Behavioral Modeling for User Access Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data loss prevention methods are inadequate in monitoring and addressing the risks of misappropriation of sensitive data by authorized users in computer systems, as they rely heavily on partitioning techniques that can be circumvented, and there is a need for improved monitoring of user behavior.

Innovation Solution

A method that involves collecting and aggregating user access log records to create behavioral models, which are used to evaluate and detect deviations in user actions, generating alerts for suspicious behavior, and providing management reports to manage and improve the scoring process over time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If partitioning techniques are used to divide source code into multiple versioned object bases with discrete user sets, then data loss prevention is improved by limiting individual user access, but the system complexity increases and monitoring capability deteriorates

Engineering Contradiction:
Improvedata loss preventionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a behavioral modeling system as an intermediary layer between the partitioned source code management system and users. This mediator collects log records from multiple VOBs, aggregates them chronologically, and applies behavioral models to detect misappropriation patterns that span across partition boundaries, thereby maintaining monitoring capability without simplifying the underlying complex partitioned structure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The behavioral modeling system performs multiple functions simultaneously: it monitors user access across partitioned VOBs, detects misappropriation behavior, generates alerts, and provides a unified monitoring interface. This multi-functional approach addresses the monitoring deterioration caused by partitioning without requiring separate monitoring systems for each VOB

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If partitioning of source code into multiple VOBs with discrete user sets is implemented, then individual user access is limited to reduce misappropriation risk, but the ability to monitor and detect cross-partition misappropriation behavior deteriorates

Engineering Contradiction:
Improvedata loss preventionVSAvoidmonitoring capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges log records from multiple partitioned VOBs into a unified chronological aggregation. By combining access logs across different VOB boundaries and applying behavioral models to the aggregated data, the system detects misappropriation patterns that involve multiple partitions, thereby restoring monitoring capability that was lost due to partitioning

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where behavioral models continuously analyze aggregated log records, generate alerts when misappropriation patterns are detected, and provide management reports. This feedback loop enables ongoing detection and response to cross-partition misappropriation behavior, compensating for the reduced monitoring capability inherent in partitioned systems

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8214364B2Modeling user access to computer resources
Publication Date: 2012.07.03 TAIWAN SEMICONDUCTOR MANUFACTURING CO LTD
  • US8214364B2 patent drawing
  • US8214364B2 patent drawing
  • US8214364B2 patent drawing

AI summary

Embodiments of the invention provide a method for detecting changes in behavior of authorized users of computer resources and reporting the detected changes to the relevant individuals. The method includes evaluating actions performed by each user against user behavioral models and business rules. As a result of the analysis, a subset of users may be identified and reported as having unusual or suspicious behavior. In response, the management may provide feedback indicating that the user behavior is due to the normal expected business needs or that the behavior warrants further review. The management feedback is available for use by machine learning algorithms to improve the analysis of user actions over time. Consequently, investigation of user actions regarding computer resources is facilitated and data loss is prevented more efficiently relative to the prior art approaches with only minimal disruption to the ongoing business processes.