Dynamic Anomaly Detector Using UEBA for Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mission-critical applications face challenges in detecting anomalies and security threats due to the complexity and volume of business process logs, which exceed human analysis capabilities, necessitating an automated and scalable solution for effective anomaly detection.

Innovation Solution

A system utilizing User and Entity Behavior Analysis (UEBA) with machine learning models for dynamic anomaly detection, incorporating data pipelines, preparation modules, parsing modules, algorithms, and engines to analyze logs and audit trails, enabling efficient classification and scoring of events, and allowing for easy extension to support new applications and predictive capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If manual analysis of business process logs is performed, then detection accuracy may be maintained, but the time required for analysis increases from milliseconds to hours

Engineering Contradiction:
Improveanalysis timeVSAvoidautomated detection capability
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The patent replaces manual mechanical analysis with automated machine learning models and algorithms that process business process logs. The system uses trained models to automatically detect anomalies, classify events, and score deviations without human intervention, reducing analysis time from hours to milliseconds while maintaining detection capability through automated decision-making systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service anomaly detection where the machine learning models autonomously analyze logs, identify patterns, and generate security alerts without requiring manual analysis. The automated system serves itself by continuously learning from data and adapting to new threat patterns, eliminating the need for human analysts to perform routine detection tasks.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive analysis of all business process logs is performed, then detection coverage is improved, but computational complexity and resource requirements increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the log analysis process into distinct machine learning models, each specialized for specific detection tasks such as anomaly detection, event classification, and deviation scoring. This modular architecture divides the comprehensive analysis into manageable components that can be processed independently, reducing overall system complexity while maintaining complete detection coverage across all log types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs universal machine learning models that can handle multiple detection functions simultaneously. The same infrastructure and algorithms are used across different mission-critical applications, allowing the system to provide comprehensive detection coverage for diverse log types and security threats without proportionally increasing complexity for each individual function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the system is extended to support new mission-critical applications, then versatility is improved, but integration complexity increases

Engineering Contradiction:
Improveapplication support capabilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal machine learning framework that can be applied across multiple mission-critical applications including ERP, CRM, SCM, and other business systems. The same detection algorithms and model architecture serve diverse applications, allowing the system to extend versatility to new applications without requiring separate complex integration processes for each one.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adapts to new applications through continuous learning and model retraining. When new mission-critical applications are integrated, the machine learning models automatically adjust to the specific log formats and patterns of each application, enabling versatile support for diverse systems while maintaining a consistent, manageable integration process through adaptive rather than static configuration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230044695A1System and method for a scalable dynamic anomaly detector
Publication Date: 2023.02.09 ONAPSIS INC
  • US20230044695A1 patent drawing
  • US20230044695A1 patent drawing
  • US20230044695A1 patent drawing

AI summary

Security can be improved in a business application or system, such as a mission-critical application, by automatically analyzing and detecting anomalies for mission-critical applications. This detection may be based on a dynamic analysis of business process logs and audit trails that includes User and Entity Behavior Analysis (“UEBA”).