Anomalous Messaging Detection via Behavioral Baselines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current email security solutions are ineffective against internal attacks originating from compromised user accounts due to malware infections and sophisticated phishing techniques, as they primarily focus on external threats and do not adequately detect abnormal behavior within the protected network.
Innovation Solution
A system utilizing machine learning for anomaly detection, establishing a baseline of normal and abnormal behaviors, and employing API commands for interaction between a messaging and account hunting platform, action center, and security operations center to detect anomalous messaging, discover compromised accounts, and generate responses to threatened attacks, thereby enhancing email security both internally and externally.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional email security solutions focus on external threats and malicious signatures, then external attack detection is improved, but internal attacks from compromised accounts cannot be detected
Solution Approach 1:
The patent inverts the traditional security approach by shifting focus from external threat detection to internal anomaly detection. Instead of scanning for malicious signatures from outside, the system monitors behavioral patterns of compromised accounts from within the network, detecting attacks that originate internally through machine learning-based anomaly detection
Solution Approach 2:
The system implements dynamic behavioral baselines that adapt to normal account activity patterns. By continuously learning and updating what constitutes normal behavior for each account, the system can dynamically detect deviations that indicate compromise, making the detection mechanism flexible and context-aware rather than static
2Loss of time
If machine learning models are trained on limited behavioral data, then training time and computational resources are reduced, but detection accuracy and anomaly identification capability deteriorate
Solution Approach 1:
The system performs preliminary actions by continuously collecting and pre-processing behavioral data in the background before anomalies occur. This includes gathering account activity data, establishing baseline behaviors, and preparing training datasets in advance, so when anomalies need detection, the models are already trained and ready, reducing both training time and improving accuracy
Solution Approach 2:
The system maintains continuous data collection and model training operations rather than periodic batch processing. This continuous operation ensures that the machine learning models are constantly improving with new data while maintaining detection readiness, balancing resource usage with detection accuracy through ongoing incremental learning
3Reliability
If comprehensive behavioral data is collected from all accounts, then detection capability is improved, but system complexity and data processing requirements increase
Solution Approach 1:
The system segments the monitoring task by creating individual behavioral profiles for each account rather than treating all accounts uniformly. This segmentation allows the system to collect comprehensive data per account while processing it in manageable units, reducing overall system complexity through modular, account-specific analysis pipelines
Solution Approach 2:
The patent introduces intermediary components including event subscribers, data normalization layers, and baseline calculation services that mediate between raw data collection and anomaly detection. These intermediaries simplify the architecture by breaking down complex processing into discrete, manageable stages with clear interfaces between components
4Speed
If real-time anomaly detection is implemented, then response time to attacks is improved, but computational resource consumption increases
Solution Approach 1:
The system applies partial monitoring by focusing computational resources on detecting specific types of anomalies and accounts based on risk assessment. Rather than analyzing every single event from every account with equal intensity, the system selectively applies deeper analysis only where anomalies are detected or risk is higher, reducing overall resource consumption while maintaining real-time detection capability
Data Source
AI summary
One embodiment disclosed relates to a system for detecting anomalous messaging, discovering compromised accounts, and generating responses to threatened attacks. The system utilizes API commands and log forwarding for interaction and communication between a messaging and account hunting platform, other hunting platforms, an action center, and a security operations center. Another embodiment relates to a method of, and system for, performing a complete root cause analysis. Another embodiment relates to a method of, and system for, anomaly discovery which may advantageously utilize reference data to correlate different anomalies for reporting as a single incident.


