Anomaly Detection False Positive Reduction via User Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Behavioral modeling approaches for anomaly detection in enterprise networks often generate excessive alerts and false positives, making it difficult to investigate anomalous behavior in a timely and effective manner.

Innovation Solution

The system determines clusters of users and resources, augmenting temporal behavior models with 'recommended' resources to reduce the likelihood of identifying normal interactions as anomalous, by incorporating a 'recommended' resource set and a 'null' column to refine the models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If behavioral modeling approach is used for anomaly detection, then anomalous behavior can be detected, but too many false positive alerts are generated

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidfalse positive alerts
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments users and resources into clusters based on behavioral similarities. By grouping entities with comparable access patterns, the system can apply cluster-specific baseline models rather than individual models, reducing false positives while maintaining detection accuracy. Users in the same cluster share common behavioral characteristics, allowing the system to distinguish between normal variations and true anomalies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically adjusts detection parameters by incorporating a 'recommended resource set' and 'null column' into the behavioral models. These parameter modifications allow the system to adapt to normal behavioral variations (such as first-time access to related resources) without compromising anomaly detection sensitivity, thereby reducing false positives while maintaining reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If behavioral modeling approach is used for anomaly detection, then anomalous behavior can be detected, but investigation time increases due to excessive alerts

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidinvestigation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By segmenting users and resources into behavioral clusters, the system reduces the overall alert volume through more accurate cluster-level baseline comparisons. This segmentation enables investigators to focus on fewer, more relevant alerts, significantly reducing investigation time while preserving the system's ability to detect true anomalies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary clustering and baseline model creation before anomaly detection occurs. By pre-establishing cluster memberships and behavioral baselines, the system prepares the detection framework in advance, enabling faster real-time analysis and reducing the time required for investigator review of potential anomalies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9727723B1Recommendation system based approach in reducing false positives in anomaly detection
Publication Date: 2017.08.08 EMC IP HLDG CO LLC
  • US9727723B1 patent drawing
  • US9727723B1 patent drawing
  • US9727723B1 patent drawing

AI summary

Techniques to reduce false positives in detecting anomalous use of resources are disclosed. In various embodiments, resource access data indicating for each resource in a set of resources respective usage data for each of one or more users of the resource is received. Cluster analysis is performed to determine one or more clusters of users. For each cluster, a set of recommended resources to be associated with the cluster is determined. For each of at least a subset of users, a temporal behavior based model for each user that reflects one or more resources included in the set of recommended resources associated with a corresponding cluster of which the user is a member is generated.