Insider Threat Detection via Access Behavior Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in detecting insider attacks in distributed environments, particularly in cloud-based systems, where vulnerabilities may go unnoticed, leading to potential widespread damage due to the trust placed in employees and automated programs.

Innovation Solution

An insider threat detection system (ITDS) that utilizes metadata repositories, including suspect behavior templates, legitimate access paths, and entity profiles, to analyze activity logs and identify potential security threats through a multi-level analysis, enabling early detection and responsive actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (virus scanning, password enforcement) are deployed, then basic security coverage is improved, but detection capability for insider attacks remains insufficient

Engineering Contradiction:
Improvebasic security coverageVSAvoidinsider attack detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the detection system into multiple specialized components: entity profile analysis, behavior template matching, access path validation, and risk scoring. Each component handles a specific aspect of insider threat detection, allowing the system to overcome the limitations of traditional monolithic security approaches while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by establishing entity profiles and behavior baselines before attacks occur. It proactively defines suspect behavior templates and legitimate access paths in advance, enabling the detection system to identify deviations from normal behavior patterns rather than merely reacting to known threats.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If multi-level analysis with multiple metadata repositories is implemented, then insider threat detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal framework where a single detection system performs multiple functions: entity profiling, behavior analysis, access path validation, and threat scoring. The metadata repositories serve multiple purposes - entity profiles provide both authentication context and behavioral baselines, while behavior templates serve both detection and validation functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces intermediary components that bridge complexity and usability: a unified detection engine coordinates multiple metadata repositories, and a risk scoring mechanism translates complex analysis results into actionable threat assessments. These intermediaries manage the complexity of multi-repository analysis while providing simplified outputs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive behavior analysis is performed on all entities, then detection coverage is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection coverageVSAvoidanalysis processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing analysis on entities and behaviors that deviate from established norms. Instead of uniformly analyzing all entity activities, the system identifies suspicious patterns first and then performs detailed analysis only on those cases, reducing overall processing time while maintaining detection coverage for critical threats.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary anti-action by pre-computing entity profiles, behavior baselines, and access path validations during low-utilization periods. This allows the detection engine to quickly compare real-time activities against pre-analyzed data, reducing real-time processing requirements while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11651313B1Insider threat detection using access behavior analysis
Publication Date: 2023.05.16 AMAZON TECH INC
  • US11651313B1 patent drawing
  • US11651313B1 patent drawing
  • US11651313B1 patent drawing

AI summary

A security threat candidate (STC) detector examines a set of activity log records representing access requests directed to data artifacts by various entities of an organization. In a first threat analysis, the STC detector determines that an activity log record indicates a use of an access path which is not present in a database of legitimate access paths for an entity. In a second threat analysis, the STC detector determines whether the behavior of the entity matches a stored suspect behavior pattern template. Results of the first and/or second analysis are transmitted to a selected security management component of the organization.