Security Event Association Rule Refresh for Ambiguous User Mappings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security awareness training methods lack context and timeliness, leading to ineffective cybersecurity threat association with users, resulting in ambiguous rule mappings that hinder targeted security training and actions.

Innovation Solution

The system implements a method for refreshing security event association rules by identifying and addressing ambiguous rule matches, updating rule lists, and triggering new rule executions based on user metadata changes, ensuring unambiguous user-event mappings for targeted training and security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security event association rules are executed against user records to match security events with users, then user-security event mapping is achieved, but ambiguous rule mappings occur when rules identify multiple different users, reducing mapping accuracy

Engineering Contradiction:
Improvemapping accuracyVSAvoidrule mapping reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system calculates an ambiguity score for each rule based on the number of users it identifies and feeds this information back to the user interface. This feedback mechanism allows administrators to see which rules are causing ambiguous mappings and take corrective action, thereby improving overall mapping accuracy while maintaining the reliability of the rule execution process.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual rule management and ambiguity detection with an automated system that executes rules, calculates ambiguity scores, and presents ranked lists of ambiguous rules to administrators. This substitution of manual processes with automated computational methods improves both the precision of mapping and the reliability of rule execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If comprehensive rule lists are maintained for security event association, then complete user-event mapping coverage is achieved, but system complexity increases due to multiple rules and thresholds

Engineering Contradiction:
Improvemapping coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary layer between the rule execution engine and the user interface, which calculates ambiguity scores and manages the presentation of rules. This intermediary simplifies the user experience by filtering and ranking ambiguous rules, thereby reducing the perceived complexity while maintaining comprehensive mapping coverage through the underlying extensive rule list.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If real-time rule execution is performed against user metadata changes, then timely security training delivery is achieved, but processing time and computational resources increase

Engineering Contradiction:
Improvetraining delivery speedVSAvoidprocessing time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining a pre-configured list of security event association rules and their thresholds. When user metadata changes occur, the system can quickly execute relevant rules without needing to recreate or reanalyze the entire rule set, thereby achieving real-time training delivery while minimizing processing time through pre-prepared rule structures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240267391A1Systems and methods for security event association rule refresh
Publication Date: 2024.08.08 KNOWBE4 INC
  • US20240267391A1 patent drawing
  • US20240267391A1 patent drawing
  • US20240267391A1 patent drawing

AI summary

Systems and methods are described for security event association rule refresh. One or more rules are executed against one or more user records in a user metadata store. The one or more rules may be configured to match a security event of one or more security events with a user of one or more users using user metadata. A count is determined of a number of times a rule of the one or more rules identifies a plurality of different users. It is further determined that one of the count exceeds a first threshold or a number of the plurality of different users exceeds a second threshold. Responsive to the determination, the rule via a user interface may display a prompt to take an action to one or more of review, remove or modify the rule by a system administrator.