Customizable User Behavior Analytics Deployment via Containerization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional User Behavior Analytics (UBA) platforms are inflexible and lack configurability, requiring sensitive machine data to be uploaded to unknown cloud environments, posing security risks and limiting the ability to customize threat detection specific to an organization's domain knowledge.
Innovation Solution
A computer-implemented method involving obtaining a content package that defines a behavior model and anomaly, updating a default container image, and deploying customized computing instances to detect anomalies within a private computing environment, allowing for customized threat detection and configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a conventional cloud-based UBA platform is used, then the platform can process vast quantities of machine data, but sensitive machine data must be uploaded to an unknown computing environment which poses security risks
Solution Approach 1:
Instead of uploading data to a cloud platform for processing, the patent inverts the approach by deploying the UBA platform locally within the private computing environment. The containerized UBA system processes data in-place, eliminating the need to transmit sensitive data externally while maintaining full data processing capabilities.
Solution Approach 2:
The patent introduces containerization technology as an intermediary layer that enables the UBA platform to run within the private environment. The container package encapsulates the UBA system with all necessary dependencies, allowing it to function as a self-contained processing environment that bridges the need for advanced analytics and local data security.
2Reliability
If a conventional UBA platform is used, then the platform can detect anomalies, but the platform has limited configurability and cannot leverage domain knowledge for customization
Solution Approach 1:
The patent implements dynamic configurability through environment variables and configuration files that can be modified within the container. The UBA platform adapts to different organizational needs by allowing runtime configuration of detection parameters, thresholds, and behavior models without requiring redeployment, enabling both reliability and adaptability.
Solution Approach 2:
The patent enables local quality customization by allowing different configuration parameters and behavior models to be applied to specific data sources, departments, or threat types within the organization. Each container instance can be tailored with domain-specific knowledge and local requirements while maintaining the core anomaly detection functionality.
3Adaptability or versatility
If a customized UBA deployment is created from scratch, then the deployment can be fully tailored to specific needs, but the burden of generating the deployment is significant
Solution Approach 1:
The patent applies preliminary action by pre-configuring the UBA platform within the container package with default behavior models, anomaly detection algorithms, and standard configuration files. This advance preparation provides a ready-to-deploy baseline that organizations can immediately use, significantly reducing the effort required compared to building from scratch while maintaining full customization capability through configuration files.
Solution Approach 2:
The patent uses copying by providing template configuration files and pre-built behavior models that can be replicated and modified. Organizations can start with pre-configured templates and copy them across different environments or data sources, then customize them as needed, dramatically reducing the manual setup effort while maintaining adaptability.
Data Source
AI summary
A deployment manager executing in a distributed computing environment generates a user behavior analytics (UBA) deployment to process structured event data. The deployment manager configures a streaming cluster to perform streaming processing on real-time data and configures a batch cluster to perform batch processing on aggregated data. A configuration manager executing in the distributed computing environment interoperates with the deployment manager to update the UBA deployment with user-provided code and configurations that define streaming and batch models, among other things. In this manner, the deployment manager provides a scalable UBA deployment that can be customized, via the configuration manager, by a user.


