Dynamic Time-Interval Risk Scoring for Internal User Behavior

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Security Information and Event Management Systems (SIEM) are inadequate in assessing dynamic security risks posed by internal users, as they rely on fixed time intervals for user behavior analysis, leading to missed insights and false positives due to rigid modeling schemes.

Innovation Solution

The approach employs time-based machine-learning models trained on varying intervals, continuously updated with new data, which analyze event data across different time intervals to generate dynamic risk scores, combining these with rule-based and non-time-based scores for a comprehensive security risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If fixed time intervals are used for user behavior analysis, then the modeling scheme is simple and rigid, but important information is missed and false positives increase

Engineering Contradiction:
Improvesecurity risk assessment accuracyVSAvoidmodeling scheme complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from static fixed-time-interval models to dynamic models that continuously adapt to user behavior patterns. The system learns and adjusts to changing user activities in real-time, allowing the analysis window and parameters to dynamically respond to actual user behavior rather than being constrained by predetermined fixed intervals.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the continuous user behavior data into multiple overlapping analysis windows with different time intervals. Instead of using a single fixed interval, the system divides the analysis into multiple segments (e.g., 5-minute, 15-minute, 1-hour windows) that can be analyzed simultaneously, capturing both short-term anomalies and long-term patterns.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional SIEM systems are used, then the system structure is simple, but security risk assessment for internal users is inadequate

Engineering Contradiction:
Improvesecurity risk assessment reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a behavior learning module as an intermediary between traditional SIEM event collection and analysis. This module learns normal user behavior patterns and serves as a mediator to distinguish between legitimate user activities and actual security threats, enhancing the reliability of risk assessment without completely replacing the traditional SIEM architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a composite security analysis system that combines traditional SIEM rule-based detection with machine learning-based behavior analysis. The system integrates multiple analytical approaches (statistical analysis, machine learning models, rule-based detection) to form a composite assessment mechanism that leverages the strengths of each approach while mitigating their individual weaknesses.

Inventive Principle:
Principle #40Composite materials

3Adaptability or versatility

If fixed window period scoring is used, then the modeling process is efficient, but user activity pattern shifts are not detected

Engineering Contradiction:
Improveadaptation to user activity changesVSAvoidmodel construction efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements periodic retraining and updating of behavior models at scheduled intervals while also allowing for continuous passive learning. The system periodically reconstructs models with updated training data to adapt to long-term behavior changes, while maintaining operational efficiency by using the existing models for scoring during the intervals between retraining cycles.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent performs preliminary behavior pattern learning during off-peak hours or using historical data before deployment. By pre-learning normal behavior patterns and establishing baseline models in advance, the system reduces the computational burden during real-time operation, maintaining both adaptability to user changes and operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12019739B2User behavior risk analytic system with multiple time intervals and shared data extraction
Publication Date: 2024.06.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12019739B2 patent drawing
  • US12019739B2 patent drawing
  • US12019739B2 patent drawing

AI summary

An approach is provided that receives event data that correspond to detected activities performed by a user on one of a set of one or more computer systems. The detected activities are performed by the user over a time duration. The approach analyzes the event data using time-based models. Each of the time-based models correspond to a different time interval that is included in the time duration. The analysis results in time-based risk scores pertaining to the user for each of the different time intervals. An action is then performed based on an overall security risk score of the user with the overall security risk score of the user being calculated based on the different time-based risk scores.