Real-time User Awareness for Network Security Attribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network intrusion detection and prevention systems fail to accurately identify individual users responsible for security issues, as they do not provide real-time awareness of user activities and often misattribute security problems due to incorrect tracking of user assignments and login/logout events.

Innovation Solution

A system and method for real-time user awareness (RUA) that correlates user names with IP addresses, attacks, configurations, and vulnerabilities by associating user names with IP addresses during login and tracking events in real-time, enabling accurate identification of users involved in security incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If administrators maintain a spreadsheet of computers assigned to users, then user assignment tracking is implemented, but the information becomes outdated when computers are shuffled between users without notification

Engineering Contradiction:
Improveuser assignment information accuracyVSAvoidtime to update spreadsheets
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system automatically receives login/logout events from network authentication sources and uses this feedback to continuously update the user-computer mapping information, eliminating the need for manual spreadsheet updates and ensuring real-time accuracy of user assignment data

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system automatically tracks and updates user assignments by monitoring authentication events without requiring administrator intervention, making the information maintenance process self-service and eliminating manual update efforts

Inventive Principle:
Principle #25Self-service

2Measurement precision

If eTelemetry software is used to match network traffic to logged-in users, then user identification capability is provided, but the system cannot track when users log out and cannot determine user responsibility for security problems

Engineering Contradiction:
Improveuser identification accuracyVSAvoiduser responsibility determination reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system merges data from multiple sources including login/logout events, network authentication sources, and intrusion detection/prevention systems into a unified user awareness profile, enabling both accurate user identification and reliable determination of user responsibility for security incidents

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system continuously receives feedback from authentication events and security incident data to update and refine user awareness information, ensuring both accurate user identification and reliable attribution of security problems to the correct users

Inventive Principle:
Principle #23Feedback

3Measurement precision

If real-time user awareness is implemented by correlating multiple data sources, then accurate user identification for security incidents is achieved, but system complexity increases

Engineering Contradiction:
Improveuser identification accuracyVSAvoiddata correlation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary user awareness system that acts as a mediator between multiple data sources (authentication systems, intrusion detection systems, network traffic analyzers) and security administrators, correlating data from these sources to provide accurate user identification while managing system complexity through a centralized coordination layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2156290B1Real-time awareness for a computer network
Publication Date: 2020.03.25 CISCO TECHNOLOGY INC
  • EP2156290B1 patent drawingFigure 1
  • EP2156290B1 patent drawingFigure 2
  • EP2156290B1 patent drawingFigure 3~5

AI summary

A computer system, device, computer software, and/or method performed by a computer system, is provided for determining a user name likely to be associated with an attack, a configuration, or a vulnerability. First data is obtained which associates user names with individual IP addresses onto which the user names were logged in. Second data is obtained which associates attacks, configurations, or vulnerabilities with individual IP addresses on which the attacks occurred or on which the configurations or vulnerabilities exist. The user names from the first data are associated with the attacks, configurations or vulnerabilities from the second data based on having the same IP address during a log-in. An individual user name is indicated as being associated with attacks which occurred while the individual user name was logged in or with configurations or vulnerabilities for an IP address onto which the user logs in.