.