Endpoint Agent Context Change Data Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing insider threat management systems face challenges in efficiently transmitting and processing large amounts of data from network endpoint devices to central servers, leading to high infrastructure costs, bandwidth issues, and potential delays in identifying insider threats.
Innovation Solution
Implementing a method where data transmissions from endpoint devices to a remote network destination are conditioned based on changes in user context, with only data sets from the beginning and end of each context change being transmitted, reducing unnecessary data transfer and maintaining system effectiveness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all user activity data is transmitted from endpoint devices to the central server, then the system can maintain high reliability in identifying insider threats, but the data transmission volume and infrastructure costs increase significantly
Solution Approach 1:
The patent extracts and transmits only the essential data elements needed for insider threat detection (beginning and end states of user context) while filtering out redundant intermediate data. This selective extraction maintains detection reliability while dramatically reducing transmission volume by approximately 70%.
Solution Approach 2:
Instead of transmitting continuous streams of user activity data, the system creates representative copies or snapshots of the user context at critical transition points (context changes). These copied state representations preserve the essential information needed for threat analysis while minimizing data transfer requirements.
2Quantity of substance
If data transmission is reduced by filtering out intermediate user activity data, then infrastructure costs and bandwidth usage decrease, but there is a risk of losing critical threat detection information
Solution Approach 1:
The system performs preliminary analysis at the endpoint device to identify when user context changes occur before transmission. By detecting context change events locally and transmitting only the data surrounding these events (beginning and end states), the system ensures critical threat information is captured while avoiding unnecessary transmission of redundant intermediate states.
Solution Approach 2:
The system implements a feedback mechanism where the endpoint agent continuously monitors user activity and compares it against previously transmitted context states. When changes are detected, the system triggers selective transmission of updated context information, ensuring the server receives timely updates on threat-relevant changes while maintaining efficient bandwidth utilization.
3Loss of information
If continuous monitoring and transmission of all user activities is implemented, then complete visibility into user behavior is achieved, but the complexity of the system infrastructure and processing requirements increase
Solution Approach 1:
The patent segments the continuous user activity monitoring into discrete context states and identifies transition points between states. By dividing the monitoring task into segments (initial state, context changes, final state) rather than continuous monitoring, the system reduces infrastructure complexity while maintaining visibility into behavior changes that may indicate insider threats.
Solution Approach 2:
The endpoint device performs self-service by autonomously monitoring its own user activity, detecting context changes, and determining what data needs to be transmitted. This local intelligence reduces the processing burden on central servers and simplifies the overall system architecture by distributing the monitoring and filtering functions to the endpoints themselves.
Data Source
AI summary
A computer-based method of reducing or limiting data transmissions from a computer to a remote network destination includes receiving an indication, at an agent on a computer, that a recent user activity has occurred at the computer. The indication typically includes data relevant to user context when the user activity occurred. The method further includes determining, with the agent, whether the data relevant to the user's context when the user activity occurred indicates that a change in user context relative to a user activity at the computer immediately prior to the recent user activity and conditioning a transmission of data relevant to the recent user activity from the computer to a remote network destination based on an outcome of the determination.


