Managed Session Monitoring Using Context-Aware ML Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity techniques struggle to dynamically monitor session activity in real-time or recorded data, often requiring manual monitoring and static rules that fail to account for context, leading to high false positive alerts and difficulty in detecting malicious activity.

Innovation Solution

Utilizing machine learning models, particularly large language models, to analyze session data and context data for identifying potential security threats by dynamically reviewing managed sessions, incorporating historical and synthetic data to improve detection accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual monitoring of sessions is implemented, then security detection capability is improved, but labor cost and time consumption increase significantly

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical monitoring with an automated machine learning system that uses large language models to analyze session data. The system automatically processes session recordings, extracts relevant information, and generates security alerts without human intervention, thereby maintaining high detection capability while eliminating time consumption associated with manual monitoring.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements self-service through autonomous automated monitoring that continuously analyzes session data without requiring human operators. The machine learning models independently process sessions, identify security risks, and generate alerts, enabling the system to serve itself in detecting security threats without external human assistance.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If hard coded rules are used for monitoring, then implementation simplicity is improved, but detection accuracy deteriorates due to high false positive rates

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent transforms the monitoring approach from static hard-coded rules to dynamic machine learning models that adapt parameters based on learned patterns. The large language models process session data with flexible parameters that adjust based on context, enabling accurate detection while maintaining implementation simplicity through automated model processing rather than manual rule configuration.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system replaces rigid mechanical rule-based monitoring with intelligent machine learning-based monitoring. The large language models automatically analyze session data, understand context, and identify security risks without relying on pre-defined hard-coded rules, thereby improving detection accuracy while keeping the system simple to implement through automated learning.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If static security rules are implemented, then system complexity is reduced, but adaptability to new threats deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidadaptability to new threats
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic monitoring using machine learning models that continuously learn and adapt to new threat patterns. The large language models process session data dynamically, adjusting their analysis based on learned behaviors and emerging security risks, thereby maintaining low system complexity while achieving high adaptability to new threats through automated learning rather than manual rule updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system replaces static mechanical rule-based security monitoring with dynamic machine learning-based monitoring. The large language models automatically adapt to new threats by learning from processed session data, eliminating the need for complex manual rule updates while maintaining simplicity in system operation and achieving continuous adaptability to evolving security risks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If context data is incorporated into analysis, then detection accuracy is improved, but data processing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces complex manual context analysis with automated machine learning processing. The large language models automatically ingest and analyze multiple data sources including session data, user profiles, device information, and network context, thereby improving detection accuracy through comprehensive context utilization while keeping data processing complexity manageable through automated model processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements a universal machine learning framework that handles multiple data types and analysis functions through a single large language model architecture. This multi-functional approach consolidates diverse data processing tasks into one unified system, improving detection accuracy through comprehensive context analysis while avoiding the complexity of multiple separate processing systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250371135A1Agile network session monitoring and enforcement
Publication Date: 2025.12.04 CYBER ARK SOFTWARE LTD
  • US20250371135A1 patent drawing
  • US20250371135A1 patent drawing
  • US20250371135A1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for dynamically reviewing managed session activity using machine learning models. Techniques include identifying a managed session between a network identity and a target resource; performing a reviewal process for the managed session, including identifying session data associated with the managed session; providing the session data and a context data as an input to at least one machine learning model; obtaining an output from the at least one machine learning model based on an analysis of the session data and the context data; and determining, based on the output, whether to perform a security action associated with the managed session.