Dynamic Time-Interval Risk Scoring for Internal User Behavior
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional Security Information and Event Management Systems (SIEM) are inadequate in assessing dynamic security risks posed by internal users, as they rely on fixed time intervals for user behavior analysis, leading to missed insights and false positives due to rigid modeling schemes.
Innovation Solution
The approach employs time-based machine-learning models trained on varying intervals, continuously updated with new data, which analyze event data across different time intervals to generate dynamic risk scores, combining these with rule-based and non-time-based scores for a comprehensive security risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If fixed time intervals are used for user behavior analysis, then the modeling scheme is simple and rigid, but important information is missed and false positives increase
Solution Approach 1:
The patent transitions from static fixed-time-interval models to dynamic models that continuously adapt to user behavior patterns. The system learns and adjusts to changing user activities in real-time, allowing the analysis window and parameters to dynamically respond to actual user behavior rather than being constrained by predetermined fixed intervals.
Solution Approach 2:
The patent segments the continuous user behavior data into multiple overlapping analysis windows with different time intervals. Instead of using a single fixed interval, the system divides the analysis into multiple segments (e.g., 5-minute, 15-minute, 1-hour windows) that can be analyzed simultaneously, capturing both short-term anomalies and long-term patterns.
2Reliability
If traditional SIEM systems are used, then the system structure is simple, but security risk assessment for internal users is inadequate
Solution Approach 1:
The patent introduces a behavior learning module as an intermediary between traditional SIEM event collection and analysis. This module learns normal user behavior patterns and serves as a mediator to distinguish between legitimate user activities and actual security threats, enhancing the reliability of risk assessment without completely replacing the traditional SIEM architecture.
Solution Approach 2:
The patent creates a composite security analysis system that combines traditional SIEM rule-based detection with machine learning-based behavior analysis. The system integrates multiple analytical approaches (statistical analysis, machine learning models, rule-based detection) to form a composite assessment mechanism that leverages the strengths of each approach while mitigating their individual weaknesses.
3Adaptability or versatility
If fixed window period scoring is used, then the modeling process is efficient, but user activity pattern shifts are not detected
Solution Approach 1:
The patent implements periodic retraining and updating of behavior models at scheduled intervals while also allowing for continuous passive learning. The system periodically reconstructs models with updated training data to adapt to long-term behavior changes, while maintaining operational efficiency by using the existing models for scoring during the intervals between retraining cycles.
Solution Approach 2:
The patent performs preliminary behavior pattern learning during off-peak hours or using historical data before deployment. By pre-learning normal behavior patterns and establishing baseline models in advance, the system reduces the computational burden during real-time operation, maintaining both adaptability to user changes and operational efficiency.
Data Source
AI summary
An approach is provided that receives event data that correspond to detected activities performed by a user on one of a set of one or more computer systems. The detected activities are performed by the user over a time duration. The approach analyzes the event data using time-based models. Each of the time-based models correspond to a different time interval that is included in the time duration. The analysis results in time-based risk scores pertaining to the user for each of the different time intervals. An action is then performed based on an overall security risk score of the user with the overall security risk score of the user being calculated based on the different time-based risk scores.


