Anomaly Detection False Positive Reduction via User Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Behavioral modeling approaches for anomaly detection in enterprise networks often generate excessive alerts and false positives, making it difficult to investigate anomalous behavior in a timely and effective manner.
Innovation Solution
The system determines clusters of users and resources, augmenting temporal behavior models with 'recommended' resources to reduce the likelihood of identifying normal interactions as anomalous, by incorporating a 'recommended' resource set and a 'null' column to refine the models.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If behavioral modeling approach is used for anomaly detection, then anomalous behavior can be detected, but too many false positive alerts are generated
Solution Approach 1:
The patent segments users and resources into clusters based on behavioral similarities. By grouping entities with comparable access patterns, the system can apply cluster-specific baseline models rather than individual models, reducing false positives while maintaining detection accuracy. Users in the same cluster share common behavioral characteristics, allowing the system to distinguish between normal variations and true anomalies.
Solution Approach 2:
The patent dynamically adjusts detection parameters by incorporating a 'recommended resource set' and 'null column' into the behavioral models. These parameter modifications allow the system to adapt to normal behavioral variations (such as first-time access to related resources) without compromising anomaly detection sensitivity, thereby reducing false positives while maintaining reliability.
2Reliability
If behavioral modeling approach is used for anomaly detection, then anomalous behavior can be detected, but investigation time increases due to excessive alerts
Solution Approach 1:
By segmenting users and resources into behavioral clusters, the system reduces the overall alert volume through more accurate cluster-level baseline comparisons. This segmentation enables investigators to focus on fewer, more relevant alerts, significantly reducing investigation time while preserving the system's ability to detect true anomalies.
Solution Approach 2:
The system performs preliminary clustering and baseline model creation before anomaly detection occurs. By pre-establishing cluster memberships and behavioral baselines, the system prepares the detection framework in advance, enabling faster real-time analysis and reducing the time required for investigator review of potential anomalies.
Data Source
AI summary
Techniques to reduce false positives in detecting anomalous use of resources are disclosed. In various embodiments, resource access data indicating for each resource in a set of resources respective usage data for each of one or more users of the resource is received. Cluster analysis is performed to determine one or more clusters of users. For each cluster, a set of recommended resources to be associated with the cluster is determined. For each of at least a subset of users, a temporal behavior based model for each user that reflects one or more resources included in the set of recommended resources associated with a corresponding cluster of which the user is a member is generated.


