AI Behavior Analysis for Insider Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional fraud and abuse detection systems, particularly those using neural networks, struggle with scalability and require high manual effort, often failing to detect new behaviors and evolving fraud methods due to their reliance on static models and limited adaptability, leading to suboptimal compliance and delayed detection.

Innovation Solution

An AI-powered behavior analysis system that monitors and profiles the specific job-related activities of system administrators, using smart-agents and case-based reasoning to identify unusual patterns and sequences of tasks, issuing security alerts and automating responses to potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional neural network models are used for fraud detection, then the system can process transactions, but the models lack adaptability to detect new fraud behaviors and require high manual effort for redevelopment

Engineering Contradiction:
Improveadaptability to new fraud behaviorsVSAvoidmanual effort for model redevelopment
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms static fraud detection models into dynamic systems that automatically adapt to new fraud patterns. The system continuously learns from transaction data and updates detection models without manual intervention, enabling real-time adaptation to evolving fraud behaviors while reducing operational complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements self-service capabilities through automated model training and deployment. The fraud detection system autonomously retrains models using new transaction data, performs hyperparameter optimization, and deploys updated models without requiring manual analyst intervention, thereby reducing manual effort while maintaining high adaptability

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If static fraud detection models are used, then the system structure is simple, but the system fails to detect evolving fraud methods and new behaviors

Engineering Contradiction:
Improvedetection of evolving fraud methodsVSAvoidcompliance detection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback loops where detection results, false positives, and new transaction patterns continuously feed back into model retraining processes. This closed-loop system automatically adjusts detection parameters and model structures based on performance metrics, maintaining high reliability while adapting to new fraud methods

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by pre-training models on historical fraud patterns and continuously preparing updated models in advance. This proactive approach ensures detection models are ready to identify emerging fraud methods before they become widespread, maintaining high compliance detection accuracy

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If individualized models are created for each system administrator, then detection precision improves, but system complexity and computational resources increase

Engineering Contradiction:
Improvebehavior anomaly detection precisionVSAvoidnumber of models to maintain
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal fraud detection framework that serves multiple system administrators simultaneously. A single adaptive model architecture processes behavior data from all administrators, automatically specializing detection for each user through learned patterns rather than requiring separate models, thereby maintaining high precision while reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments behavior analysis into modular components that can be independently processed. By dividing administrator behavior data into distinct feature sets and using ensemble methods, the system achieves individualized detection precision through coordinated simple models rather than requiring one complex model per administrator

Inventive Principle:
Principle #1Segmentation

4Speed

If real-time monitoring of system administrator behaviors is implemented, then insider threats are detected faster, but system resource consumption and processing time increase

Engineering Contradiction:
Improvedetection speed of suspicious activitiesVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent applies partial monitoring by focusing computational resources on high-risk behaviors and anomaly detection rather than analyzing all administrator actions equally. The system uses sampling strategies and selective deep analysis only for suspicious patterns, achieving fast real-time detection of threats while minimizing overall resource consumption through targeted rather than exhaustive monitoring

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9280661B2System administrator behavior analysis
Publication Date: 2016.03.08 BRIGHTERION INC
  • US9280661B2 patent drawing
  • US9280661B2 patent drawing
  • US9280661B2 patent drawing

AI summary

A network computer system is protected from malicious attacks by its own system administrators by a large number of addressable and assignable smart-agents that are individually allocated to independently follow and represent those system administrators, the jobs those system administrated are assigned to work on, and the system resource tasks that such system administrators can employ in furtherance of the completion of a particular job.