Graph-Based Authentication Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for detecting network intrusions in enterprise computer networks are inadequate for identifying advanced adversaries using zero-day exploits and stealthy procedures, as they rely on signatures of known-bad events and rudimentary behavioral analytics, leading to high false positives and delayed detection.
Innovation Solution
A graph data model is constructed using authentication logs to detect anomalous authentication events through unsupervised node embedding and link prediction, identifying low-probability links indicative of malicious lateral movement by authenticating entities within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature-based intrusion detection is used, then detection of known malware is improved, but detection of zero-day exploits and novel malware deteriorates
Solution Approach 1:
The patent transforms authentication log data from traditional tabular formats into graph-structured data, where nodes represent authenticating entities (users, machines, services) and edges represent authentication events. This structural parameter change enables the system to capture relational patterns and contextual information that signature-based methods miss, allowing detection of novel lateral movement techniques without relying on known malware signatures.
Solution Approach 2:
The invention adds a dimensional transformation by representing authentication data as graphs with multiple node types and edge attributes, creating a multi-dimensional view of authentication behavior. This dimensional enrichment allows the system to analyze patterns across different entity types and relationships simultaneously, improving detection of sophisticated attacks that operate across multiple dimensions of the network.
2Reliability
If rudimentary behavioral analytics are used, then detection of abnormal network activity is improved, but false positive rate increases
Solution Approach 1:
The patent segments the authentication graph into different node types (users, machines, services) and edge types (authentication events with various attributes). This segmentation allows the system to apply type-specific analysis and understand the contextual meaning of different authentication patterns, reducing false positives by distinguishing between legitimate and malicious behavior based on entity relationships rather than generic statistical anomalies.
Solution Approach 2:
The graph structure acts as an intermediary that transforms raw authentication logs into meaningful relational patterns. The graph model mediates between the raw data and the detection algorithm, enabling the system to understand the contextual relationships between authenticating entities and reduce false positives by considering the broader authentication ecosystem rather than isolated events.
3Measurement precision
If traditional behavioral analytics are used, then detection of network anomalies is improved, but investigation complexity increases
Solution Approach 1:
By transforming authentication data into graph representations, the patent adds structural dimensions that make patterns more visually and analytically apparent. The graph structure organizes complex authentication relationships in a way that is easier to investigate and understand, allowing security analysts to trace authentication paths and identify lateral movement patterns more efficiently than with traditional tabular analytics.
Solution Approach 2:
The graph data model serves multiple functions simultaneously: it enables anomaly detection, provides investigative context, and captures relational patterns. This multi-functionality reduces investigation complexity by consolidating multiple analysis needs into a single unified representation that can be queried and visualized in various ways.
Data Source
AI summary
A system includes a log receiving module, an authentication graph module, a sampling module, an embedding module, a training module, a link prediction module, and an anomaly detection module. The log receiving module is configured to receive a first plurality of network-level authentication logs. The authentication graph module is configured to generate an authentication graph. The sampling module is configured to generate a plurality of sequences. The embedding module is configured to tune a plurality of node embeddings according to the plurality of sequences. The training module is configured to train a link predictor according to the plurality of node embeddings and ground-truth edge information from the authentication graph. The link prediction module is configured to apply the link predictor to performs a link prediction. The anomaly detection module is configured to perform anomaly detection according to the link prediction.


