Automated Intelligence Gathering System for Insider Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in detecting insider threats as they require manual analysis of large datasets, which is time-consuming and often necessitates skilled investigators, limiting the ability to quickly identify and respond to data exfiltration by employees.

Innovation Solution

An intelligence gathering system comprising a forensic data source, investigation module, and report generation module, which collects and analyzes subject data using machine learning models to generate investigation reports, assisting investigators with automated data analysis and keyword searches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of large datasets is used to detect insider threats, then investigation accuracy can be maintained by skilled investigators, but investigation time increases significantly and scalability is limited

Engineering Contradiction:
Improveinvestigation accuracyVSAvoidinvestigation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an automated analysis system that acts as an intermediary between the forensic data source and the investigator. This system includes modules for automated data collection, analysis, and report generation, which process large datasets and present findings to investigators, thereby reducing investigation time while maintaining accuracy through automated detection algorithms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual analysis process with an automated computer-based system. The system uses software modules to automatically collect, analyze, and report on forensic data, substituting human manual effort with automated computational processes that can handle large datasets much faster while maintaining consistent analysis quality

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If skilled investigators conduct investigations manually, then investigation effectiveness is maximized, but the requirement for skilled investigators limits scalability and increases operational complexity

Engineering Contradiction:
Improveinvestigation effectivenessVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables the investigation system to serve itself by implementing automated data collection, analysis, and report generation capabilities. The system automatically processes forensic data without requiring constant human intervention, allowing less experienced investigators to effectively conduct investigations while maintaining consistent quality across multiple cases, thereby improving scalability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal investigation platform that can handle multiple types of forensic data and investigation scenarios through a single automated system. The system is designed to be adaptable to different investigation requirements while providing consistent automated analysis, allowing the same platform to serve multiple investigators and cases simultaneously, thereby enhancing scalability

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated analysis systems are implemented, then investigation speed and scalability improve, but the complexity of the system increases

Engineering Contradiction:
Improveinvestigation speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent divides the automated investigation system into distinct functional modules: data collection module, data analysis module, and report generation module. Each module performs a specific function and can be independently configured and maintained, reducing overall system complexity while enabling high-speed automated processing through specialized components working in sequence

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4261758A1Computer method and system for intelligence gathering
Publication Date: 2023.10.18 MAGNET FORENSICS INC
  • EP4261758A1 patent drawingFigure 1~2
  • EP4261758A1 patent drawingFigure 3~4
  • EP4261758A1 patent drawingFigure 5~6

AI summary

A system and associated method for intelligence gathering is provided. The system includes a forensic data source, an investigation module, and a report generation module. The investigation module is configured to collect subject data of a subject from the forensic data source and transmit subject data to the report generation module. The report generation module is configured to receive the subject data from the investigation module and analyze subject data to generate an investigation report output.