Anomalous Activity Detection via Dynamic Security Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for monitoring and managing electronic confidential information lack the ability to effectively detect anomalous activity, often resulting in inefficient and inaccurate threat assessments due to inadequate consideration of individual user characteristics, network-specific requirements, and the burden of manual data analysis across multiple data feeds.
Innovation Solution
A system that consolidates and enriches electronic data from multiple sources, removes duplicates, and applies dynamic security policies based on user account groups, utilizing prior knowledge and analysis to enhance detection efficiency and accuracy, and provides a graphical interface for focused monitoring and escalation of threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple data feeds are monitored to detect threats, then detection coverage is improved, but analysis time and resource consumption increase
Solution Approach 1:
The patent consolidates multiple data feeds from different security applications into a single unified data structure. This merging process combines threat indicators, user behaviors, and security events into one integrated view, reducing the time required to analyze separate data sources while maintaining comprehensive detection coverage.
Solution Approach 2:
The system performs preliminary analysis and consolidation of data feeds before threat detection. By pre-processing and organizing data from multiple sources into standardized structures in advance, the system reduces the computational burden during actual threat analysis, thereby decreasing analysis time without compromising detection reliability.
2Productivity
If duplicate records are removed to improve analysis efficiency, then processing speed increases, but data completeness may be compromised
Solution Approach 1:
The system implements a feedback mechanism that tracks and learns from duplicate record patterns. By analyzing historical data to identify genuine duplicates versus unique events, the system can confidently remove true duplicates while preserving important data variations, thus improving efficiency without losing critical information.
Solution Approach 2:
The patent applies parameter-based filtering to distinguish duplicates from unique records. By changing and adjusting parameters such as time windows, event types, and user contexts, the system dynamically determines what constitutes a duplicate versus a meaningful separate event, maintaining data completeness while enhancing processing efficiency.
3Ease of manufacture
If generic security policies are applied across all users, then implementation simplicity is improved, but detection accuracy decreases
Solution Approach 1:
The system applies local quality by customizing security policies according to specific user roles, departments, and job functions. Instead of uniform policies, each user group receives tailored thresholds and monitoring rules that reflect their actual work patterns and risk profiles, thereby improving detection accuracy while maintaining manageable complexity through structured customization.
Solution Approach 2:
The patent implements dynamic security policies that adapt to user behavior patterns and contextual factors. Policies automatically adjust based on user roles, time of day, location, and historical behavior, allowing the system to maintain simplicity in implementation while achieving high detection accuracy through context-aware, dynamically adjusted rules.
4Measurement precision
If manual review of security data is performed to ensure accuracy, then detection precision is improved, but processing speed decreases
Solution Approach 1:
The system performs self-service by automatically analyzing and filtering security data using machine learning algorithms and predefined detection rules. The automated analysis provides high-precision threat detection without requiring manual review for every event, thereby maintaining detection precision while significantly improving response speed. Manual intervention is reserved only for complex or ambiguous cases.
Data Source
AI summary
The disclosure addresses the detection of anomalous activity. Some embodiments are directed towards a system for receiving an indication relating to a plurality of controls, identification information associated with a responsible account, and instructions from a responsible account associated with the monitoring of thresholds of controls being monitored. The plurality of user account may be organized into groups based upon information relating to the user accounts, and instructions may be applied to the groups to create a dynamic security policy.


