Entitlement-Specific ML for Anomalous User Behavior Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Role-Based Access Control (RBAC) systems face scaling limitations and complexity in large organizations, making it inefficient to manually review thousands of user access instances for anomalies, which increases cybersecurity risks and compliance challenges.
Innovation Solution
Implementing a data-driven infrastructure with a computer-implemented method that uses an entitlement-specific machine learning algorithm to automatically detect anomalous user behavior by analyzing session data, generating an anomaly score, and updating the algorithm based on manager reviews, while also identifying repeatable tasks for automation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual review of access instances is implemented, then security monitoring capability is improved, but labor burden and time consumption increase significantly
Solution Approach 1:
The patent replaces the manual mechanical review process with an automated machine learning system. The ML model analyzes access patterns, user behavior, and session data to automatically detect anomalies, substituting human reviewers with an automated computational system that processes data at machine speed without manual intervention.
Solution Approach 2:
The system enables self-service security monitoring where the ML model continuously learns from historical data and automatically adapts to detect anomalies without requiring manual configuration or review. The system serves itself by automatically updating its understanding of normal vs. anomalous behavior patterns.
2Adaptability or versatility
If RBAC system is scaled to large organizations, then access management coverage is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal ML-based anomaly detection framework that works across diverse technology assets, user roles, and organizational structures. Rather than requiring separate RBAC configurations for each asset or role, the system provides a unified layer of security monitoring that adapts to various contexts through machine learning, reducing the complexity of managing access control across large organizations.
3Measurement precision
If human review of every access instance is required, then security detection accuracy is improved, but productivity decreases
Solution Approach 1:
The patent applies partial action by using the ML model to pre-filter and prioritize access instances, focusing human review only on high-risk anomalies rather than requiring review of every access instance. The system performs excessive analysis computationally to reduce the need for excessive human review, achieving both accuracy and throughput by intelligently selecting what requires human attention.
Data Source
AI summary
Systems and methods for data-driven infrastructure controls are disclosed. According to one embodiment, in an information processing apparatus comprising at least one computer processor, a computer-implemented method for automatically detecting anomalous user behavior within a unified entitlement framework may include: (1) receiving an access request for a technology asset from a user on a computing device, the access request comprising session data comprising one or more of user identification, user location, key strokes, and user computing device identification; (2) applying an entitlement-specific machine learning algorithm to the session data to generate an anomaly score; (3) storing the session data and associated anomaly score; (4) sending a review request to a manager; (5) receiving review results from the manager; and (6) updating the entitlement-specific machine learning algorithm based on the anomaly score and the review results from the manager.


