Real-time User Awareness for Network Security Attribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network intrusion detection and prevention systems fail to accurately identify individual users responsible for security issues, as they do not provide real-time awareness of user activities and often misattribute security problems due to incorrect tracking of user assignments and login/logout events.
Innovation Solution
A system and method for real-time user awareness (RUA) that correlates user names with IP addresses, attacks, configurations, and vulnerabilities by associating user names with IP addresses during login and tracking events in real-time, enabling accurate identification of users involved in security incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If administrators maintain a spreadsheet of computers assigned to users, then user assignment tracking is implemented, but the information becomes outdated when computers are shuffled between users without notification
Solution Approach 1:
The system automatically receives login/logout events from network authentication sources and uses this feedback to continuously update the user-computer mapping information, eliminating the need for manual spreadsheet updates and ensuring real-time accuracy of user assignment data
Solution Approach 2:
The system automatically tracks and updates user assignments by monitoring authentication events without requiring administrator intervention, making the information maintenance process self-service and eliminating manual update efforts
2Measurement precision
If eTelemetry software is used to match network traffic to logged-in users, then user identification capability is provided, but the system cannot track when users log out and cannot determine user responsibility for security problems
Solution Approach 1:
The system merges data from multiple sources including login/logout events, network authentication sources, and intrusion detection/prevention systems into a unified user awareness profile, enabling both accurate user identification and reliable determination of user responsibility for security incidents
Solution Approach 2:
The system continuously receives feedback from authentication events and security incident data to update and refine user awareness information, ensuring both accurate user identification and reliable attribution of security problems to the correct users
3Measurement precision
If real-time user awareness is implemented by correlating multiple data sources, then accurate user identification for security incidents is achieved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary user awareness system that acts as a mediator between multiple data sources (authentication systems, intrusion detection systems, network traffic analyzers) and security administrators, correlating data from these sources to provide accurate user identification while managing system complexity through a centralized coordination layer
Data Source
Figure 1
Figure 2
Figure 3~5
AI summary
A computer system, device, computer software, and/or method performed by a computer system, is provided for determining a user name likely to be associated with an attack, a configuration, or a vulnerability. First data is obtained which associates user names with individual IP addresses onto which the user names were logged in. Second data is obtained which associates attacks, configurations, or vulnerabilities with individual IP addresses on which the attacks occurred or on which the configurations or vulnerabilities exist. The user names from the first data are associated with the attacks, configurations or vulnerabilities from the second data based on having the same IP address during a log-in. An individual user name is indicated as being associated with attacks which occurred while the individual user name was logged in or with configurations or vulnerabilities for an IP address onto which the user logs in.