Agentless UEBA Risk Scoring via HR Data Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing User Entity Behavioral Analytics (UEBA) systems struggle to efficiently detect anomalous behavior and score risks for high-profile users, as they are event-driven and require high computing overhead, and do not effectively account for risks associated with high-profile users or integrate with human resources data.
Innovation Solution
A computing system that receives user activity data from an agentless monitoring source, identifies anomalous activity, and cross-references user identifiers with active directory and human resources data to determine the probability of adverse events, activating a monitoring agent and generating interactive notifications when thresholds are exceeded.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If UEBA systems use event-driven architecture to capture and process user activity data in real-time, then anomaly detection capability is improved, but computing system overhead increases significantly
Solution Approach 1:
The system performs preliminary actions by pre-processing user activity data and pre-calculating baseline behaviors before actual monitoring. User activity data is collected and stored in advance, allowing the system to establish behavioral baselines without requiring intensive real-time computation during anomaly detection events.
Solution Approach 2:
The patent introduces an intermediary layer between data collection and analysis by using a data lake as a intermediate storage repository. This data lake accumulates raw user activity data from multiple sources, allowing batch processing and pre-computation of behavioral patterns, thereby reducing the computing burden on real-time analysis systems.
2Measurement precision
If UEBA systems integrate multiple facets of user data (identification data, credentials, job role data) from separate systems, then insight into user behavior is improved, but system complexity and data integration overhead increase
Solution Approach 1:
The system merges multiple previously siloed data sources including user identification data, account credentials, and job role data into a unified data structure. This consolidation allows comprehensive user behavior analysis without requiring complex point-to-point integrations between separate systems, as all data types are accessed through a common interface.
Solution Approach 2:
The patent creates a universal data model that handles multiple types of user data (identification, credentials, job roles, activity logs) through a single integrated framework. This multi-functional approach allows the system to process diverse data types uniformly, reducing integration complexity while maintaining comprehensive user behavior insights.
3Measurement precision
If UEBA systems deploy key-logger applications on monitored user devices across the organization, then user activity monitoring capability is improved, but deployment and maintenance overhead increases
Solution Approach 1:
The system extracts the monitoring capability from device-specific key-logger applications and relocates it to a centralized server-based architecture. User activity data is collected through existing system logs and event streams, eliminating the need to deploy and maintain separate monitoring agents on each user device while preserving comprehensive monitoring capability.
Solution Approach 2:
The patent enables the monitoring system to self-serve by utilizing existing infrastructure and data sources within the organization. The system leverages already-collected user activity data from standard system logs, authentication services, and application event streams, eliminating the need for additional software deployment on monitored devices.
4Speed
If UEBA systems process streams of event-related data from various devices contemporaneously with user activity, then real-time detection capability is improved, but computing resource consumption increases
Solution Approach 1:
The system implements periodic action by processing user activity data in scheduled batches rather than continuously in real-time. User activity data is collected over time intervals and processed periodically to identify anomalies, reducing peak computing resource consumption while maintaining effective detection capability through time-delayed analysis.
Data Source
AI summary
A computing system comprising a processing circuit is configured to receive, via a data channel from an agentless monitoring data source, user activity data associated with a first computing device of a first user, determine a policy violation based on the user activity data, compare employee-related information associated with the first user to a threshold, determine a baseline level of risk based on the employee-related information exceeding the threshold, determine a user score based on at least one of a threat dimension or an exposure dimension or an impact dimension, determine a probability of an adverse event based on the determined baseline level of risk and the user score, generate a user-interactive electronic notification comprising an indication of the probability of the adverse event, and transmit the user-interactive electronic notification to a second computing device of a second user.


