Insider Threat Detection Platform Using Behavioral Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions inadequately address insider fraud threats within enterprises, as they primarily focus on external threats and lack comprehensive tools to detect and manage internal risks effectively, often resulting in limited context for complex data types and susceptibility to evasive tricks.

Innovation Solution

A computer-implemented method and system that identifies insider threat detection rules, obtains behavioral data from various sources, determines a threat score, and initiates protective actions when the score meets a threshold, utilizing a combination of behavioral data sources and customizable threat detection rules to monitor and limit insider access and investigate potential fraud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security solutions (DLP, content filtering, IAM) are used to detect insider fraud, then specific threats can be blocked, but comprehensive protection against complex insider fraud is lost due to limited context and inability to detect evasive tricks

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomprehensive protection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple previously separate security functions (user behavior analytics, data loss prevention, identity and access management, content filtering) into a unified insider threat detection platform. This integration allows the system to correlate data across all these functions, providing comprehensive protection while maintaining high detection accuracy through centralized analysis.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The insider threat detection platform is designed as a universal system that can detect multiple types of insider fraud (data theft, intellectual property misappropriation, customer information leakage) using a single integrated architecture. The system adapts to different fraud scenarios through configurable detection rules and machine learning models, providing versatile protection without requiring separate specialized tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate security tools (DLP, IAM, content filtering) are deployed to address different threats, then specific security gaps can be filled, but system complexity increases and integrated risk management is lost

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent consolidates multiple security tools into a single insider threat detection platform that integrates user behavior analytics, data loss prevention, identity and access management, and content filtering capabilities. This merger maintains comprehensive security coverage while reducing integration complexity by providing a unified architecture with centralized data collection and analysis.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

While integrating multiple security functions, the system segments the detection process into distinct modules (data collection, behavior analysis, threat detection, response actions) that can be independently configured and maintained. This modular segmentation allows comprehensive security coverage without overwhelming system complexity, as each module handles specific security aspects.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If existing security technologies are carefully configured to detect suspicious behavior, then false positives can be reduced, but the system requires specialized expertise and complex tuning

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem configuration ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The insider threat detection platform incorporates automated machine learning models that continuously analyze user behavior patterns and automatically adjust detection thresholds and rules. This self-service capability maintains high detection precision while reducing the need for specialized manual configuration and tuning, as the system adapts automatically to emerging fraud patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where detection results, false positives, and investigator actions are continuously fed back into the machine learning models. This feedback mechanism refines detection precision over time while simplifying operation, as the system learns from actual performance data rather than requiring manual recalibration by experts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8868728B2Systems and methods for detecting and investigating insider fraud
Publication Date: 2014.10.21 ACCENTURE GLOBAL SERVICES LTD
  • US8868728B2 patent drawing
  • US8868728B2 patent drawing
  • US8868728B2 patent drawing

AI summary

Systems, methods, and apparatus, including computer programs encoded on computer storage media, for detecting insider fraud. One method includes identifying one or more insider threat detection rules for an enterprise and obtaining behavioral data for an enterprise insider from multiple behavioral data sources. The enterprise is associated with a plurality of enterprise insiders, and the behavioral data describes at least one action of the first enterprise insider. The method further includes determining a threat score for the first enterprise insider based on the behavioral data for the first enterprise insider and one or more of the insider threat detection rules and initiating, when the threat score satisfies a threat threshold, one or more protective actions.