Auto Smart Groups Trend Analytics for Adaptive Cybersecurity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems struggle to detect and mitigate new and unknown security threats involving social engineering, relying heavily on employee recognition, which is inefficient and prone to human error, while current security awareness training methods fail to identify organizational trends and vulnerabilities effectively.

Innovation Solution

A system and method for auto smart groups trend analytics that automatically generates and applies multiple criteria combinations to categorize user data into query-based groups, analyzing user count trends and statistical significance to identify potential cybersecurity threats and vulnerabilities, using a security awareness system to provide targeted training and risk scoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cybersecurity tools such as antivirus, anti-ransomware, and anti-phishing are used to detect known attacks, then detection capability for known threats is improved, but the system cannot detect new and unknown security threats involving social engineering

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by automatically generating multiple criteria combinations and query-based groups before security incidents occur. It analyzes user count trends and statistical significance in advance to establish baseline patterns of normal user behavior across different departments, roles, and time periods, enabling proactive detection of anomalies rather than reactive response to known threats

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements dynamics by continuously analyzing user count trends over time and automatically adjusting criteria combinations to identify changing patterns. It dynamically generates multiple query variations and updates statistical significance assessments as new data becomes available, allowing the system to adapt to evolving threat landscapes and organizational changes rather than relying on static detection rules

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If employees are relied upon to recognize social engineering threats through security awareness training, then adaptability to unknown threats is improved, but human error and inefficiency increase

Engineering Contradiction:
Improvethreat recognition capabilityVSAvoidthreat recognition accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback by automatically analyzing user count trends and statistical significance data to generate insights about potential security threats. It provides continuous feedback to security teams through automated reports and alerts, eliminating the need for manual analysis and reducing human error while maintaining high adaptability to new threat patterns

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by automatically generating multiple criteria combinations, executing queries across databases, analyzing user count trends, and determining statistical significance without human intervention. It autonomously identifies anomalies and generates security insights, replacing manual employee analysis with automated intelligent processing that eliminates human error while maintaining adaptability

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple criteria combinations are generated to categorize user data into query-based groups, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvetrend analysis precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies segmentation by dividing the user population into multiple query-based groups using different criteria combinations (e.g., by department, role, time period). It segments user count data into manageable groups that can be analyzed independently for statistical significance, improving detection precision while maintaining system manageability through structured organization of complex data

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universality by creating a multi-functional automated analysis platform that handles multiple criteria combinations, executes various types of queries, performs trend analysis, and determines statistical significance through a single integrated system. This universal approach manages complexity by consolidating multiple functions into one cohesive system rather than requiring separate tools for each analytical task

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12355789B2Auto smart groups trend analytics
Publication Date: 2025.07.08 KNOWBE4 INC
  • US12355789B2 patent drawing
  • US12355789B2 patent drawing
  • US12355789B2 patent drawing

AI summary

The systems and methods disclose creating variations of criteria for a query-based group of users. One or more criteria from a plurality of criteria available is selected to form a query to identify members of query-based group of users. Using the selected one or more criteria, query-based groups of users are generated. Each of the plurality of query-based groups of users may have a query with a variation of the selected one or more criteria. A user count data of user membership in each query-based group of the query-based groups of users is determined based at least on applying the query of each of the plurality of query-based groups of users to one or more databases. One or more of the plurality of query-based groups of users is identified as being validated for a statistical significance based at least on the user count data and the one or more criteria.