Network Space Clustering for Group-Based Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures are unable to perform mitigation actions on groups of users potentially impacted by malicious entities in a network, instead focusing on individual users, which limits the effectiveness in addressing security breaches.

Innovation Solution

A system and method to generate a network space comprising a cluster of network locations corresponding to a subset of users based on risk levels, allowing simultaneous mitigation actions such as logging off users or recording sessions for multiple users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If current security measures apply mitigation actions to individual users at a time, then the system complexity remains manageable, but the productivity and effectiveness of security response are reduced

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges individual user security contexts into network-wide segments by creating network spaces that group multiple users together. This allows mitigation actions to be applied to groups of users simultaneously rather than individually, improving security response effectiveness while managing system complexity through hierarchical organization of users into segments.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the network into multiple network spaces based on user risk profiles and characteristics. Each network space can be independently managed and applied mitigation actions to specific segments, allowing efficient group-based security responses without overwhelming system complexity. The segmentation enables targeted mitigation while maintaining manageable system architecture.

Inventive Principle:
Principle #1Segmentation

2Loss of time

If mitigation actions are applied to groups of users simultaneously, then the productivity and response time improve, but the device complexity increases

Engineering Contradiction:
Improveresponse timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-segmenting users into network spaces based on risk profiles before security incidents occur. This pre-organization enables rapid response time during actual incidents, as mitigation actions can be applied to entire network spaces immediately without needing to individually identify and process each user, thus reducing response time while managing complexity through pre-established structures.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If individual user monitoring is performed, then the measurement precision of user risk is high, but the loss of time for security response increases

Engineering Contradiction:
Improveuser risk assessment accuracyVSAvoidsecurity response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent combines individual user risk assessments into aggregated network space risk profiles. By merging individual measurements into group-level assessments, the system maintains measurement precision for user risk while enabling parallel processing of multiple users, thus reducing security response time without sacrificing the accuracy of risk assessment.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12381888B2System and method for deriving network address spaces affected by security threats to apply mitigations
Publication Date: 2025.08.05 CITRIX SYSTEMS INC
  • US12381888B2 patent drawing
  • US12381888B2 patent drawing
  • US12381888B2 patent drawing

AI summary

Described embodiments provide systems and methods for generating a network space to perform mitigation actions on a plurality of users. At least one server may determine a plurality of users of one or more levels of riskiness in a network environment, and network locations of the users. Using a plurality of clustering features, the at least one server may generate a network space comprising a cluster of network locations corresponding to a subset of the users of at least a defined level of riskiness. The at least one server may perform a mitigation action on the subset of users corresponding to the generated network space.