Bayesian Models for Network Credential Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions inadequately address the detection of user credential theft and misuse within networks, particularly failing to effectively identify anomalous behavior through statistical modeling of event logs.

Innovation Solution

The implementation of Bayesian statistical models derived from computing system event logs to independently analyze time series of user credentials and machine events, flagging anomalous behavior for potential security incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based approaches are used to detect security incidents, then detection capability is provided, but false alarms increase and detection precision deteriorates

Engineering Contradiction:
Improvesecurity incident detectionVSAvoidanomaly detection precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent replaces rule-based mechanical detection systems with statistical modeling approaches. Instead of using fixed rules to detect security incidents, the system employs Bayesian statistical models to analyze event log patterns and identify anomalies, thereby improving detection precision while maintaining reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameters of detection by transitioning from binary rule-based detection to probabilistic statistical modeling. By using p-values and confidence intervals from Bayesian models, the system dynamically adjusts detection thresholds based on learned normal behavior patterns, reducing false alarms while improving anomaly detection precision

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If single sign-on is implemented to improve user experience, then authentication convenience is improved, but credential security deteriorates as attackers can easily recover credentials from memory

Engineering Contradiction:
Improveuser authentication convenienceVSAvoidcredential theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms by continuously monitoring authentication events and updating behavioral models in real-time. The system learns normal authentication patterns for each user and provides feedback when deviations occur, enabling dynamic security responses that maintain convenience while detecting credential misuse

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces statistical behavioral models as intermediaries between authentication systems and security detection. These models analyze event log patterns and serve as a layer that detects credential theft without interfering with normal single sign-on operations, thereby maintaining user convenience while improving security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive event log analysis is performed to improve security detection, then detection capability is improved, but computational complexity and processing time increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by analyzing event logs independently for each user credential separately. This divides the complex task of analyzing all network events into manageable per-user segments, reducing computational complexity while maintaining comprehensive detection capability through individualized behavioral models

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10375095B1Modeling behavior in a network using event logs
Publication Date: 2019.08.06 TRIAD NATIONAL SECURITY LLC
  • US10375095B1 patent drawing
  • US10375095B1 patent drawing
  • US10375095B1 patent drawing

AI summary

A framework is provided for modeling the activity surrounding user credentials and/or machine level activity on a computer network using computer event logs by viewing the logs attributed to each user as a multivariate data stream. The methodology performs well in detecting compromised user credentials at a very low false positive rate. Such a methodology may detect both users of compromised credentials by external actors and otherwise authorized users who have begun engaging in malicious activity.