Entitlement-Specific ML for Anomalous User Behavior Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Role-Based Access Control (RBAC) systems face scaling limitations and complexity in large organizations, making it inefficient to manually review thousands of user access instances for anomalies, which increases cybersecurity risks and compliance challenges.

Innovation Solution

Implementing a data-driven infrastructure with a computer-implemented method that uses an entitlement-specific machine learning algorithm to automatically detect anomalous user behavior by analyzing session data, generating an anomaly score, and updating the algorithm based on manager reviews, while also identifying repeatable tasks for automation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review of access instances is implemented, then security monitoring capability is improved, but labor burden and time consumption increase significantly

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidtime for reviewing access instances
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical review process with an automated machine learning system. The ML model analyzes access patterns, user behavior, and session data to automatically detect anomalies, substituting human reviewers with an automated computational system that processes data at machine speed without manual intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service security monitoring where the ML model continuously learns from historical data and automatically adapts to detect anomalies without requiring manual configuration or review. The system serves itself by automatically updating its understanding of normal vs. anomalous behavior patterns.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If RBAC system is scaled to large organizations, then access management coverage is improved, but system complexity increases

Engineering Contradiction:
Improveaccess management coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal ML-based anomaly detection framework that works across diverse technology assets, user roles, and organizational structures. Rather than requiring separate RBAC configurations for each asset or role, the system provides a unified layer of security monitoring that adapts to various contexts through machine learning, reducing the complexity of managing access control across large organizations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If human review of every access instance is required, then security detection accuracy is improved, but productivity decreases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidaccess review throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial action by using the ML model to pre-filter and prioritize access instances, focusing human review only on high-risk anomalies rather than requiring review of every access instance. The system performs excessive analysis computationally to reduce the need for excessive human review, achieving both accuracy and throughput by intelligently selecting what requires human attention.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11546362B2Systems and methods for data-driven infrastructure controls
Publication Date: 2023.01.03 JPMORGAN CHASE BANK NA
  • US11546362B2 patent drawing
  • US11546362B2 patent drawing
  • US11546362B2 patent drawing

AI summary

Systems and methods for data-driven infrastructure controls are disclosed. According to one embodiment, in an information processing apparatus comprising at least one computer processor, a computer-implemented method for automatically detecting anomalous user behavior within a unified entitlement framework may include: (1) receiving an access request for a technology asset from a user on a computing device, the access request comprising session data comprising one or more of user identification, user location, key strokes, and user computing device identification; (2) applying an entitlement-specific machine learning algorithm to the session data to generate an anomaly score; (3) storing the session data and associated anomaly score; (4) sending a review request to a manager; (5) receiving review results from the manager; and (6) updating the entitlement-specific machine learning algorithm based on the anomaly score and the review results from the manager.