Dynamic Peer Grouping for UEBA False Positive Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user and entity behavior analytics (UEBA) systems generate high false positive rates due to their inability to provide granular enough information, as they compare user behavior to both user and group profiles, which are not sufficiently nuanced to effectively reduce false positives.

Innovation Solution

The system employs dynamic grouping based on app usage and location, using machine learning and statistical analysis to compare user behavior to both user and peer group profiles, reducing false positives by assigning users to groups that best model their behavior, and utilizing alert scoring and decay factors to calculate a user confidence or risk score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If user behavior is compared to group profiles in UEBA systems, then anomaly detection capability is improved, but false positive rate increases due to insufficient granularity

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments users into dynamically formed peer groups based on similar behavior patterns, rather than using a single monolithic group profile. This segmentation allows for more granular comparison - each user is evaluated against a customized peer group that reflects their actual behavior characteristics, thereby improving anomaly detection precision while reducing false positives caused by comparing dissimilar users against a generic group profile.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If static grouping methods are used in UEBA systems, then system complexity is reduced, but adaptability to changing user behavior patterns deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidadaptability to behavior changes
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic peer group formation where groups are automatically reconfigured based on current user behavior patterns. Instead of static assignments, the system continuously monitors behavior and redistributes users into peer groups that best match their observed patterns. This dynamic approach enables the system to adapt to changing behavior while maintaining manageable complexity through automated algorithms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically forming and reconfiguring peer groups based on observed behavior patterns without requiring manual intervention. The algorithms autonomously analyze user behavior, identify patterns, and assign users to appropriate peer groups, reducing the operational burden while maintaining high adaptability to behavior changes.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If detailed individual user profiles are maintained, then measurement precision of user behavior is improved, but information processing requirements and system complexity increase

Engineering Contradiction:
Improveuser behavior measurement precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges individual user behavior data with peer group behavior patterns to create a composite analysis framework. Instead of maintaining completely separate detailed profiles for each user, the system combines individual observations with aggregated peer group characteristics, achieving high measurement precision through the synergistic interaction of individual and collective behavior patterns while reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11444951B1Reducing false detection of anomalous user behavior on a computer network
Publication Date: 2022.09.13 NETSKOPE INC
  • US11444951B1 patent drawing
  • US11444951B1 patent drawing
  • US11444951B1 patent drawing

AI summary

The disclosed technology teaches a method of reducing false detection of anomalous user behavior on a computer network, including forming groups from identity and access management (IAM) properties and assigning the users into initially assigned groups based on respective IAM properties, and recording individual user behavior in a statistical profile, including application usage frequency. The method also includes dynamically assigning a user with a realigned group, different from the initial assigned group, based on comparing the recorded user behavior, with user behavior in statistical profiles of the users in the groups, evaluating and reporting anomalous events among ongoing behavior of the individual user based on deviations from a statistical profile of the realigned group. The method utilizes common app usage for forming the groups, in some cases. Further, evaluating anomalous events includes evaluating deviations of the events among ongoing behavior of the individual user based from the individual's statistical profile.