Enterprise Graph Insider Influence Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity solutions struggle to effectively assess and mitigate the influence of insiders on enterprise assets, particularly due to the dynamic and interdependent contexts of data sharing within enterprises.
Innovation Solution
A method and system that utilize an enterprise graph to assess insider influence by detecting communities of individuals, calculating influence weights, and analyzing behavioral thresholds to identify potential insiders and their susceptibility to influence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing solutions monitor individual behavior deviations to detect insider threats, then detection capability is improved, but they fail to assess the influence spread to other benign users and indirect access to assets
Solution Approach 1:
The patent combines individual behavior monitoring with community influence analysis by integrating graph-based community detection with behavioral anomaly detection. This merging allows the system to simultaneously track individual deviations and assess their influence spread across the enterprise network, capturing both direct insider actions and indirect influence on benign users.
Solution Approach 2:
The patent adds a new dimension of analysis by constructing enterprise graphs that represent relationships between users, communities, and assets. This graph-based dimension transforms the detection from purely individual behavioral analysis to a multi-dimensional assessment that includes influence propagation paths, community structures, and indirect access routes to enterprise assets.
2Reliability
If the system analyzes casual data exchange within teams as normal behavior, then false positives are reduced, but influential insiders can force or persuade peers to share privileged information undetected
Solution Approach 1:
The patent applies local quality by differentiating between normal team collaboration and suspicious influence-based data sharing. The system analyzes the local structure of data exchange patterns within communities, identifying anomalies in the nature and direction of information flow that indicate insider influence, while maintaining tolerance for normal collaborative behaviors.
Solution Approach 2:
The system implements feedback mechanisms that continuously monitor data sharing patterns and adjust the assessment of insider influence. By feeding back community structure changes and information flow patterns to the detection algorithm, the system can dynamically identify when normal collaboration transitions to influence-based sharing, reducing false positives while catching actual threats.
3Reliability
If corrective actions are taken against identified insiders, then individual threats are mitigated, but a large unknown attack surface remains from individuals already influenced by insiders
Solution Approach 1:
The patent applies preliminary action by proactively identifying individuals who are susceptible to insider influence before they are actually compromised. By detecting community structures and influence patterns in advance, the system can implement preventive measures against potentially influenced users, reducing the effective attack surface before threats materialize.
Solution Approach 2:
The system segments the enterprise network into communities and identifies influence boundaries. This segmentation allows targeted mitigation strategies that focus on high-risk communities and individuals, rather than applying blanket restrictions across the entire enterprise, thereby reducing the effective attack surface while maintaining operational efficiency.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
This disclosure relates generally to system and method for assessing insider influence on enterprise assets. Existing work focuses on the detection of insider threat and does not consider the influence of an insider on their peers and subordinates. The present disclosure aggregates and preprocesses the enterprise data specific to the individuals received from various sources, and further creates an enterprise graph between entities. Weights of every edge connected between any two entities in the enterprise graph is then calculated. Community of the individuals are detected wherein, relevant insider(s) are identified, and susceptibility of the individuals for probable influence by relevant insider(s) based on the analysis scenarios(s) is calculated. Paths taken by the relevant insider(s) is calculated for estimating probability of data loss. The present disclosure identifies the assets which are under possible threat from the relevant insider(s), obtains cumulative risk associated with the enterprise and generates an analysis report accordingly.