Dynamic Anomaly Detector Using UEBA for Log Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mission-critical applications face challenges in detecting anomalies and security threats due to the complexity and volume of business process logs, which exceed human analysis capabilities, necessitating an automated and scalable solution for effective anomaly detection.
Innovation Solution
A system utilizing User and Entity Behavior Analysis (UEBA) with machine learning models for dynamic anomaly detection, incorporating data pipelines, preparation modules, parsing modules, algorithms, and engines to analyze logs and audit trails, enabling efficient classification and scoring of events, and allowing for easy extension to support new applications and predictive capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If manual analysis of business process logs is performed, then detection accuracy may be maintained, but the time required for analysis increases from milliseconds to hours
Solution Approach 1:
The patent replaces manual mechanical analysis with automated machine learning models and algorithms that process business process logs. The system uses trained models to automatically detect anomalies, classify events, and score deviations without human intervention, reducing analysis time from hours to milliseconds while maintaining detection capability through automated decision-making systems.
Solution Approach 2:
The system enables self-service anomaly detection where the machine learning models autonomously analyze logs, identify patterns, and generate security alerts without requiring manual analysis. The automated system serves itself by continuously learning from data and adapting to new threat patterns, eliminating the need for human analysts to perform routine detection tasks.
2Reliability
If comprehensive analysis of all business process logs is performed, then detection coverage is improved, but computational complexity and resource requirements increase
Solution Approach 1:
The patent segments the log analysis process into distinct machine learning models, each specialized for specific detection tasks such as anomaly detection, event classification, and deviation scoring. This modular architecture divides the comprehensive analysis into manageable components that can be processed independently, reducing overall system complexity while maintaining complete detection coverage across all log types.
Solution Approach 2:
The system employs universal machine learning models that can handle multiple detection functions simultaneously. The same infrastructure and algorithms are used across different mission-critical applications, allowing the system to provide comprehensive detection coverage for diverse log types and security threats without proportionally increasing complexity for each individual function.
3Adaptability or versatility
If the system is extended to support new mission-critical applications, then versatility is improved, but integration complexity increases
Solution Approach 1:
The patent implements a universal machine learning framework that can be applied across multiple mission-critical applications including ERP, CRM, SCM, and other business systems. The same detection algorithms and model architecture serve diverse applications, allowing the system to extend versatility to new applications without requiring separate complex integration processes for each one.
Solution Approach 2:
The system dynamically adapts to new applications through continuous learning and model retraining. When new mission-critical applications are integrated, the machine learning models automatically adjust to the specific log formats and patterns of each application, enabling versatile support for diverse systems while maintaining a consistent, manageable integration process through adaptive rather than static configuration.
Data Source
AI summary
Security can be improved in a business application or system, such as a mission-critical application, by automatically analyzing and detecting anomalies for mission-critical applications. This detection may be based on a dynamic analysis of business process logs and audit trails that includes User and Entity Behavior Analysis (“UEBA”).


