Unknown Application Detection via Event Resolution and Registry Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems fail to detect and monitor software applications that are not officially provided by an organization, posing a security risk due to undetected usage and lack of configuration consistency.
Innovation Solution
An application identification server scans recorded events for target information, applies resolution techniques to identify unknown applications, and compares them to an organization-specific registry to determine and analyze their risk, enabling monitoring and restriction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security teams monitor only officially purveyed applications, then configuration consistency and security control are improved, but detection capability for unknown applications deteriorates
Solution Approach 1:
The system performs preliminary actions by proactively scanning recorded events and applying resolution techniques to identify unknown applications before they can pose security risks. The application identification server continuously monitors network traffic and detects target information, then resolves this information to identify applications that need to be added to the organization's known applications list.
Solution Approach 2:
The patent introduces an intermediary system - the application identification server - that acts as a mediator between network traffic monitoring and security policy enforcement. This intermediary component analyzes recorded events, applies resolution techniques, and provides intelligence about unknown applications to both the monitoring system and security teams.
2Reliability
If the organization maintains a registry of known applications, then security control and configuration consistency are improved, but the ability to detect new or unknown applications deteriorates
Solution Approach 1:
The system implements feedback mechanisms where the application identification server continuously monitors network traffic, identifies unknown applications, and provides feedback to update the organization's known applications registry. This feedback loop enables the system to adapt to new applications while maintaining security control through the registry.
Solution Approach 2:
The system performs preliminary identification of unknown applications through scanning recorded events and applying resolution techniques before these applications are officially recognized. This preliminary action allows the organization to detect and respond to new applications proactively rather than reactively.
3Reliability
If security teams manually detect unknown applications, then configuration consistency can be maintained, but productivity and response time deteriorate
Solution Approach 1:
The application identification server performs self-service by automatically scanning recorded events, applying resolution techniques, and identifying unknown applications without requiring manual intervention from security teams. The system autonomously monitors network traffic, resolves target information to application identifiers, and provides intelligence about unknown applications.
Solution Approach 2:
The patent replaces manual mechanical processes with automated electronic systems. Instead of security teams manually analyzing network traffic and identifying applications, the system uses automated scanning of recorded events, electronic resolution techniques, and computer-based identification processes to detect unknown applications.
Data Source
AI summary
Detection of unknown applications is disclosed, including: detecting an event associated with accessing an application; determining target information associated with the event; and identifying the application from the target information.


