UEBA-EDR Integration for Security Event Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint security tools lack sufficient context and information for confident security event classification, leading to inefficiencies in identifying and addressing security incidents.

Innovation Solution

Integration of User Entity Behavior Analytics (UEBA) with endpoint detection and response (EDR) technology to enhance security event classification by leveraging historical user behavior data and machine-learning classifiers for more accurate threat assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If endpoint detection and response (EDR) technology is used for security event classification, then security events can be detected and blocked, but the classification accuracy is insufficient due to lack of context and information

Engineering Contradiction:
Improvesecurity event classification accuracyVSAvoidcontext and information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent combines EDR technology with User Entity Behavior Analytics (UEBA) to merge endpoint-level security detection with user behavior context. The UEBA component analyzes historical user behavior patterns and provides contextual information about user activities, which is then integrated with EDR security events to improve classification accuracy and reduce false positives.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces UEBA as an intermediary system that bridges the gap between raw security events and meaningful classification. The UEBA system acts as a mediator that enriches security events with user behavior context, providing the missing information needed for accurate classification without requiring changes to the core EDR functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual investigation and classification of security incidents is performed, then accurate classification can be achieved, but the total cost of ownership increases

Engineering Contradiction:
Improvesecurity incident classification accuracyVSAvoidtotal cost of ownership
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements automated investigation and classification capabilities through the integration of EDR and UEBA systems. The combined system performs self-service security event analysis by automatically correlating security events with user behavior patterns, eliminating the need for manual investigation while maintaining high classification accuracy and reducing operational costs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the operational parameters of security classification from manual processes to automated processes by introducing machine learning algorithms and behavior analytics. This transformation maintains classification accuracy while significantly reducing the resource requirements and total cost of ownership associated with manual security incident management.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If automated investigation and classification is implemented, then total cost of ownership is reduced, but classification accuracy may be insufficient without sufficient context

Engineering Contradiction:
Improvetotal cost of ownershipVSAvoidsecurity event classification accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent implements preliminary action by continuously collecting and analyzing user behavior data before security incidents occur. The UEBA system establishes baseline user behavior patterns in advance, so when security events are detected, the automated classification system already has contextual information ready, enabling accurate automated classification without manual intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the automated classification system continuously learns from classified security events and refines its understanding of user behavior patterns. This feedback loop improves classification accuracy over time while maintaining automated operation, ensuring that the system becomes increasingly accurate without requiring additional manual resources.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11924235B2Leveraging user-behavior analytics for improved security event classification
Publication Date: 2024.03.05 FORTINET INC
  • US11924235B2 patent drawing
  • US11924235B2 patent drawing
  • US11924235B2 patent drawing

AI summary

Systems and methods for improving security event classification by leveraging user-behavior analytics are provided. According to an embodiment, a UEBA-based security event classification service of a cloud-based security platform maintains information regarding historical user behavior of various users of an enterprise network. An endpoint protection platform running on an endpoint device that is part of the enterprise network performs an initial classification of the event, based on which the endpoint protection platform blocks activity by the process. The endpoint production platform requests input from the cloud-based security platform which causes the cloud-based security platform performs a reclassification of the event based on contextual information, multiple data feeds and the UEBA-based security event classification service. Based on the reclassification of the event, the cloud-based security platform causes the endpoint protection platform to allow the process to proceed by providing the resulting security event classification to the endpoint protection platform.