Cross-Platform IM Threat Detection Using User Risk Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security systems are insufficient in identifying and responding to evolving cyber threats, particularly those originating from instant messaging platforms, and human users can inadvertently cause further damage.

Innovation Solution

A cyber threat defense system that incorporates data from instant messaging platforms using machine-learning models to identify deviations from normal behavior, constructs user profiles, and executes autonomous responses to mitigate threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls and endpoint security methods are used, then basic network protection is provided, but the system cannot effectively identify evolving cyber threats such as Trojans, worms, and malicious actions

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical security tools (firewalls, endpoint security) with an AI-based behavioral analysis system. The system uses machine learning models to analyze user behavior patterns across multiple platforms, substituting rule-based mechanical security with intelligent, adaptive threat detection that can identify evolving threats without requiring constant rule updates.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a composite security approach by integrating data from multiple platforms (instant messaging, email, cloud services, endpoints) into a unified behavioral analysis framework. This composite system combines diverse data sources to form a comprehensive user profile, enabling more reliable threat detection than any single platform could achieve alone.

Inventive Principle:
Principle #40Composite materials

2Measurement precision

If comprehensive data collection from multiple platforms is implemented, then user behavior analysis accuracy improves, but system complexity and data processing requirements increase

Engineering Contradiction:
Improveuser behavior analysis accuracyVSAvoiddata collection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal data collection framework that uses standardized APIs and protocols to gather information from diverse platforms (instant messaging, email, cloud services, endpoints). This multi-functional approach allows the same behavioral analysis engine to process data from multiple sources uniformly, improving measurement precision without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer (the behavioral analysis platform) that sits between diverse data sources and the threat detection engine. This intermediary standardizes and normalizes data from multiple platforms into a common format, enabling accurate behavioral analysis while simplifying the integration complexity through a unified interface layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If AI classifiers are applied to analyze instant messaging data, then threat identification accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidthreat analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by continuously training and updating AI classifiers with historical data in the background, so that when actual threat analysis is needed, the models are already optimized and ready. User behavioral baselines are established in advance through continuous monitoring of normal activity patterns, enabling faster real-time threat detection without extensive processing during critical events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial action by applying AI classification selectively - not all instant messaging data is analyzed with full AI power. Instead, the system uses lightweight filtering for obvious cases and reserves intensive AI analysis for suspicious or high-risk messages, reducing overall processing time while maintaining high threat identification accuracy for critical cases.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12615290B2Cyber security for instant messaging across platforms
Publication Date: 2026.04.28 DARKTRACE HLDG LTD
  • US12615290B2 patent drawing
  • US12615290B2 patent drawing
  • US12615290B2 patent drawing

AI summary

A cyber threat defense system can incorporate data from an instant messaging platform with multiple other platforms in a client system to identify cyber threats across the client system. The system can have one or more instant messaging modules to collect instant messaging data from one or more network entities that utilizes one or more instant messaging platforms. A user specific profile module can identify a user of the client system associated with the user account based on a composite user profile constructed from user context data collected across multiple platforms of the client system. A risk profile module can associate the user with a user risk profile based on the composite user profile. The risk profile module can apply one or more artificial intelligence classifiers to the instant message based on the user risk profile. A cyber threat module is configured to identify whether the instant messaging data corresponds to a cyber threat partially based on the user risk profile. An autonomous response module can execute an autonomous response in response to the cyber threat factoring in the user risk profile.