Heartbeat-Based User Identification for Enterprise Email Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in effectively securing endpoints against malicious activities, particularly in identifying and remediating potential threats within the network, as existing solutions often focus on network addresses rather than user-based identification.

Innovation Solution

Implementing a threat management facility that monitors electronic communications for indicators of malicious activity, allowing user-based inquiry to identify potential sources, and subsequently locates, analyzes, and remediates associated devices within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network address-based monitoring is used to identify malicious activity sources, then network traffic can be monitored, but the precision of identifying the actual user source is insufficient

Engineering Contradiction:
Improveidentification precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a heartbeat message mechanism as an intermediary between endpoints and the threat management facility. Each endpoint sends periodic heartbeat messages containing its identity information, creating a mapping between network addresses and actual users. This intermediary system enables precise user identification without requiring direct complex analysis of all network traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of endpoint identity information through heartbeat messages. Instead of directly tracking complex network traffic patterns to identify users, the system uses simplified heartbeat copies that contain essential identity data, making user identification more precise while reducing system complexity.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive monitoring of all network communications is implemented, then threat detection capability is improved, but the complexity of managing and analyzing the data increases

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential identity information from endpoint communications through the heartbeat message mechanism. Instead of monitoring and analyzing all network traffic data, the system extracts and tracks only the critical identity markers in periodic heartbeat messages, maintaining reliable threat detection while significantly reducing data management complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary action by collecting endpoint identity information in advance through periodic heartbeat messages. This pre-collection of identity data creates a ready-reference mapping before threats occur, enabling rapid and accurate identification of malicious activity sources without the need for complex real-time analysis of all communications.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If user-based identification is implemented instead of network address identification, then the ability to locate and remediate specific user devices is improved, but the complexity of tracking user devices increases

Engineering Contradiction:
Improvedevice location easeVSAvoidtracking system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The endpoint devices perform self-service by automatically sending periodic heartbeat messages containing their identity information to the threat management facility. This self-service mechanism eliminates the need for complex centralized tracking systems, as each endpoint autonomously provides its own identification data, making device location easier while keeping the tracking system simple.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses periodic heartbeat messages to maintain user-device mappings. Instead of continuous complex tracking, endpoints periodically send identity information at set intervals, creating an up-to-date reference system with minimal complexity. This periodic action ensures devices can be easily located when needed while avoiding the overhead of continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10868821B2Electronic mail security using a heartbeat
Publication Date: 2020.12.15 SOPHOS LTD
  • US10868821B2 patent drawing
  • US10868821B2 patent drawing
  • US10868821B2 patent drawing

AI summary

Electronic communications passing through a communication gateway or similar device for an enterprise can be monitored for indicators of malicious activity. When potentially malicious activity is identified, a user-based inquiry can be employed to identify potential sources of the malicious activity within the enterprise network. More specifically, by identifying a user that sourced the communication, instead of or in addition to a network address, devices within the enterprise network associated with the user can be located, analyzed, and remediated as appropriate.