Dynamic Unauthorized Activity Detection System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprises face challenges in detecting and controlling unauthorized access to systems and data across multiple units, as existing systems primarily focus on account-level mitigation without analyzing enterprise-wide vulnerabilities effectively.
Innovation Solution
A dynamic takeover detection and control system that aggregates and analyzes unauthorized activity data from multiple enterprise units using machine learning to identify threats and execute mitigation actions, such as modifying system operations or authentication requirements, while updating machine learning datasets for continuous improvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If account-level mitigation actions are executed to detect and respond to unauthorized access attempts, then response effectiveness at individual account level is improved, but enterprise-wide vulnerability detection capability deteriorates due to lack of aggregated analysis
Solution Approach 1:
The patent combines account-level monitoring systems across multiple enterprise units into a centralized aggregation system that collects and analyzes unauthorized activity data from diverse sources. This merging enables enterprise-wide pattern recognition while maintaining individual account response capabilities, resolving the contradiction between localized effectiveness and global detection capability.
Solution Approach 2:
The system creates a multi-functional platform that simultaneously performs account-level mitigation responses and enterprise-wide vulnerability analysis. By making the system universal, it can operate at both individual account level and aggregate enterprise level, preventing the trade-off between response effectiveness and detection capability.
2Adaptability or versatility
If data from multiple enterprise units is aggregated and analyzed using machine learning to identify enterprise-wide threats, then enterprise-wide vulnerability detection capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces machine learning models as intermediary components that automatically process and analyze aggregated unauthorized activity data. These intermediaries handle the complex pattern recognition and threat identification tasks, reducing the operational complexity burden on the overall system while maintaining high enterprise-wide detection capability.
Solution Approach 2:
The system employs self-updating machine learning models that automatically learn from new data patterns and improve detection capabilities without requiring manual reconfiguration. This self-service mechanism handles the complexity of adapting to new threats autonomously, maintaining detection effectiveness while minimizing human intervention requirements.
3Measurement precision
If machine learning models are continuously updated with mitigation data to improve detection accuracy, then measurement precision of threat detection is improved, but processing time and computational resources increase
Solution Approach 1:
The patent implements periodic batch updates of machine learning models using aggregated mitigation data, rather than continuous real-time retraining. This periodic action allows the system to accumulate sufficient training data and perform model updates at scheduled intervals, improving detection accuracy while managing computational resource consumption and processing time effectively.
Data Source
AI summary
Systems for dynamically detecting and controlling unauthorized events are presented. In some examples, data may be received from one or more computing systems. In some examples, the computing systems may each be associated with an enterprise unit within an enterprise organization. The data may include, in some examples, processed unauthorized activity event data, such as account takeover event data. The data received may be aggregated and analyzed (e.g., using machine learning) to identify potential threats and threat outputs. In some examples, the threat output may include a user interface indicating the threat or potential threat, systems or applications potentially impacted, enterprise units impacted, and the like. Based on the threat output, one or more mitigation actions may be identified and executed. The mitigation actions may include modifying operation of one or more systems, modifying authentication requirements, and the like.


