Adaptive Baseline Behavior Model for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional information security measures in network data environments focus solely on access control, neglecting the method, frequency, and timing of information access, and fail to account for aggregate group behavior, leading to security breaches due to undetected changes in user behavior.
Innovation Solution
An auto-adaptive baseline behavior model is generated to profile individual and collective behavior in a network data environment, monitoring activities, updating behavior variables, and issuing alerts when threshold conditions are met, allowing personnel to redefine conditions or have the model automatically adjust.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional access control mechanisms are used to determine what information users can access, then authorization is established, but the method, frequency, and timing of information access are not monitored
Solution Approach 1:
The system performs preliminary actions by establishing baseline behavior models for users before monitoring begins. These models capture normal access patterns including method, frequency, and timing. When monitoring starts, deviations from these pre-established baselines are automatically detected, enabling proactive security responses rather than reactive ones.
Solution Approach 2:
The monitoring system performs self-service by automatically learning and adapting to user behavior patterns without requiring manual configuration. The baseline models are dynamically updated based on observed behavior, and the system autonomously identifies anomalies when access patterns deviate from established norms, reducing the need for manual security rule maintenance.
2Reliability
If access control focuses on individual member activities, then individual authorization is enforced, but aggregate group behavior is not monitored
Solution Approach 1:
The system merges individual behavior monitoring with collective behavior analysis. Baseline models are created at both individual user levels and group levels, allowing the system to detect anomalies in individual behavior as well as unusual aggregate patterns. This dual-level approach enables detection of both insider threats and coordinated attacks that affect multiple users.
Solution Approach 2:
The behavior modeling system serves multiple functions simultaneously: it monitors individual user access patterns, tracks group aggregate behavior, establishes baselines for comparison, and detects anomalies at both individual and collective levels. This multi-functional approach maximizes security detection capability while using a unified modeling framework.
3Adaptability or versatility
If fixed threshold conditions are used in baseline models, then simple alert generation is achieved, but the system cannot adapt to changing behavior patterns
Solution Approach 1:
The system implements dynamics by making threshold values adaptive rather than fixed. Baseline models continuously learn from observed behavior patterns and automatically adjust thresholds to reflect changing normal behavior. This allows the system to adapt to legitimate behavior changes (such as users adopting new workflows) while maintaining sensitivity to actual security threats.
Solution Approach 2:
The system employs feedback mechanisms where alert responses are fed back into the baseline models. When alerts are generated and investigated, the outcomes are used to refine and update the baseline behavior patterns and threshold settings. This closed-loop feedback enables continuous improvement of detection accuracy and adaptation to evolving behavior patterns.
Data Source
AI summary
A method for generating an auto-adaptive baseline model for profiling individual and collective behavior of a plurality of network users. The method comprises the steps of creating a model, defining a plurality of members and a plurality of collective variables, each member corresponding to a user, and including a plurality of individual variables, defining conditions for each collective variable and individual variable, upon detecting an activity by a user, updating corresponding individual variables and collective variables, and comparing updated individual variables and collective variables against corresponding conditions. If a condition is met, an alert event is issued to notify designated personnel; otherwise, returning to the step of upon detecting activity. Finally, upon receiving an alert event, the designated personnel decides whether to manually redefine the conditions or to ignore the alert event. If the alert event is ignored, said conditions are automatically redefined in accordance with system defined mechanisms.


