Threat Detection Network with Local Behavior Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Endpoint Detection & Response (EDR) systems face challenges with large data volumes, leading to increased costs and resource consumption, and struggle to detect subtle behavioral changes indicative of malicious activity, particularly when attackers mimic normal behavior.
Innovation Solution
A threat detection method involving security agent modules that collect and analyze data to generate local behavior models, share these models across network nodes and a backend system, and alert on deviations from expected behavior, using machine learning models to identify anomalies and automate data collection adjustments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If selective data collection limitation is implemented, then data overhead is reduced, but threat detection effectiveness deteriorates
Solution Approach 1:
The patent segments data collection and processing across multiple levels: local endpoint agents collect data locally, local behavior models are generated at each endpoint, and these models are then shared with the backend. This segmentation allows selective transmission of only essential behavioral models rather than raw data, reducing data overhead while maintaining detection effectiveness through distributed intelligence.
2Measurement precision
If complete data collection is implemented, then threat detection accuracy is improved, but resource consumption increases
Solution Approach 1:
The patent extracts the essential behavioral patterns from raw data by generating behavior models locally at each endpoint. Instead of transmitting complete raw data to the backend, only the extracted behavioral models are shared. This extraction process maintains detection accuracy by preserving key behavioral characteristics while dramatically reducing the volume of data that needs to be transmitted and processed centrally.
3Reliability
If behavior models are shared across all nodes, then detection reliability is improved, but data transfer volume increases
Solution Approach 1:
The patent creates behavior models that serve multiple functions: they are generated locally for immediate anomaly detection at the endpoint, and simultaneously shared with the backend and other nodes for centralized analysis and cross-endpoint correlation. This multi-functionality allows the same behavioral data structure to serve both local and centralized detection needs, reducing redundant data transfer while maintaining comprehensive detection coverage.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A network node (5a-5h) of a threat detection network, a backend server (2) of a threat detection network, a threat detection network and a threat detection method in a threat detection network. The threat detection network comprises interconnected network nodes (5a-5h) and a backend system (2), wherein at least part of the nodes (5a-5h) comprise security agent modules (6a-6h) which collect data related to the respective network node (5a-5h). The method comprises collecting and/or analyzing at the network node (5a-5h) data related to a network node (5a-5h), generating at least one local behavior model at the network node (5a-5h) related to the network node (5a-5h) on the basis of the collected and/or analyzed data, sharing at least one generated local behavior model related to the network node (5a-5h) with one or more other nodes (5a-5h) and/or with the backend system (2), comparing user activity in a node (5a-5h) to the generated local behavior model and/or a received behavior model, and alerting the backend (2) and/or the other nodes (5a-5h ), e.g. about anomalous behavior, if deviation from the generated local behavior model and/or the received behavior model is detected.