Terminable Agent for Adaptive Security Incident Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-virus solutions in computerized environments are insufficient in detecting and mitigating security incidents, as they primarily rely on signature-based detection and lack adaptive capabilities to address varying types of threats effectively.

Innovation Solution

A system generates terminable agents upon detecting deviations from expected behavior in user devices, which collect and analyze metadata to determine if a security incident has occurred, and initiates appropriate actions such as terminating processes, removing content, or generating firewall protection, while terminating once the incident is cleared.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based detection methods are used, then known viruses can be identified, but new and unknown threats cannot be detected

Engineering Contradiction:
Improvevirus detection accuracyVSAvoidthreat detection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection mechanisms by switching between signature-based detection for known threats and anomaly-based detection for unknown threats. The detection approach is not static but evolves based on the nature of the threat being detected, enabling both precision for known viruses and versatility for new threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes detection parameters based on the threat type. For known viruses, it uses fixed signature parameters; for unknown threats, it dynamically adjusts parameters to detect behavioral anomalies and deviations from normal system operation, thereby achieving both detection accuracy and adaptability.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If basic virus signature searching is used, then implementation is simple, but detection effectiveness is insufficient

Engineering Contradiction:
Improvesystem implementation simplicityVSAvoidsecurity incident detection effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The security system is segmented into multiple specialized components: signature-based detection module, anomaly-based detection module, metadata collection module, and response execution module. Each segment handles specific aspects of threat detection, maintaining implementation simplicity while significantly improving detection effectiveness through coordinated operation of specialized components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces terminable agents as intermediary components that bridge the detection engine and the security response mechanisms. These agents collect metadata, analyze deviations, and execute appropriate responses, thereby enhancing detection effectiveness without significantly complicating the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If terminable agents are deployed to user devices, then adaptive threat response is enabled, but system complexity increases

Engineering Contradiction:
Improvesecurity response adaptabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The terminable agent is designed as a universal, multi-functional component that can perform multiple security operations: collecting metadata, detecting anomalies, determining security incidents, and executing various response actions. This multi-functionality reduces the need for multiple specialized components, thereby limiting the increase in system complexity while maintaining high adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The terminable agent operates autonomously on user devices, self-managing its execution and termination without requiring constant external control. It independently collects metadata, analyzes deviations, determines security incidents, and executes responses, reducing the complexity of centralized control mechanisms while maintaining adaptive security responses.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10243985B2System and methods thereof for monitoring and preventing security incidents in a computerized environment
Publication Date: 2019.03.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10243985B2 patent drawing
  • US10243985B2 patent drawing

AI summary

A system detects and handles security incidents in a computerized environment. The system collects metadata respective of one or more user devices communicatively coupled in the computerized environment. Respective of the collected metadata, the system generates expected behavior patterns of the user devices within the computerized environment. The system continuously monitors the actual behavior of the user devices. Upon detection of deviations from the expected behavior patterns, the system sends a terminable agent to the user device in which the deviation was detected. The system then receives from the terminable agent metadata respective of the deviation. Upon determination that the deviation is a security incident respective of the metadata, the system configures the terminable agent to initiate actions respective thereto. The type of actions required is determined respective of the metadata received from the terminable agent. Upon removal of the security incident, the agent may be terminated.