Identity Access Management via Behavioral Network Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for network security, such as login names, passwords, digital certificates, and IP addresses, are inadequate in preventing unauthorized access and spoofing, lacking a robust mechanism for identity verification and access management.

Innovation Solution

A system and method for identity and access management that utilizes behavioral network analysis and correlation to dynamically adjust access rules, generating alerts and predicting future unauthorized access attempts, without relying on host agents or centralized authentication appliances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods such as login names, passwords, and digital certificates are used for access management, then basic authentication is provided, but security against spoofing and remote theft is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control by continuously monitoring network traffic patterns and user behavior characteristics in real-time. The system adapts security parameters dynamically based on observed behavioral patterns, transitioning from static authentication to dynamic verification that adjusts to current threat levels and user anomalies.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces traditional mechanical authentication systems (passwords, certificates, IP verification) with a behavioral analysis system that uses network traffic pattern recognition. Instead of relying on static credentials that can be stolen or spoofed, the system substitutes a continuous behavioral monitoring mechanism that analyzes communication patterns, timing, and data flow characteristics.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If IP addresses and geo-location services are used to verify user identity, then basic location-based authentication is provided, but the system is vulnerable to spoofing techniques

Engineering Contradiction:
Improveuser identity verificationVSAvoidspoofing vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback loops where network traffic patterns are monitored, analyzed, and used to adjust security decisions in real-time. The system receives feedback from behavioral analysis and dynamically modifies access control parameters, creating a closed-loop security system that continuously learns and adapts to new threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces behavioral pattern analysis as an intermediary layer between the network and access control decisions. Instead of directly trusting IP addresses or geo-location data, the system uses behavioral intermediaries that analyze traffic patterns, timing characteristics, and communication behaviors to verify genuine user identity while blocking spoofed requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If static access rules are implemented for network security zones, then basic access control is provided, but the system cannot adapt to future unauthorized access attempts

Engineering Contradiction:
Improveaccess control adaptabilityVSAvoidresponse time to threats
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary behavioral analysis and pattern recognition to identify potential security threats before they materialize into successful attacks. By continuously monitoring and analyzing network traffic patterns, the system detects anomalous behaviors and prepares preventive measures in advance, blocking potential threats before they can compromise the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service security where the system automatically monitors, analyzes, and responds to security threats without requiring constant human intervention. The behavioral analysis system autonomously adjusts access control rules, generates alerts, and prevents unauthorized access attempts by learning from observed patterns and making real-time security decisions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9338176B2Systems and methods of identity and access management
Publication Date: 2016.05.10 MASERGY COMMUNICATIONS INC
  • US9338176B2 patent drawing
  • US9338176B2 patent drawing
  • US9338176B2 patent drawing

AI summary

The present disclosure generally provides systems and methods of providing identification and access management. The system could include a network security zone having access rules for a network resource object associated with the network. The system could also include a module to collect information related to an attempt to access the network resource object and to generate an alert if the collected information fails to meet certain requirements related to the access rules. The module could change the access rules to prevent possible future unauthorized access attempts based on the collected information.