User Behavior Scoring in Online Security Event Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise networks face cyber threats due to varying user behaviors and lack of adherence to security policies, leading to potential data breaches and malware infections, as users engage in risky online activities and ignore security protocols.

Innovation Solution

A system that collects and analyzes user behavior data from endpoints, applies machine learning to assess risk, and implements responsive actions based on predefined security policies, including training, warnings, and access controls to mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users are given access to the enterprise network and public networks, then productivity and business operations are enabled, but security risks increase due to cyber-attacks entering through user connections

Engineering Contradiction:
Improvebusiness operationsVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security management system that sits between users and the enterprise network resources. This system includes security agents on user devices, a security information and event management (SIEM) platform, and policy enforcement mechanisms that mediate all network access requests, allowing productive operations while filtering and controlling security risks through layered security policies and real-time monitoring

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the enterprise network access control into multiple independent components: user identity management, device compliance checking, network resource authorization, and real-time threat detection. Each segment operates independently but coordinates through the central security management platform, allowing granular control over different aspects of network access to maintain productivity while addressing specific security concerns

Inventive Principle:
Principle #1Segmentation

2Reliability

If security monitoring and control measures are implemented, then security risks are reduced, but user convenience and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service security mechanisms where the security management system automatically performs device compliance verification, policy enforcement, and threat response actions without requiring manual user intervention. The security agents on user devices automatically report status and receive enforcement decisions, while the central platform automatically adjusts access permissions based on real-time security assessments, reducing user burden while maintaining strong security controls

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically changes security parameters such as access permissions, monitoring intensity, and policy strictness based on real-time user behavior analysis, device security posture, and threat levels. The system adjusts these parameters automatically without user awareness or action, maintaining ease of operation while adapting security measures to current risk conditions

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive user behavior analysis is performed, then security threats are identified more accurately, but data processing requirements and system complexity increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex data processing task into distributed components: security agents on user devices collect and pre-process local behavior data, regional servers aggregate data from multiple users, and the central SIEM platform performs comprehensive analysis. This segmentation allows accurate threat detection through distributed processing while reducing the complexity burden on any single system component

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security management platform that handles multiple functions: user authentication, device compliance checking, network access control, threat detection, and incident response. By consolidating these functions into a single multi-functional system, the patent reduces overall system complexity compared to having separate specialized systems for each function, while maintaining high threat detection accuracy through integrated analysis

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12425427B2Method and system for online user security information event management
Publication Date: 2025.09.23 CELESTYA LTD
  • US12425427B2 patent drawing
  • US12425427B2 patent drawing
  • US12425427B2 patent drawing

AI summary

A method for providing an automated response to user behavior comprising: receiving, by a computer system, data of user actions taken on a computer of the user, the computer of the user in communication with the computer system; analyzing the received data against the knowledge level of the user as determined by the computer system, and/or, the user's responses to simulations generated by the computer system, to determine a score for the user; and, in response to the score, making a behavior recommendation for the user and/or making a decision to take an action associated with the computer of the user.