Threat Detection via Multi-Dimensional Behavior Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions fail to detect sophisticated malware, lateral movement, data exfiltration, and inside attacks within complex networks, leading to data loss, downtime, and high recovery costs, as they rely on outdated signature and heuristic matching methods that are ineffective against advanced threat activities.

Innovation Solution

A system that monitors both north-south and east-west traffic using multiple collectors to detect first and second-order indicators of compromise, generating a risk score and incident alerts to prevent and respond to threats across the entire kill chain, including lateral movement and data exfiltration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If legacy security solutions use signature and heuristic matching methods, then they can detect known threats, but they fail to detect sophisticated malware, lateral movement, data exfiltration, and inside attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect advanced threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system transitions from static signature-based detection to dynamic behavior analysis. It continuously monitors and analyzes the behavior of processes, applications, and users in real-time, adapting to new threats by learning from observed patterns rather than relying on pre-defined signatures that cannot detect zero-day attacks or sophisticated malware.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention adds a new dimension of analysis by implementing user entity behavior analysis (UEBA) that examines not just what processes are doing, but who is doing it and in what context. This multi-dimensional approach combines process behavior, user behavior, entity relationships, and environmental context to detect threats that would be invisible to traditional single-dimension signature matching.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If current security solutions focus on detecting threat acts of infecting or penetrating a target system, then they can identify initial breaches, but they fail to detect lateral movement and data exfiltration

Engineering Contradiction:
Improvedetection of initial breachesVSAvoiddata exfiltration detection
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements continuous monitoring and analysis of entity behavior throughout the entire attack lifecycle. Rather than performing discrete security checks, it continuously tracks user and process behavior patterns, enabling detection of lateral movement and data exfiltration activities that occur after initial compromise. This continuous observation allows the system to follow the attacker's actions through the network.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system incorporates feedback loops where detected behaviors are analyzed and used to adjust detection thresholds and alerting mechanisms. When unusual behaviors are detected, the system intensifies monitoring and correlates with additional data sources, providing feedback that improves detection accuracy for subsequent events and enables real-time response to ongoing exfiltration activities.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If security solutions rely on isolated context analysis of agent behavior, then they can simplify detection processes, but they fail to detect sophisticated threat activities in complex networks

Engineering Contradiction:
Improvedetection process simplicityVSAvoidthreat detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system merges multiple previously isolated analysis contexts into a unified behavioral analysis framework. It combines process behavior analysis, user entity behavior analysis, network traffic analysis, and endpoint detection into an integrated system that correlates data across all these domains. This unified approach maintains operational simplicity through centralized management while achieving high detection precision through multi-source correlation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The invention creates a universal detection platform that performs multiple security functions through a single behavioral analysis engine. The same core technology detects malware, lateral movement, data exfiltration, insider threats, and advanced persistent threats, eliminating the need for separate specialized tools and simplifying the security operations workflow while maintaining comprehensive detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11902303B2System and method for detecting lateral movement and data exfiltration
Publication Date: 2024.02.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11902303B2 patent drawing
  • US11902303B2 patent drawing
  • US11902303B2 patent drawing

AI summary

A system configured to detect a threat activity on a network. The system including a digital device configured to detect a first order indicator of compromise on a network, detect a second order indicator of compromise on the network, generate a risk score based on correlating said first order indicator of compromise on the network with the second order indicator of compromise on said network, and generate at least one incident alert based on comparing the risk score to a threshold.