Behavioral Analysis for Credential Risk Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for securing computing systems are not effectively deterrents against attacks, particularly when unauthorized individuals use compromised login credentials to access sensitive information.

Innovation Solution

A system and method that collect timestamped data from various software products to differentiate normal user behavior from malicious activity, analyzing this data to determine risk levels and triggering security actions when thresholds are exceeded, such as disconnecting devices, prompting multi-factor authentication, and alerting administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security methods are used to protect computing systems, then basic security coverage is provided, but they are not effectively deterrents against attacks using compromised credentials

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by collecting timestamped data from multiple software products and analyzing user behavior patterns before an attack occurs. This establishes a baseline of normal behavior that enables proactive detection of credential compromise, moving security from reactive to preventive mode

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops by monitoring user behavior, comparing it against learned normal patterns, and dynamically adjusting security measures. When anomalies are detected, the system provides feedback through risk classification and triggers appropriate security actions, creating a self-adjusting security mechanism

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If security actions are triggered for high-risk credentials, then malicious attacks are thwarted, but authorized users may be disrupted

Engineering Contradiction:
Improveattack preventionVSAvoiduser operation continuity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies local quality by differentiating security responses based on specific user behavior contexts. Instead of blanket security measures, it targets only the specific credential or session showing anomalous behavior, leaving other authorized user operations unaffected. This localized approach minimizes disruption to legitimate users while maintaining strong protection against attacks

Inventive Principle:
Principle #3Local quality

3Measurement precision

If multiple data sources are collected and analyzed, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvebehavior analysis accuracyVSAvoiddata collection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges data from multiple different software products into a unified analysis framework. By collecting timestamped data from various sources and integrating them through a common behavioral analysis model, the system achieves comprehensive detection accuracy while managing complexity through standardized data processing procedures

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11277421B2Systems and methods for detecting and thwarting attacks on an IT environment
Publication Date: 2022.03.15 CITRIX SYSTEMS INC
  • US11277421B2 patent drawing
  • US11277421B2 patent drawing
  • US11277421B2 patent drawing

AI summary

Systems and methods for detecting and thwarting attacks on a computing system. The methods comprise: collecting timestamped data from different software products comprising a unified end point management product, an SBC/ADV product, an application delivery controller product, a content collaboration product, and/or a software defined WAN product; analyzing the collected timestamped data to determine if an observed user behavior matches a learned normal user behavior of an authorized user associated with a user account; determining a risk classification level associated with a credential used by a user to log into the user account, when the observed user behavior does not match the learned normal user behavior of the authorized user; and causing at least one security related action to be performed when the risk classification level is greater than a threshold level or the risk classification level is one of a top N highest risk classification levels.