Insider Threat Detection via Collaboration Graph Anomaly Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security operations centers face challenges in timely detection of insider threats due to the large number of users with extensive access to networks, making it difficult to manually identify anomalous behavior and defend against potential security threats.
Innovation Solution
A computer-implemented method that generates collaboration graphs to analyze access patterns of target users, compares them to average patterns, and performs security actions when anomalies are detected, such as blocking access or preventing data transmission, to automatically detect and mitigate insider threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual detection methods are used by SOC network administrators, then detection accuracy can be maintained through human analysis, but the detection speed and timeliness deteriorate due to the large number of users and extensive network access
Solution Approach 1:
The patent replaces manual mechanical analysis by network administrators with an automated computer-implemented system that uses collaboration graphs and anomaly scoring to detect insider threats, thereby maintaining detection accuracy while dramatically improving speed and timeliness
Solution Approach 2:
The patent creates collaboration graphs that copy and represent user access patterns, allowing the system to analyze and compare behavioral patterns automatically without requiring manual review of each user's activity, thus resolving the contradiction between accurate detection and timely response
2Productivity
If extensive access is granted to users for operational efficiency, then productivity is improved, but security vulnerability increases due to potential insider threats
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors user collaboration patterns, generates anomaly scores, and triggers security actions when thresholds are exceeded, allowing the organization to maintain extensive user access while automatically detecting and responding to insider threats that could exploit such access
3Loss of time
If automated detection systems are implemented, then detection speed and timeliness are improved, but system complexity increases due to collaboration graphs and anomaly scoring
Solution Approach 1:
The patent creates a multi-functional system where the collaboration graph technology serves multiple purposes: modeling user behavior, detecting anomalies, identifying insider threats, and triggering security actions, thereby justifying the increased system complexity through its broad applicability and effectiveness in resolving the timeliness problem
Data Source
AI summary
Automatically detecting insider threats using user collaboration patterns. In one embodiment, a method may include identifying collaborative access of one or more network resources in a network between a target user using a target network device and other users using other network devices in the network during multiple prior time periods and during a current time period, generating prior collaboration graphs for the prior time periods, generating an average collaboration graph by combining the prior collaboration graphs, generating a current collaboration graph for the current time period, generating an anomaly score by comparing the current collaboration graph to the average collaboration graph, determining that the collaborative access of the one or more network resources during the current time period is anomalous by determining that the anomaly score exceeds a threshold, and, in response to the anomaly score exceeding the threshold, performing a security action on the target network device.


