User and Group Threat Protection Zones for Contextual Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems fail to detect personalized or business-specific threats due to limited analysis time, lack of user context, and insufficient depth in threat detection, particularly in browser-based and endpoint security measures, leading to missed detections and vulnerabilities.

Innovation Solution

A cloud-based threat analysis system with user identity integration provides personalized threat detection through continuous monitoring and analysis of browsing behavior, establishing protection zones based on user profiles, and performing deep inspection and threat intelligence aggregation to identify and mitigate threats before and during attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional endpoint security measures are used, then device protection is provided, but detection precision is insufficient due to limited analysis time and lack of user context

Engineering Contradiction:
Improvethreat detection precisionVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary threat intelligence aggregation and protection zone establishment before actual threats materialize. By continuously monitoring network destinations and establishing protection zones in advance, the system prepares threat detection frameworks beforehand, enabling faster and more precise detection when threats occur without consuming excessive analysis time during critical moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces protection zones as an intermediary layer between users and network destinations. These zones aggregate threat intelligence and contextual information, serving as a mediator that enhances detection precision by providing enriched context without requiring real-time analysis of every interaction, thus resolving the time-precision tradeoff.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If generic network security measures are applied, then broad coverage is achieved, but adaptability to personalized or business-specific threats is insufficient

Engineering Contradiction:
Improvepersonalized threat protectionVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system applies local quality by creating user-specific and business-specific protection zones tailored to individual needs. Each protection zone is customized based on user profiles, browsing behavior, and organizational context, providing localized threat protection that adapts to specific users or businesses rather than applying uniform generic security measures across all users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the network environment into distinct protection zones for different users, businesses, and network destinations. This segmentation allows each zone to be independently configured and optimized for specific threat profiles, enhancing adaptability to personalized threats while managing complexity through modular zone-based architecture.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If deep threat analysis is performed, then detection capability is improved, but productivity is reduced due to continuous monitoring requirements

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements periodic action by continuously monitoring network destinations and updating protection zones at scheduled intervals rather than performing exhaustive deep analysis on every user interaction. This periodic deep analysis approach maintains high detection capability through regular threat intelligence aggregation while preserving productivity by avoiding constant full-scale scanning of all network traffic.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies partial action by focusing deep analysis resources on specific protection zones and high-risk network destinations rather than uniformly analyzing all network traffic. By concentrating deep threat analysis where most needed based on risk assessment and user context, the system maintains high detection capability while improving overall processing efficiency through selective deep inspection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12413607B2User and group specific threat protection system and method
Publication Date: 2025.09.09 GEN DIGITAL INC
  • US12413607B2 patent drawing
  • US12413607B2 patent drawing
  • US12413607B2 patent drawing

AI summary

A method of managing access to a network destination. The method includes establishing a first network zone for a user, the first network zone including a plurality of network destinations. The first network zone is monitored and one or more changes in the first network zone are determined. A first network destination in the first network zone is analyzed responsive to determining the one or more changes in the first network zone to determine a first threat. An attempt by the user to access the first network destination is detected, and access by the user to the first network destination is restricted based on the determining the first threat.