Customizable User Behavior Analytics Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional User Behavior Analytics (UBA) platforms are insecure due to cloud-based nature, requiring sensitive data upload and offering limited configurability, making it difficult for IT infrastructure administrators to customize threat detection specific to their environment.
Innovation Solution
A computer-implemented method involving obtaining a content package to define a behavior model, updating a default container image, and deploying customized computing instances to detect anomalies within a private computing environment, allowing for customized threat detection and anomaly monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If UBA platform is deployed in cloud-based environment, then scalability and service accessibility are improved, but security is worsened due to sensitive data upload requirements
Solution Approach 1:
Instead of uploading data to a cloud-based UBA platform, the patent inverts the approach by deploying the UBA platform within the customer's own cloud environment. This allows the platform to remain accessible and functional while eliminating the security risk of data transmission to external cloud services.
Solution Approach 2:
The patent introduces a containerized UBA platform as an intermediary that can be deployed in hybrid cloud environments. This intermediary enables organizations to maintain data security by keeping sensitive data within their own infrastructure while still utilizing UBA capabilities through the containerized deployment model.
2Reliability
If conventional UBA platform is used, then basic anomaly detection is provided, but configurability is limited making customization difficult
Solution Approach 1:
The patent segments the UBA platform into containerized microservices that can be independently configured and deployed. This segmentation allows administrators to selectively enable or disable specific anomaly detection models and behaviors based on their organizational needs, thereby improving configurability while maintaining detection capabilities.
Solution Approach 2:
The patent implements dynamic configurability through container orchestration systems that allow runtime modification of UBA platform behavior. Administrators can dynamically add, remove, or update anomaly detection models and adjust detection parameters without redeploying the entire platform, enabling flexible adaptation to changing security requirements.
3Measurement precision
If custom anomaly detection models are implemented, then detection precision for specific threats is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal containerized platform that can host multiple specialized anomaly detection models simultaneously. This multi-functional approach allows the system to maintain high detection precision for various threat types while managing complexity through a unified deployment and orchestration framework that handles model lifecycle management centrally.
Data Source
AI summary
A deployment manager executing in a distributed computing environment generates a user behavior analytics (UBA) deployment to process structured event data. The deployment manager configures a streaming cluster to perform streaming processing on real-time data and configures a batch cluster to perform batch processing on aggregated data. A configuration manager executing in the distributed computing environment interoperates with the deployment manager to update the UBA deployment with user-provided code and configurations that define streaming and batch models, among other things. In this manner, the deployment manager provides a scalable UBA deployment that can be customized, via the configuration manager, by a user.


