Cloud Security Anomaly Detection via Unsupervised Pattern Recognition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud security systems face challenges in proactively learning user behavior and detecting anomalous activity, as existing solutions like policy-based monitoring are limited in their ability to adapt and identify complex patterns, leading to potential security risks.

Innovation Solution

A cloud security system that utilizes machine learning techniques to learn patterns of user behavior over time, generate models, and identify deviations through the analysis of activity data, enabling the detection of anomalous behavior and real-time alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If policy-based monitoring is used to monitor cloud service usage, then security monitoring coverage is provided, but the system cannot proactively learn user behavior patterns or detect anomalous activity

Engineering Contradiction:
Improveability to learn user behavior patternsVSAvoidmonitoring system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional policy-based mechanical monitoring with machine learning-based pattern recognition. The system uses unsupervised learning algorithms to automatically discover user behavior patterns without manual policy configuration, enabling proactive anomaly detection while reducing operational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The monitoring system performs self-learning by automatically analyzing activity data and generating behavior patterns without external intervention. The machine learning models continuously adapt to new user behaviors autonomously, eliminating the need for manual policy updates and improving adaptability.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional security monitoring methods are used, then basic security coverage is achieved, but false alarms cannot be reduced through pattern recognition

Engineering Contradiction:
Improveaccuracy of security detectionVSAvoiddifficulty in identifying anomalous behavior
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary learning by establishing baseline user behavior patterns before security incidents occur. By pre-processing activity data and generating behavior models in advance, the system can accurately compare actual activity against established patterns, reducing false alarms and improving detection reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system implements continuous feedback loops where detected anomalies are fed back into the learning process. The machine learning models continuously refine behavior patterns based on new data, improving the accuracy of anomaly detection over time and reducing false positives through adaptive learning.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11165800B2Cloud based security monitoring using unsupervised pattern recognition and deep learning
Publication Date: 2021.11.02 ORACLE INT CORP
  • US11165800B2 patent drawing
  • US11165800B2 patent drawing
  • US11165800B2 patent drawing

AI summary

Provided are systems and methods for a cloud security system that learns patterns of user behavior and uses the patterns to detect anomalous behavior in a network. Techniques discussed herein include obtaining activity data from a service provider system. The activity data describes actions performed during use of a cloud service over a period of time. A pattern corresponding to a series of actions performed over a subset of time can be identified. The pattern can be added a model associated with the cloud service. The model represents usage of the cloud service by the one or more users. Additional activity data can be obtained from the service provider system. Using the model, a set of actions can be identified in the additional activity data that do not correspond to the model. The set of actions and an indicator that identifies the set of actions as anomalous can be output.