Cyber Behavior Profile with Temporal Detail for Insider Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures are inadequate in addressing insider threats, as they rely on static rules and struggle to detect malicious behavior from trusted users, especially when influenced by external factors or stressors, and are limited by the unpredictability of human behavior and resource constraints.

Innovation Solution

A method and system for generating a cyber behavior profile by monitoring user interactions, converting them into multi-layered electronic information, and creating a unique multi-dimensional profile to detect acceptable, anomalous, and malicious behavior, utilizing a user behavior monitoring system that includes physical and cyber behavior elements, and implementing this profile as a blockchain for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If static rules and traditional security measures are used to protect systems, then implementation is straightforward and resource consumption is low, but detection precision of malicious insider behavior is insufficient

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic user behavior profiling that continuously adapts to changing user patterns and contexts. The system transitions from static security rules to dynamic behavioral analysis, where security parameters are continuously updated based on observed user behavior, enabling detection of malicious activities that deviate from established baselines while accounting for legitimate behavior changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces multi-dimensional behavioral analysis by examining user interactions across multiple layers including temporal patterns, resource access patterns, and contextual factors. This dimensional expansion allows the system to detect malicious behavior through anomalies in the behavioral space rather than relying on traditional single-dimension security rules.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive user behavior monitoring is implemented to detect insider threats, then detection capability is improved, but resource consumption and system complexity increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements selective monitoring that focuses computational resources on analyzing only the behavioral dimensions most relevant to detecting insider threats. Rather than monitoring all possible user actions with equal intensity, the system identifies and prioritizes critical behavioral patterns, applying partial action principles to optimize resource utilization while maintaining security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system employs self-learning mechanisms where the behavioral profiling automatically adapts to organizational patterns without requiring continuous manual configuration or analysis. The monitoring system serves itself by automatically establishing baselines, updating profiles, and adjusting detection thresholds, reducing the need for external computational resources and expert intervention.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If traditional behavioral baseline analysis is used without accounting for temporal patterns, then analysis is simpler and faster, but detection accuracy decreases due to inability to account for legitimate behavior changes

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent incorporates temporal analysis by examining user behavior at multiple time scales, including periodic patterns such as daily routines, weekly cycles, and seasonal variations. The system analyzes behavioral data periodically to detect deviations from established temporal patterns, enabling differentiation between legitimate behavior changes (such as vacation patterns) and malicious activities.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs preliminary behavioral baseline establishment during normal operational periods before detecting anomalies. By pre-characterizing legitimate user behavior patterns across various temporal contexts, the system prepares detection thresholds and profiles in advance, enabling more accurate real-time detection without requiring complex on-the-fly analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11575685B2User behavior profile including temporal detail corresponding to user interaction
Publication Date: 2023.02.07 FORCEPOINT LLC
  • US11575685B2 patent drawing
  • US11575685B2 patent drawing
  • US11575685B2 patent drawing

AI summary

A system, method, and computer-usable medium are disclosed for generating a cyber behavior profile comprising monitoring user interactions between a user and an information handling system; converting the user interactions into electronic information representing the user interactions, the electronic information representing the user interactions comprising temporal detail corresponding to the user interaction; and generating a user behavior profile based upon the electronic information representing the user interactions, the generating the user profile including a layer of detail corresponding to the temporal detail corresponding to the user interaction.