Group Analysis for Proactive Suspicious Account Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional attack detection systems are reactive, often detecting malicious accounts after damage is done, and struggle to identify large-scale, coordinated attacks due to their isolated examination of events and reliance on manual rule creation, missing stealthy and incubating malicious activities.
Innovation Solution
A group-analysis method that clusters accounts or events based on similarity and compares them to a global profile, using big data analytics to automatically detect suspicious accounts and activities, and generate risk models for real-time or batch analysis, enabling proactive detection of malicious accounts and activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional attack detection systems examine events in isolation and rely on manual rule creation, then individual malicious accounts can be detected, but large-scale coordinated attacks and stealthy malicious activities cannot be effectively identified
Solution Approach 1:
The patent combines multiple isolated event examinations into a unified group analysis framework. Events from multiple accounts are grouped together based on similarity metrics, allowing the system to detect coordinated attacks by analyzing patterns across groups rather than examining individual events in isolation. This merging approach enables detection of stealthy malicious activities that would be invisible when looking at single accounts separately.
Solution Approach 2:
The system creates a universal detection framework that handles both individual account detection and large-scale coordinated attack detection through the same group analysis mechanism. The automated grouping and profiling system provides multi-functionality by adapting to different attack patterns and scales, replacing the need for separate manual rule creation for different attack types.
2Reliability
If reactive detection methods are used to identify malicious accounts after damage is done, then confirmed threats can be blocked, but proactive detection of incubating malicious activities is not achieved
Solution Approach 1:
The system performs preliminary analysis by continuously grouping and profiling accounts in advance, building suspicion scores and risk models before malicious activities cause significant damage. This preliminary grouping action allows the system to detect and respond to incubating malicious activities proactively, rather than waiting for confirmation of damage before taking action.
Solution Approach 2:
The system implements feedback mechanisms where detection results and group profiles are continuously refined based on new data. As more events are analyzed, the grouping and profiling feedback loop improves detection accuracy over time, allowing the system to become more reliable in proactive detection while reducing response time through learned patterns.
3Adaptability or versatility
If manual rule creation is used for attack detection, then detection logic can be customized, but automation and scalability are limited
Solution Approach 1:
The system provides self-service automation by automatically creating detection rules through machine learning from grouped event patterns. Instead of requiring manual rule creation, the system serves itself by learning detection patterns from data, automatically generating and refining detection logic. This maintains adaptability to new attack types while achieving full automation and scalability.
Solution Approach 2:
The system dynamically changes detection parameters based on learned patterns from group analysis. Rather than using fixed manual rules, the system adapts detection thresholds, grouping criteria, and profiling parameters automatically based on the data it processes, enabling both flexibility and automation simultaneously through parameter optimization.
4Use of energy by moving object
If isolated examination of individual accounts is performed, then resource requirements are low, but the ability to detect coordinated attacks controlled by the same attackers is reduced
Solution Approach 1:
The system segments the large-scale detection problem into manageable account groups based on similarity metrics. By dividing the overall population into smaller groups that share common characteristics, the system can analyze coordinated attacks at a scalable level, examining groups rather than individually analyzing every account while maintaining low computational overhead through efficient grouping strategies.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for detecting suspicious users. One of the methods includes obtaining a collection of event logs or event feeds associated with a plurality of users to generate a collection of user properties; using the user properties to generate a plurality of groups of events; determining whether one or more groups are suspicious groups; and in response to a determination that one or more groups are suspicious, determining whether there are malicious accounts or events associated with each suspicious group.


