Adaptive Baseline Behavior Model for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information security measures in network data environments focus solely on access control, neglecting the method, frequency, and timing of information access, and fail to account for aggregate group behavior, leading to security breaches due to undetected changes in user behavior.

Innovation Solution

An auto-adaptive baseline behavior model is generated to profile individual and collective behavior in a network data environment, monitoring activities, updating behavior variables, and issuing alerts when threshold conditions are met, allowing personnel to redefine conditions or have the model automatically adjust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional access control mechanisms are used to determine what information users can access, then authorization is established, but the method, frequency, and timing of information access are not monitored

Engineering Contradiction:
Improveinformation securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing baseline behavior models for users before monitoring begins. These models capture normal access patterns including method, frequency, and timing. When monitoring starts, deviations from these pre-established baselines are automatically detected, enabling proactive security responses rather than reactive ones.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system performs self-service by automatically learning and adapting to user behavior patterns without requiring manual configuration. The baseline models are dynamically updated based on observed behavior, and the system autonomously identifies anomalies when access patterns deviate from established norms, reducing the need for manual security rule maintenance.

Inventive Principle:
Principle #25Self-service

2Reliability

If access control focuses on individual member activities, then individual authorization is enforced, but aggregate group behavior is not monitored

Engineering Contradiction:
Improvedetection of security breachesVSAvoidbehavior modeling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges individual behavior monitoring with collective behavior analysis. Baseline models are created at both individual user levels and group levels, allowing the system to detect anomalies in individual behavior as well as unusual aggregate patterns. This dual-level approach enables detection of both insider threats and coordinated attacks that affect multiple users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The behavior modeling system serves multiple functions simultaneously: it monitors individual user access patterns, tracks group aggregate behavior, establishes baselines for comparison, and detects anomalies at both individual and collective levels. This multi-functional approach maximizes security detection capability while using a unified modeling framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If fixed threshold conditions are used in baseline models, then simple alert generation is achieved, but the system cannot adapt to changing behavior patterns

Engineering Contradiction:
Improveadaptation to behavior changesVSAvoidautomatic threshold adjustment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamics by making threshold values adaptive rather than fixed. Baseline models continuously learn from observed behavior patterns and automatically adjust thresholds to reflect changing normal behavior. This allows the system to adapt to legitimate behavior changes (such as users adopting new workflows) while maintaining sensitivity to actual security threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs feedback mechanisms where alert responses are fed back into the baseline models. When alerts are generated and investigated, the outcomes are used to refine and update the baseline behavior patterns and threshold settings. This closed-loop feedback enables continuous improvement of detection accuracy and adaptation to evolving behavior patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8606913B2Method for adaptively building a baseline behavior model
Publication Date: 2013.12.10 DATIPHY
  • US8606913B2 patent drawing
  • US8606913B2 patent drawing
  • US8606913B2 patent drawing

AI summary

A method for generating an auto-adaptive baseline model for profiling individual and collective behavior of a plurality of network users. The method comprises the steps of creating a model, defining a plurality of members and a plurality of collective variables, each member corresponding to a user, and including a plurality of individual variables, defining conditions for each collective variable and individual variable, upon detecting an activity by a user, updating corresponding individual variables and collective variables, and comparing updated individual variables and collective variables against corresponding conditions. If a condition is met, an alert event is issued to notify designated personnel; otherwise, returning to the step of upon detecting activity. Finally, upon receiving an alert event, the designated personnel decides whether to manually redefine the conditions or to ignore the alert event. If the alert event is ignored, said conditions are automatically redefined in accordance with system defined mechanisms.