Intermediary Server for SaaS User Action Auditing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging for IT administrators to properly audit changes in Software as a Service (SaaS) applications due to varying auditing capabilities across different apps, and users face difficulties in understanding how to perform actions within or across these applications, especially in unfamiliar systems, which can lead to security risks.

Innovation Solution

A system that collects and analyzes user action data across multiple Web/SaaS applications to determine patterns, allowing for appropriate actions such as blocking unauthorized access or guiding users through optimal task flows, independently of the individual apps' auditing capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a system collects and analyzes user action data across multiple Web/SaaS applications to detect patterns and determine actions, then auditing capability and security are improved, but device complexity increases

Engineering Contradiction:
Improveauditing capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary component that collects user action data from multiple Web/SaaS applications, generates data structures, detects patterns, and determines actions. This intermediary server consolidates the auditing functionality, allowing individual applications to maintain their existing auditing capabilities while the server provides centralized analysis and coordination across applications, thus improving overall auditing capability without requiring each application to become more complex

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server performs multiple functions including collecting user action data, generating data structures, detecting patterns, determining actions, and coordinating with applications. By consolidating these diverse functions into a single multi-functional system, the patent improves auditing capability across multiple applications while avoiding the need to increase complexity in each individual application component

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the system generates a data structure separately from the different Web applications based on received user action data, then adaptability across different applications is improved, but device complexity increases

Engineering Contradiction:
Improvecross-application adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent separates the auditing and analysis functionality into a distinct server component that operates independently from the Web/SaaS applications. The server generates data structures separately from the applications based on collected user action data, allowing the system to adapt to different applications without modifying their internal structures. This segmentation enables cross-application adaptability while containing complexity in the dedicated server component

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The server acts as an intermediary that receives user action data from various applications, processes it into standardized data structures, and uses these structures to detect patterns and determine actions. This intermediary approach allows the system to adapt to multiple different applications through a universal data structure format without requiring each application to implement complex auditing logic, thus improving adaptability while managing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system detects patterns of user actions and determines actions such as blocking access or generating alerts, then security is improved, but loss of time in processing and responding increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The server continuously collects user action data and generates data structures in advance, maintaining updated records of user behaviors and patterns. By having this data preparation work done preliminarily and continuously, the system can quickly detect patterns and determine security actions when needed, improving security response time while distributing the processing load over time rather than concentrating it all at once

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11586685B2Systems and methods for generating data structures from browser data to determine and initiate actions based thereon
Publication Date: 2023.02.21 CITRIX SYSTEMS INC
  • US11586685B2 patent drawing
  • US11586685B2 patent drawing
  • US11586685B2 patent drawing

AI summary

A computing device may include a memory and a processor configured to cooperate with the memory to receive data from browsers of client devices configured to remotely access different Web applications through the browsers, with the data being indicative of user actions performed within the different Web applications. The processor may also be configured to cooperate with the memory to generate a data structure separately from the different Web applications based upon the received data, determine an action to perform based upon the data structure, and perform the determined action.