Endpoint Agent Context Change Data Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing insider threat management systems face challenges in efficiently transmitting and processing large amounts of data from network endpoint devices to central servers, leading to high infrastructure costs, bandwidth issues, and potential delays in identifying insider threats.

Innovation Solution

Implementing a method where data transmissions from endpoint devices to a remote network destination are conditioned based on changes in user context, with only data sets from the beginning and end of each context change being transmitted, reducing unnecessary data transfer and maintaining system effectiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all user activity data is transmitted from endpoint devices to the central server, then the system can maintain high reliability in identifying insider threats, but the data transmission volume and infrastructure costs increase significantly

Engineering Contradiction:
Improveinsider threat identification effectivenessVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and transmits only the essential data elements needed for insider threat detection (beginning and end states of user context) while filtering out redundant intermediate data. This selective extraction maintains detection reliability while dramatically reducing transmission volume by approximately 70%.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of transmitting continuous streams of user activity data, the system creates representative copies or snapshots of the user context at critical transition points (context changes). These copied state representations preserve the essential information needed for threat analysis while minimizing data transfer requirements.

Inventive Principle:
Principle #26Copying

2Quantity of substance

If data transmission is reduced by filtering out intermediate user activity data, then infrastructure costs and bandwidth usage decrease, but there is a risk of losing critical threat detection information

Engineering Contradiction:
Improvedata transmission volumeVSAvoidthreat detection information
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The system performs preliminary analysis at the endpoint device to identify when user context changes occur before transmission. By detecting context change events locally and transmitting only the data surrounding these events (beginning and end states), the system ensures critical threat information is captured while avoiding unnecessary transmission of redundant intermediate states.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the endpoint agent continuously monitors user activity and compares it against previously transmitted context states. When changes are detected, the system triggers selective transmission of updated context information, ensuring the server receives timely updates on threat-relevant changes while maintaining efficient bandwidth utilization.

Inventive Principle:
Principle #23Feedback

3Loss of information

If continuous monitoring and transmission of all user activities is implemented, then complete visibility into user behavior is achieved, but the complexity of the system infrastructure and processing requirements increase

Engineering Contradiction:
Improveuser behavior visibilityVSAvoidsystem infrastructure complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the continuous user activity monitoring into discrete context states and identifies transition points between states. By dividing the monitoring task into segments (initial state, context changes, final state) rather than continuous monitoring, the system reduces infrastructure complexity while maintaining visibility into behavior changes that may indicate insider threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The endpoint device performs self-service by autonomously monitoring its own user activity, detecting context changes, and determining what data needs to be transmitted. This local intelligence reduces the processing burden on central servers and simplifies the overall system architecture by distributing the monitoring and filtering functions to the endpoints themselves.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11811894B2Reduction of data transmissions based on end-user context
Publication Date: 2023.11.07 GOLDMAN SACHS BANK USA
  • US11811894B2 patent drawing
  • US11811894B2 patent drawing
  • US11811894B2 patent drawing

AI summary

A computer-based method of reducing or limiting data transmissions from a computer to a remote network destination includes receiving an indication, at an agent on a computer, that a recent user activity has occurred at the computer. The indication typically includes data relevant to user context when the user activity occurred. The method further includes determining, with the agent, whether the data relevant to the user's context when the user activity occurred indicates that a change in user context relative to a user activity at the computer immediately prior to the recent user activity and conditioning a transmission of data relevant to the recent user activity from the computer to a remote network destination based on an outcome of the determination.