Human Non-Human Interaction Detection Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems lack effective methods to distinguish between human and non-human interactions with computing devices, relying on hard-coded signatures or rules, which can lead to misclassification and inadequate threat detection.

Innovation Solution

A method and system that utilize a presence estimation model to determine the probability of human or non-human interactions based on computer metadata, applying risk threat detectors and generating a human/non-human presence estimation model through supervised, unsupervised, or semi-supervised training to differentiate between human and non-human agent interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If hard-coded signatures or rules are used to distinguish human and non-human interactions, then the system is simpler to implement, but the accuracy and reliability of threat detection deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidthreat detection accuracy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transforms the detection approach by changing from static hard-coded signatures to dynamic machine learning models that continuously learn from data. The system trains models on features such as timing patterns, interaction sequences, and behavioral characteristics to accurately distinguish human from non-human interactions, thereby improving detection accuracy while maintaining manageable system complexity through automated learning processes.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical approach of hard-coded rules with an intelligent system using machine learning algorithms. The machine learning models process and analyze interaction patterns automatically, substituting the need for manual rule creation and maintenance with automated computational processes that adapt to evolving threat landscapes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If all interactive logins are assumed to be from humans, then the system operates with simpler assumptions, but the ability to detect non-human actors deteriorates

Engineering Contradiction:
Improvesystem operation simplicityVSAvoidhuman vs non-human distinction accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors interaction patterns and uses this information to refine machine learning models. The models learn from actual interaction data, adjusting their classifications of human versus non-human actors based on observed behaviors, timing patterns, and interaction sequences, thereby improving measurement precision through continuous learning.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by automatically training and refining its own detection models using real-world interaction data. The machine learning algorithms process logins, authentication events, and interaction patterns independently, enabling the system to improve its own accuracy without requiring manual intervention or complex external processing.

Inventive Principle:
Principle #25Self-service

3Productivity

If no distinction is made between human and non-human events, then the system maintains simpler processing, but the signal-to-noise ratio in security analysis deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsignal-to-noise ratio
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent extracts and separates human interactions from non-human interactions using machine learning classification. By identifying and isolating non-human patterns (such as automated scripts, bots, or compromised accounts), the system can focus security analysis resources on genuine human behavior, thereby improving the signal-to-noise ratio while maintaining processing efficiency through targeted analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments security events into distinct categories of human and non-human interactions based on learned patterns. This segmentation allows the system to process and analyze different types of events with appropriate methods, improving the signal-to-noise ratio by separating meaningful security-relevant human actions from automated or suspicious non-human activities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10868823B2Systems and methods for discriminating between human and non-human interactions with computing devices on a computer network
Publication Date: 2020.12.15 INTERSET SOFTWARE
  • US10868823B2 patent drawing
  • US10868823B2 patent drawing
  • US10868823B2 patent drawing

AI summary

Humans as well as non-human actors may interact with computer devices on a computer network. As described herein, it is possible to train and apply human vs. non-human detection models to provide an indication of the probability that a human or a non-human actor was interacting with a computer device during a particular time period. The probability that a human or non-human was interacting with computers during a particular time may be used to improve various actions, including selecting one or more different threat detection models to apply during the particular time, selecting data to use with threat detection models during the time, or selecting data from the particular time to store.