Anomalous Behavior Detection via Extracted Activity Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer systems lack sufficient granularity in detecting anomalous user and entity behavior, leading to inefficient processor and network usage when attempting to identify potential problems through screen sharing methods.
Innovation Solution
A system and method that defines data sources, monitors user activities, calculates scores based on behavior patterns, and alerts administrators to anomalous behavior, allowing for granular review and potential privilege revocation without impacting network and computing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If screen sharing is used to detect anomalous user behavior, then detection granularity is improved, but processor and network resources are excessively consumed
Solution Approach 1:
The patent extracts only the essential behavior data needed for anomaly detection from the user's computer system, rather than transmitting the entire screen display. This is achieved by collecting specific activity data points (such as application usage, file access patterns, and system events) and transmitting only this extracted information to the remote monitoring system, thereby maintaining detection granularity while dramatically reducing network and processor resource consumption.
Solution Approach 2:
Instead of sharing the actual screen display, the patent creates simplified digital representations or copies of user behavior patterns. The system generates structured data copies that capture essential activity information (application names, event types, timestamps) without replicating the visual screen content, allowing remote analysis while minimizing resource usage on both client and server sides.
2Measurement precision
If comprehensive behavior monitoring is implemented, then anomaly detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the behavior monitoring system into distinct functional modules: a data collection component that gathers activity information, a scoring component that evaluates behaviors against defined criteria, and an alerting component that notifies administrators of anomalies. This segmentation allows comprehensive monitoring capabilities while managing complexity through modular design, where each component has a specific, well-defined function.
Solution Approach 2:
The patent employs configurable parameters and models that can be adjusted to match specific organizational requirements. The system allows administrators to define custom behavior scores, thresholds, and monitoring rules without changing the underlying system architecture. This parameter-based approach enables comprehensive monitoring adaptability while maintaining system simplicity through configuration rather than structural complexity.
Data Source
AI summary
A system and method collects activity data from one or more data sources recording activities of users and other entities and identifies anomalous activity using a statistical analysis of behaviors that are defined using one or more activities, optionally performed in a sequence, optionally performed within a limited time period, and optionally meeting or being excluded from, a filter. The analysis may incorporate the use of a normal, and any number of special, periods, where the analysis uses data from prior periods of the same type.


