Cloud Application Anomaly Detection via User Behavior Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to effectively detect and respond to anomalies in access patterns to cloud applications, which can indicate malicious activity, compromising data security in cloud-based networks.

Innovation Solution

A security application that collects behavior data from users and client computers accessing cloud applications, establishes baselines, detects anomalies, aggregates risk data, and performs countermeasures based on determined risk values to prevent malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current security systems are used to monitor cloud application access, then basic security monitoring is provided, but anomalies in access patterns cannot be effectively detected

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoiddata security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by collecting behavior data and establishing baselines for normal access patterns before actual security threats occur. This proactive approach enables the system to detect anomalies by comparing current access patterns against pre-established baselines, improving detection precision while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring access patterns, comparing them against baselines, and adjusting security responses based on detected anomalies. The feedback loop includes collecting behavior data, detecting deviations from normal patterns, determining risk values, and executing countermeasures, thereby enhancing both detection capability and security reliability simultaneously.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive behavior data is collected from all users and client computers, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata collection and processing system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system divides the complex monitoring task into manageable segments by collecting behavior data separately from different sources (users, client computers, cloud applications) and processing them through distinct functional modules. Each segment handles specific aspects of data collection, baseline establishment, and anomaly detection, reducing overall system complexity while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs universal components that perform multiple functions: the behavior data collection mechanism serves both users and client computers, the baseline establishment process works across different cloud applications, and the anomaly detection engine analyzes patterns from multiple sources using the same core algorithms, thereby improving detection accuracy without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If real-time anomaly detection is implemented across multiple baselines and users, then security response time is improved, but computational requirements increase

Engineering Contradiction:
Improvesecurity response timeVSAvoidcomputational resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by focusing computational resources on detecting anomalies that exceed specific risk thresholds rather than analyzing every single access event in detail. The anomaly aggregation function consolidates multiple baseline violations, allowing the system to respond rapidly to significant threats while using computational resources efficiently by avoiding redundant analysis of minor deviations.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system merges multiple anomaly detections across different baselines and users into aggregated anomaly data, reducing the total number of individual analyses required. By combining related anomalies and processing them collectively, the system maintains real-time detection capability across multiple targets while reducing overall computational resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10536473B2System and method for detecting anomalies associated with network traffic to cloud applications
Publication Date: 2020.01.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10536473B2 patent drawing
  • US10536473B2 patent drawing
  • US10536473B2 patent drawing

AI summary

An anomaly detection system is provided and includes a processor, a memory, and a security application that is stored in the memory and includes instructions. The instructions are configured to collect information of behavior data for the users of an organization accessing cloud applications via a distributed network. The behavior data includes one or more parameters tracked over time for the users. The instructions are further configured to: establish baselines for each of the users and for each of the cloud applications or types of cloud applications of the organization; detect anomalies based on the baselines; provide aggregated anomaly data by aggregating anomalies corresponding to two or more of the baselines and a same behavior or corresponding to multiple users of a same cloud application during a same period of time; determine a risk value based on the aggregated anomaly data; and perform a countermeasure based on the risk value.