Network Security Attribution via Metadata Association Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in accurately attributing network events to specific users within an enterprise environment, especially when users employ proxy servers or when unique identifiers are not explicitly present in event data, making it difficult to assess and respond to potential security threats effectively.

Innovation Solution

A network security system that dynamically associates users with network and endpoint events by analyzing IP addresses, email addresses, device identifiers, and other metadata, using a combination of association rules and confidence values to determine user involvement, even in cases where proxy servers are used or identifiers are obfuscated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security systems use traditional attribution methods relying on explicit user identifiers, then user identification is straightforward, but users can circumvent security measures by using proxy servers or obfuscating identifiers

Engineering Contradiction:
Improveuser attribution accuracyVSAvoidability to detect obfuscated user identities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary attribution model that acts as a mediator between network events and user identities. Instead of directly linking events to users through explicit identifiers, the system uses an intermediary layer of metadata (device identifiers, network patterns, behavioral characteristics) to infer user identity, thereby detecting obfuscated or proxy-based users without requiring direct identifier exposure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameters used for user attribution from explicit identifiers (usernames, emails) to indirect parameters (device fingerprints, network behavior patterns, temporal-spatial metadata). This parameter transformation enables the system to attribute users even when traditional identifiers are obfuscated, proxies are used, or users intentionally conceal their identities

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If the system collects and analyzes detailed user information for accurate attribution, then user identification improves, but user privacy is compromised

Engineering Contradiction:
Improveuser identification precisionVSAvoiduser privacy intrusion
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary metadata and network event characteristics needed for attribution, separating this minimal data from comprehensive user profiles. By taking out only the essential features (device identifiers, network patterns, event metadata) rather than collecting full user information, the system achieves precise attribution while minimizing privacy intrusion

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of collecting actual user information directly, the system creates copies or representations of user activity through metadata and network event analysis. These copies capture user behavior patterns and identification features without containing personal identifiable information, enabling attribution while preserving user privacy

Inventive Principle:
Principle #26Copying

3Speed

If the system processes and analyzes network events in real-time, then security response speed improves, but computational resources and processing complexity increase

Engineering Contradiction:
Improvesecurity response speedVSAvoidevent processing complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the network event processing into distinct modules: event collection, metadata extraction, attribution analysis, and response generation. Each segment handles specific tasks independently, allowing real-time processing of individual events while distributing computational complexity across multiple processing stages rather than requiring monolithic complex analysis for every event

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12166774B2Network security systems for attributing network events to users
Publication Date: 2024.12.10 TARGET BRANDS INC
  • US12166774B2 patent drawing
  • US12166774B2 patent drawing
  • US12166774B2 patent drawing

AI summary

Disclosed are techniques for associating users of a network infrastructure to network or endpoint events within the network infrastructure. A method can include receiving, by a network security system that monitors and protects the network infrastructure, a packet for a network event, the packet including (i) information identifying a user device from which the network event originates and (ii) a payload, determining whether the packet triggers at least one association rule in a group of association rules, determining candidate users to be associated with the network event based on the rule triggered by the packet, determining confidence values for the candidate users to be associated with the network event based on the rule triggered by the packet, and returning the candidate users to associate with the network event and the corresponding confidence values.