Group Analysis for Proactive Suspicious Account Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional attack detection systems are reactive, often detecting malicious accounts after damage is done, and struggle to identify large-scale, coordinated attacks due to their isolated examination of events and reliance on manual rule creation, missing stealthy and incubating malicious activities.

Innovation Solution

A group-analysis method that clusters accounts or events based on similarity and compares them to a global profile, using big data analytics to automatically detect suspicious accounts and activities, and generate risk models for real-time or batch analysis, enabling proactive detection of malicious accounts and activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional attack detection systems examine events in isolation and rely on manual rule creation, then individual malicious accounts can be detected, but large-scale coordinated attacks and stealthy malicious activities cannot be effectively identified

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect coordinated attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple isolated event examinations into a unified group analysis framework. Events from multiple accounts are grouped together based on similarity metrics, allowing the system to detect coordinated attacks by analyzing patterns across groups rather than examining individual events in isolation. This merging approach enables detection of stealthy malicious activities that would be invisible when looking at single accounts separately.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a universal detection framework that handles both individual account detection and large-scale coordinated attack detection through the same group analysis mechanism. The automated grouping and profiling system provides multi-functionality by adapting to different attack patterns and scales, replacing the need for separate manual rule creation for different attack types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If reactive detection methods are used to identify malicious accounts after damage is done, then confirmed threats can be blocked, but proactive detection of incubating malicious activities is not achieved

Engineering Contradiction:
Improvethreat confirmation accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by continuously grouping and profiling accounts in advance, building suspicion scores and risk models before malicious activities cause significant damage. This preliminary grouping action allows the system to detect and respond to incubating malicious activities proactively, rather than waiting for confirmation of damage before taking action.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where detection results and group profiles are continuously refined based on new data. As more events are analyzed, the grouping and profiling feedback loop improves detection accuracy over time, allowing the system to become more reliable in proactive detection while reducing response time through learned patterns.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If manual rule creation is used for attack detection, then detection logic can be customized, but automation and scalability are limited

Engineering Contradiction:
Improvedetection rule flexibilityVSAvoiddetection process automation
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The system provides self-service automation by automatically creating detection rules through machine learning from grouped event patterns. Instead of requiring manual rule creation, the system serves itself by learning detection patterns from data, automatically generating and refining detection logic. This maintains adaptability to new attack types while achieving full automation and scalability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes detection parameters based on learned patterns from group analysis. Rather than using fixed manual rules, the system adapts detection thresholds, grouping criteria, and profiling parameters automatically based on the data it processes, enabling both flexibility and automation simultaneously through parameter optimization.

Inventive Principle:
Principle #35Parameter changes

4Use of energy by moving object

If isolated examination of individual accounts is performed, then resource requirements are low, but the ability to detect coordinated attacks controlled by the same attackers is reduced

Engineering Contradiction:
Improvecomputational resourcesVSAvoidcoordinated attack detection capability
Core Design Contradiction:
Use of energy by moving objectVSAdaptability or versatility

Solution Approach 1:

The system segments the large-scale detection problem into manageable account groups based on similarity metrics. By dividing the overall population into smaller groups that share common characteristics, the system can analyze coordinated attacks at a scalable level, examining groups rather than individually analyzing every account while maintaining low computational overhead through efficient grouping strategies.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10110616B1Using group analysis to determine suspicious accounts or activities
Publication Date: 2018.10.23 DATAVISOR INC
  • US10110616B1 patent drawing
  • US10110616B1 patent drawing
  • US10110616B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for detecting suspicious users. One of the methods includes obtaining a collection of event logs or event feeds associated with a plurality of users to generate a collection of user properties; using the user properties to generate a plurality of groups of events; determining whether one or more groups are suspicious groups; and in response to a determination that one or more groups are suspicious, determining whether there are malicious accounts or events associated with each suspicious group.