Anomaly Detection System Using Predictive Approval Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security and anomaly detection technologies are not configured to provide a reliable and efficient solution for predicting anomalous requests and preventing anomalous interactions in network communications, particularly for organization entities, leading to difficulties in detecting and preventing unauthorized access and malicious activities.

Innovation Solution

A system integrated with a processor and memory that processes user profiles by generating data objects, comparing them to approved, audit, and disapproved data sets to determine anomalous indicators, and using an anomaly learning model to predict the approval status of user profiles, thereby flagging or disapproving suspicious requests in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current information security and anomaly detection technologies are used, then basic security monitoring is maintained, but the system cannot reliably predict anomalous requests or prevent anomalous interactions

Engineering Contradiction:
Improveanomaly prediction reliabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the anomaly detection process into multiple independent modules: user profile data collection, data object generation, multiple database comparison (approved, audit, disapproved), anomaly indicator generation, and machine learning-based predictive approval determination. Each module handles a specific aspect of the detection process, improving reliability while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-establishing multiple reference databases (approved user profiles, audit data from third-party sources, disapproved anomalous data) and pre-generating data objects from user profiles before actual anomaly detection occurs. This preparatory work enables more accurate and reliable anomaly prediction when actual requests are evaluated against these pre-prepared reference sets.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive data comparison is performed to detect anomalous requests, then detection accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidrequest processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial comparison actions by comparing user profile data objects against multiple specialized databases (approved, audit, disapproved) with different comparison criteria. Rather than performing exhaustive analysis on all possible data points simultaneously, the system selectively compares relevant data objects against appropriate reference databases, achieving high detection accuracy while controlling processing time through targeted partial comparisons.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The machine learning model performs self-service by automatically determining predictive approval status based on the generated anomaly indicators, eliminating the need for manual review of each anomaly case. The system serves itself by using the collected anomaly data to train and improve its own detection capabilities over time, reducing both processing time and resource requirements for ongoing operations.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If user profiles are processed through multiple database comparisons and anomaly analysis, then security protection improves, but network resource consumption increases

Engineering Contradiction:
Improveprotection against anomalous interactionsVSAvoidnetwork resource consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary data object generation and anomaly indicator creation before final approval determination. By pre-processing user profile data into structured data objects and pre-comparing them against reference databases to generate anomaly indicators, the system reduces the computational burden during actual request processing, thereby protecting against anomalous interactions while minimizing real-time network resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces data objects as intermediaries between raw user profile data and the anomaly detection process. These structured data objects serve as a intermediate representation that simplifies subsequent comparisons against reference databases and reduces the complexity of anomaly analysis, thereby improving security protection while reducing the network resources required for processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12088477B2System and method for predicting anomalous requests and preventing anomalous interactions in a network
Publication Date: 2024.09.10 BANK OF AMERICA CORP
  • US12088477B2 patent drawing
  • US12088477B2 patent drawing
  • US12088477B2 patent drawing

AI summary

A system for predicting an anomalous request comprises a processor associated with a server. The processor is configured to generate a first set of data objects associated with a first user profile. The processor is configured to compare the first set of the data objects to approved data and audit data to generate a second set of data objects with a set of anomalous data indicators for the first user profile. The processor is further configured to process the second set of the data objects through an anomaly learning model to determine a predictive degree of approval associated with the user profile. The processor is further configured to determine to how to process the user profile based on the predictive degree of approval. The processor is further configured to assign a profile indicator to the user profile.