Behavior Reasoning Component for Insider Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting insider threats in organizations are inadequate, leading to high false negative and false positive rates, as they rely on signature detection and anomaly detection, which struggle to anticipate new malicious behavior and differentiate between malicious and non-malicious intent, resulting in significant financial losses and data breaches.

Innovation Solution

A two-stage network system that processes network activity precursors using a behavior reasoning component (BRC) to predict insider threat levels, differentiate between sabotage and theft motivations, and provide ongoing trend analysis, exceeding the capabilities of current analyst processing by associating specific combinations of antecedent precursors with insider threat behaviors through trained pattern classifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature detection methods are used to detect known malicious activities, then detection accuracy for known threats is improved, but the system cannot detect new malicious behavior resulting in high false negative rates

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect new malicious behavior
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing precursor network activities that occur before malicious behavior is executed. By detecting and analyzing these precursor patterns (such as unusual data access, communication patterns, or system configuration changes) before the actual malicious act, the system can identify potential threats that signature-based methods would miss, thereby improving detection of new malicious behaviors while maintaining accuracy for known threats

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions from static signature-based detection to dynamic behavioral analysis. Instead of relying on fixed signatures, the system continuously learns and adapts to new malicious patterns by analyzing network activity dynamics, user behavior changes, and temporal patterns in precursor activities. This dynamic approach enables the system to detect novel threats while maintaining high detection accuracy through adaptive pattern recognition

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If anomaly detection methods are used to detect deviations from baseline activity, then new malicious activity can be detected, but the system produces high false positive rates due to non-normed human behavior

Engineering Contradiction:
Improveability to detect new malicious activityVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system segments the analysis into multiple distinct stages: precursor detection, pattern recognition, and threat classification. By breaking down the detection process into separate analytical components, each focusing on specific aspects of network behavior (such as data access patterns, communication anomalies, or temporal deviations), the system can identify malicious activities more precisely while filtering out benign variations in human behavior that would otherwise trigger false positives

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer of analysis between raw network activity and threat determination. This intermediary layer analyzes precursor patterns and contextual information to distinguish between malicious and benign deviations from baseline behavior. By examining multiple indicators and contextual factors through this intermediary analysis layer, the system reduces false positives while maintaining the ability to detect new malicious activities

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If current detection methods focus on network activity endpoints, then specific malicious activities can be identified, but the system cannot anticipate sabotage or theft before they occur

Engineering Contradiction:
Improveidentification of malicious activitiesVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary detection and analysis of precursor network activities that indicate potential malicious intent before the actual sabotage or theft occurs. By monitoring and analyzing early-stage indicators (such as unusual data access patterns, preparatory communications, or system reconnaissance) and triggering early warnings, the organization gains valuable time to intervene and prevent the malicious act, thereby reducing detection time while maintaining precise identification of threats

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10270790B1Network activity monitoring method and apparatus
Publication Date: 2019.04.23 ANBECO LLC
  • US10270790B1 patent drawing
  • US10270790B1 patent drawing
  • US10270790B1 patent drawing

AI summary

The present invention relates to an insider threat detection system which includes at least two stages: a front end sensor stage with activity detection from detectors, and a behavior reasoning component (BRC) with following automated reporting. As opposed to typical monitoring systems that seek to identify network activities as endpoint activities, work on a small number of static triggered rules or anomalous deviations from established norms, the present invention includes a behavior reasoning component (BRC) that uses network activity as precursor indicators to subsequent malicious or non-malicious behaviors, using BRC pattern classifiers, to predict likely malicious insider behaviors and alert security personnel to insider threat from high probability sabotage, fraud, or theft of sensitive, proprietary, classified data/information.