Anomalous Messaging Detection via Behavioral Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email security solutions are ineffective against internal attacks originating from compromised user accounts due to malware infections and sophisticated phishing techniques, as they primarily focus on external threats and do not adequately detect abnormal behavior within the protected network.

Innovation Solution

A system utilizing machine learning for anomaly detection, establishing a baseline of normal and abnormal behaviors, and employing API commands for interaction between a messaging and account hunting platform, action center, and security operations center to detect anomalous messaging, discover compromised accounts, and generate responses to threatened attacks, thereby enhancing email security both internally and externally.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional email security solutions focus on external threats and malicious signatures, then external attack detection is improved, but internal attacks from compromised accounts cannot be detected

Engineering Contradiction:
Improveemail security effectivenessVSAvoiddetection coverage against different attack types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional security approach by shifting focus from external threat detection to internal anomaly detection. Instead of scanning for malicious signatures from outside, the system monitors behavioral patterns of compromised accounts from within the network, detecting attacks that originate internally through machine learning-based anomaly detection

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system implements dynamic behavioral baselines that adapt to normal account activity patterns. By continuously learning and updating what constitutes normal behavior for each account, the system can dynamically detect deviations that indicate compromise, making the detection mechanism flexible and context-aware rather than static

Inventive Principle:
Principle #15Dynamics

2Loss of time

If machine learning models are trained on limited behavioral data, then training time and computational resources are reduced, but detection accuracy and anomaly identification capability deteriorate

Engineering Contradiction:
Improvemodel training timeVSAvoidanomaly detection accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by continuously collecting and pre-processing behavioral data in the background before anomalies occur. This includes gathering account activity data, establishing baseline behaviors, and preparing training datasets in advance, so when anomalies need detection, the models are already trained and ready, reducing both training time and improving accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous data collection and model training operations rather than periodic batch processing. This continuous operation ensures that the machine learning models are constantly improving with new data while maintaining detection readiness, balancing resource usage with detection accuracy through ongoing incremental learning

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If comprehensive behavioral data is collected from all accounts, then detection capability is improved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the monitoring task by creating individual behavioral profiles for each account rather than treating all accounts uniformly. This segmentation allows the system to collect comprehensive data per account while processing it in manageable units, reducing overall system complexity through modular, account-specific analysis pipelines

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including event subscribers, data normalization layers, and baseline calculation services that mediate between raw data collection and anomaly detection. These intermediaries simplify the architecture by breaking down complex processing into discrete, manageable stages with clear interfaces between components

Inventive Principle:
Principle #24Intermediary (Mediator)

4Speed

If real-time anomaly detection is implemented, then response time to attacks is improved, but computational resource consumption increases

Engineering Contradiction:
Improveattack response timeVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring by focusing computational resources on detecting specific types of anomalies and accounts based on risk assessment. Rather than analyzing every single event from every account with equal intensity, the system selectively applies deeper analysis only where anomalies are detected or risk is higher, reducing overall resource consumption while maintaining real-time detection capability

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11128649B1Systems and methods for detecting and responding to anomalous messaging and compromised accounts
Publication Date: 2021.09.21 TREND MICRO INC
  • US11128649B1 patent drawing
  • US11128649B1 patent drawing
  • US11128649B1 patent drawing

AI summary

One embodiment disclosed relates to a system for detecting anomalous messaging, discovering compromised accounts, and generating responses to threatened attacks. The system utilizes API commands and log forwarding for interaction and communication between a messaging and account hunting platform, other hunting platforms, an action center, and a security operations center. Another embodiment relates to a method of, and system for, performing a complete root cause analysis. Another embodiment relates to a method of, and system for, anomaly discovery which may advantageously utilize reference data to correlate different anomalies for reporting as a single incident.