Managed Session Monitoring Using Context-Aware ML Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity techniques struggle to dynamically monitor session activity in real-time or recorded data, often requiring manual monitoring and static rules that fail to account for context, leading to high false positive alerts and difficulty in detecting malicious activity.
Innovation Solution
Utilizing machine learning models, particularly large language models, to analyze session data and context data for identifying potential security threats by dynamically reviewing managed sessions, incorporating historical and synthetic data to improve detection accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual monitoring of sessions is implemented, then security detection capability is improved, but labor cost and time consumption increase significantly
Solution Approach 1:
The patent replaces manual mechanical monitoring with an automated machine learning system that uses large language models to analyze session data. The system automatically processes session recordings, extracts relevant information, and generates security alerts without human intervention, thereby maintaining high detection capability while eliminating time consumption associated with manual monitoring.
Solution Approach 2:
The system implements self-service through autonomous automated monitoring that continuously analyzes session data without requiring human operators. The machine learning models independently process sessions, identify security risks, and generate alerts, enabling the system to serve itself in detecting security threats without external human assistance.
2Ease of manufacture
If hard coded rules are used for monitoring, then implementation simplicity is improved, but detection accuracy deteriorates due to high false positive rates
Solution Approach 1:
The patent transforms the monitoring approach from static hard-coded rules to dynamic machine learning models that adapt parameters based on learned patterns. The large language models process session data with flexible parameters that adjust based on context, enabling accurate detection while maintaining implementation simplicity through automated model processing rather than manual rule configuration.
Solution Approach 2:
The system replaces rigid mechanical rule-based monitoring with intelligent machine learning-based monitoring. The large language models automatically analyze session data, understand context, and identify security risks without relying on pre-defined hard-coded rules, thereby improving detection accuracy while keeping the system simple to implement through automated learning.
3Device complexity
If static security rules are implemented, then system complexity is reduced, but adaptability to new threats deteriorates
Solution Approach 1:
The patent implements dynamic monitoring using machine learning models that continuously learn and adapt to new threat patterns. The large language models process session data dynamically, adjusting their analysis based on learned behaviors and emerging security risks, thereby maintaining low system complexity while achieving high adaptability to new threats through automated learning rather than manual rule updates.
Solution Approach 2:
The system replaces static mechanical rule-based security monitoring with dynamic machine learning-based monitoring. The large language models automatically adapt to new threats by learning from processed session data, eliminating the need for complex manual rule updates while maintaining simplicity in system operation and achieving continuous adaptability to evolving security risks.
4Measurement precision
If context data is incorporated into analysis, then detection accuracy is improved, but data processing complexity increases
Solution Approach 1:
The patent replaces complex manual context analysis with automated machine learning processing. The large language models automatically ingest and analyze multiple data sources including session data, user profiles, device information, and network context, thereby improving detection accuracy through comprehensive context utilization while keeping data processing complexity manageable through automated model processing.
Solution Approach 2:
The system implements a universal machine learning framework that handles multiple data types and analysis functions through a single large language model architecture. This multi-functional approach consolidates diverse data processing tasks into one unified system, improving detection accuracy through comprehensive context analysis while avoiding the complexity of multiple separate processing systems.
Data Source
AI summary
Disclosed embodiments relate to systems and methods for dynamically reviewing managed session activity using machine learning models. Techniques include identifying a managed session between a network identity and a target resource; performing a reviewal process for the managed session, including identifying session data associated with the managed session; providing the session data and a context data as an input to at least one machine learning model; obtaining an output from the at least one machine learning model based on an analysis of the session data and the context data; and determining, based on the output, whether to perform a security action associated with the managed session.


