Capability Graph Insider Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems are inadequate in detecting and mitigating insider threats, as insiders with authorized permissions can pose significant risks due to their established relationships and varied access levels, making it difficult to distinguish malicious actions from legitimate functions.

Innovation Solution

A system that models potential future states of a network or computer system using a capability graph, identifying undesirable states and determining if they are reachable by insiders, allowing for the modification of capabilities to prevent transitions to these states while minimizing impact on legitimate operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If insider permissions are revoked to prevent malicious actions, then security against insider threats is improved, but legitimate organizational operations are hindered

Engineering Contradiction:
Improvesecurity against insider threatsVSAvoidlegitimate organizational operations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments permissions into fine-grained capabilities organized in a capability graph. Instead of revoking all permissions, the system identifies and restricts only specific capabilities that enable undesirable states, while preserving other capabilities needed for legitimate operations. This allows precise control over insider access at the capability level rather than using broad permission revocation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic capability management where permissions are adjusted based on real-time system state analysis. The capability graph is continuously updated to reflect current system conditions, allowing the system to dynamically grant or restrict capabilities as needed. This enables the system to adapt to changing operational requirements while maintaining security.

Inventive Principle:
Principle #15Dynamics

2Reliability

If capability restrictions are applied to prevent reachable undesirable states, then insider threat mitigation is improved, but false positives increase

Engineering Contradiction:
Improveinsider threat mitigationVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent employs feedback mechanisms where the system continuously monitors actual system state transitions and compares them against the capability graph predictions. When discrepancies are detected, the system refines its analysis and adjusts capability restrictions accordingly. This feedback loop enables the system to learn from actual behavior patterns and reduce false positives while maintaining effective threat mitigation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the parameters of capability representation by organizing permissions as a directed graph of capabilities and their relationships. This graphical representation allows the system to analyze the structure and flow of capabilities, enabling more accurate prediction of which capability combinations can lead to undesirable states. The parameter transformation from flat permission lists to structured capability graphs improves detection precision.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If comprehensive capability monitoring is implemented, then detection of insider threats is improved, but system complexity increases

Engineering Contradiction:
Improveinsider threat detectionVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The capability graph serves multiple functions simultaneously: it represents the system's security model, tracks capability assignments, predicts potential threats, and guides access control decisions. By using a single unified data structure for these diverse purposes, the patent reduces overall system complexity compared to implementing separate mechanisms for each function. The capability graph acts as a multi-functional core that simplifies the overall architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11757918B2Capability based insider threat detection
Publication Date: 2023.09.12 NOBLIS INC
  • US11757918B2 patent drawing
  • US11757918B2 patent drawing
  • US11757918B2 patent drawing

AI summary

Systems and methods for mitigating cybersecurity threats are provided. A system for mitigating cybersecurity threats may be configured to identify, based on a model of a system, future states, wherein the model depicts a plurality of states for the system and a plurality of capabilities enabling transitions between the plurality of states. Identifying future states may be based on a current state of the system, and the future states may comprise an undesirable state. The system may determine, based on the model of the system, whether the undesirable state is a reachable state, wherein the determination is based on capabilities possessed by an insider entity. In accordance with a determination that the undesirable state is a reachable state, the system may modify a capability possessed by the insider entity, wherein modifying the capability prevents the insider entity from causing the system to transition to the undesirable state.