Trusted File Awareness Using Endpoint–Cloud Event Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to accurately detect data exfiltration via network-based services, such as cloud storage, due to the generation of massive amounts of non-indicative alerts, making it difficult to prevent unauthorized data transfers from authorized computing devices to unauthorized accounts or vice versa.
Innovation Solution
A system that monitors both endpoint and authorized accounts on network-based service providers for file system element events, matching events from both sources to identify unauthorized transfers by correlating file system element events on client computing devices with those on network-based services, thereby reducing false alarms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional monitoring methods are used to detect data exfiltration, then coverage of detection is improved, but false alarm rate increases significantly
Solution Approach 1:
The patent segments the detection process into two independent monitoring components: one monitoring the client computing device and another monitoring the network-based service account. By dividing the detection into separate event streams that are later correlated, the system can identify true exfiltration events while filtering out false alarms that occur in only one stream.
Solution Approach 2:
The patent introduces an intermediary correlation mechanism that matches events between the client device stream and the service account stream. This intermediary layer compares file system element events from both sources and identifies mismatches that indicate true exfiltration, while filtering out matched events that represent legitimate operations.
2Measurement precision
If monitoring is performed on both endpoint and network service, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The monitoring system is segmented into two independent but coordinated components: endpoint monitoring on the client device and service monitoring on the network-based service. Each component independently collects events from its respective source, reducing the complexity of any single monitoring module while achieving high detection accuracy through their coordination.
Solution Approach 2:
Each monitoring component operates autonomously, collecting and processing events from its own source independently. The endpoint monitor collects file system events locally, while the service monitor collects account events independently. They then self-correlate through event matching without requiring complex centralized coordination, reducing overall system complexity.
Data Source
AI summary
Disclosed in some examples are methods, systems, devices, and machine-readable mediums which monitor for file system element transfers to and from both the endpoint and authorized accounts on network-based service providers (e.g., cloud-based storage). The system uses the capabilities of monitoring both the network-based service and the client computing device to filter out legitimate uploads to authorized network-based services and legitimate downloads to authorized computing devices. By matching events, it filters out events that are likely legitimate, the system may provide more accurate information, notifications, awareness, and unmatched event indications.


