DDSGA Masquerade Detection with User-Specific Alignment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional masquerade detection systems face challenges in accurately distinguishing between legitimate and malicious user activities in large-scale computer systems, particularly in masquerade attacks where attackers assume the identity of legitimate users, leading to difficulties in detecting unauthorized access and high false positive rates.
Innovation Solution
The Data-Driven Semi-Global Alignment (DDSGA) system uses distinct alignment parameters for each user, building profiles and models based on historical data to identify masquerade attacks by comparing sample signatures with reference signatures, and dynamically updates patterns to improve detection accuracy and reduce false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional masquerade detection systems compare user profiles against logs to detect attacks, then detection capability is provided, but accuracy deteriorates in large-scale systems with high false positive rates
Solution Approach 1:
The patent transforms the detection approach by changing from conventional profile-log comparison to sequence alignment with distinct parameters. Each user has customized alignment parameters (gap penalties, substitution matrices) based on their behavioral patterns, transforming the detection mechanism to achieve higher accuracy in distinguishing masquerade attacks from legitimate behavior variations.
Solution Approach 2:
The system implements local quality by creating user-specific detection models rather than using a uniform approach. Each user's behavioral sequences are analyzed with customized alignment parameters tailored to their specific patterns, allowing the system to adapt to individual user characteristics and improve local detection accuracy for each user context.
2Measurement precision
If conventional systems use uniform detection methods for all users, then system simplicity is maintained, but detection accuracy deteriorates due to inability to distinguish individual user patterns
Solution Approach 1:
The patent segments the detection system into user-specific components, where each user has their own profile, behavioral sequences, and alignment parameters. This segmentation allows the system to handle multiple users with distinct patterns independently, improving measurement precision for each user while managing complexity through modular, reusable alignment frameworks.
Solution Approach 2:
The system incorporates dynamics by allowing alignment parameters to be customized and updated for each user based on their behavioral patterns. The detection model adapts to individual users dynamically, adjusting gap penalties, substitution matrices, and other parameters to match each user's specific behavior, thereby improving accuracy without requiring complete system redesign.
3Reliability
If conventional masquerade detection systems analyze user behaviors in large-scale systems, then detection coverage is improved, but computational intensity increases leading to performance degradation
Solution Approach 1:
The patent applies preliminary action by pre-processing user behavioral data into structured sequences and pre-calculating alignment parameters during a setup phase. User profiles and behavioral patterns are analyzed in advance to establish baseline parameters, so that during actual detection, the system can perform faster alignment operations without repeated heavy computation, improving real-time performance.
Solution Approach 2:
The system replaces conventional mechanical comparison methods with sequence alignment algorithms inspired by biological sequence analysis. This substitution enables more efficient handling of behavioral data by using optimized dynamic programming approaches and heuristic methods, reducing computational intensity while maintaining or improving detection reliability in large-scale systems.
Data Source
AI summary
Systems and methods are provided for intrusion detection, specifically, identifying masquerade attacks in large scale, multiuser systems, which improves the scoring systems over conventional masquerade detection systems by adopting distinct alignment parameters for each user. For example, the use of DDSGA may result in a masquerade intrusion detection hit ratio of approximately 88.4% with a small false positive rate of approximately 1.7%. DDSGA may also improve the masquerade intrusion detection hit ratio by about 21.9% over convention masquerade detection techniques and lower the Maxion-Townsend cost by approximately 22.5%. It will also improve the computational overhead.


