Enterprise Messaging Behavior Profiles for Suspicious Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise messaging systems face increased security threats due to users trusting messages from within their network, as unauthorized users can infiltrate with stolen credentials, posing greater risks than spam emails, as they appear authentic and can access sensitive information.

Innovation Solution

A security system builds behavior profiles for users based on their communication patterns, using machine learning to detect anomalies and implement preventative actions such as adversarial engagement models, multi-factor authentication, and access revocation to mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to communicate freely within the enterprise messaging system, then ease of operation and productivity are improved, but security reliability deteriorates as unauthorized users can infiltrate with stolen credentials

Engineering Contradiction:
Improvemessaging accessibilityVSAvoidsecurity trust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by building behavior profiles for users before security incidents occur. These profiles capture normal communication patterns, devices used, and interaction styles. When a security threat is detected, the system can quickly compare against pre-established profiles to identify anomalies, enabling rapid response while maintaining continuous messaging operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The behavior profile acts as an intermediary between the user and the security system. Instead of directly monitoring and blocking user communications, the system uses behavior profiles as a mediator to indirectly assess security risks. This intermediary layer allows messaging to flow freely while security verification occurs in the background through pattern matching.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system monitors user behavior to detect security threats, then security reliability is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically building and updating behavior profiles without requiring manual configuration or intervention. The profiles are generated from observed user communications and automatically maintained, reducing the complexity of security system management while improving detection reliability through continuous learning.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback mechanisms where detected security threats and blocked communications are fed back into the behavior profile system. This feedback loop continuously refines the profiles and improves detection accuracy over time, enhancing security reliability while the automated nature of the feedback process avoids adding manual complexity.

Inventive Principle:
Principle #23Feedback

3Reliability

If the system blocks suspicious messages to prevent security threats, then security reliability is improved, but loss of information increases as legitimate communications may be blocked

Engineering Contradiction:
Improvesecurity protectionVSAvoidlegitimate message delivery
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies partial action by not blocking all messages that deviate from normal patterns, but only those that exceed certain anomaly thresholds. This selective approach allows legitimate variations in user behavior to pass through while blocking only the most suspicious communications, balancing security protection with information flow.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary anti-action by proactively protecting against security threats through behavior analysis before blocking occurs. By establishing baseline behavior patterns and detecting deviations, the system can prevent malicious messages while maintaining normal communications, reducing the need for overly aggressive blocking that would lose legitimate information.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12395535B2Security techniques for enterprise messaging systems
Publication Date: 2025.08.19 SALESFORCE INC
  • US12395535B2 patent drawing
  • US12395535B2 patent drawing
  • US12395535B2 patent drawing

AI summary

The disclosed techniques identify and prevent suspicious activity occurring within a messaging software executed via an enterprise system. The disclosed techniques detect a current message sent from a particular user account of the messaging software executed via the enterprise system at a user device. The techniques compare the current message and user account activity associated with the current message with a behavior profile of the particular user account, where the behavior profile is generated based on prior user account activity that includes one or more prior messages sent from the user account via the enterprise system, and where the prior account activity occurs before the current message. Based on the comparing and predetermined risk levels, the disclosed techniques determine a risk level of the current message. Based on the determined risk level of the current message, the disclosed techniques perform preventative actions with respect to the particular user account.