UEBA-EDR Integration for Security Event Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint security tools lack sufficient context and information for confident security event classification, leading to inefficiencies in identifying and addressing security incidents.
Innovation Solution
Integration of User Entity Behavior Analytics (UEBA) with endpoint detection and response (EDR) technology to enhance security event classification by leveraging historical user behavior data and machine-learning classifiers for more accurate threat assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If endpoint detection and response (EDR) technology is used for security event classification, then security events can be detected and blocked, but the classification accuracy is insufficient due to lack of context and information
Solution Approach 1:
The patent combines EDR technology with User Entity Behavior Analytics (UEBA) to merge endpoint-level security detection with user behavior context. The UEBA component analyzes historical user behavior patterns and provides contextual information about user activities, which is then integrated with EDR security events to improve classification accuracy and reduce false positives.
Solution Approach 2:
The patent introduces UEBA as an intermediary system that bridges the gap between raw security events and meaningful classification. The UEBA system acts as a mediator that enriches security events with user behavior context, providing the missing information needed for accurate classification without requiring changes to the core EDR functionality.
2Measurement precision
If manual investigation and classification of security incidents is performed, then accurate classification can be achieved, but the total cost of ownership increases
Solution Approach 1:
The patent implements automated investigation and classification capabilities through the integration of EDR and UEBA systems. The combined system performs self-service security event analysis by automatically correlating security events with user behavior patterns, eliminating the need for manual investigation while maintaining high classification accuracy and reducing operational costs.
Solution Approach 2:
The patent changes the operational parameters of security classification from manual processes to automated processes by introducing machine learning algorithms and behavior analytics. This transformation maintains classification accuracy while significantly reducing the resource requirements and total cost of ownership associated with manual security incident management.
3Device complexity
If automated investigation and classification is implemented, then total cost of ownership is reduced, but classification accuracy may be insufficient without sufficient context
Solution Approach 1:
The patent implements preliminary action by continuously collecting and analyzing user behavior data before security incidents occur. The UEBA system establishes baseline user behavior patterns in advance, so when security events are detected, the automated classification system already has contextual information ready, enabling accurate automated classification without manual intervention.
Solution Approach 2:
The patent incorporates feedback mechanisms where the automated classification system continuously learns from classified security events and refines its understanding of user behavior patterns. This feedback loop improves classification accuracy over time while maintaining automated operation, ensuring that the system becomes increasingly accurate without requiring additional manual resources.
Data Source
AI summary
Systems and methods for improving security event classification by leveraging user-behavior analytics are provided. According to an embodiment, a UEBA-based security event classification service of a cloud-based security platform maintains information regarding historical user behavior of various users of an enterprise network. An endpoint protection platform running on an endpoint device that is part of the enterprise network performs an initial classification of the event, based on which the endpoint protection platform blocks activity by the process. The endpoint production platform requests input from the cloud-based security platform which causes the cloud-based security platform performs a reclassification of the event based on contextual information, multiple data feeds and the UEBA-based security event classification service. Based on the reclassification of the event, the cloud-based security platform causes the endpoint protection platform to allow the process to proceed by providing the resulting security event classification to the endpoint protection platform.


