Insider Threat Detection via Collaboration Graph Anomaly Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security operations centers face challenges in timely detection of insider threats due to the large number of users with extensive access to networks, making it difficult to manually identify anomalous behavior and defend against potential security threats.

Innovation Solution

A computer-implemented method that generates collaboration graphs to analyze access patterns of target users, compares them to average patterns, and performs security actions when anomalies are detected, such as blocking access or preventing data transmission, to automatically detect and mitigate insider threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual detection methods are used by SOC network administrators, then detection accuracy can be maintained through human analysis, but the detection speed and timeliness deteriorate due to the large number of users and extensive network access

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection timeliness
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis by network administrators with an automated computer-implemented system that uses collaboration graphs and anomaly scoring to detect insider threats, thereby maintaining detection accuracy while dramatically improving speed and timeliness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates collaboration graphs that copy and represent user access patterns, allowing the system to analyze and compare behavioral patterns automatically without requiring manual review of each user's activity, thus resolving the contradiction between accurate detection and timely response

Inventive Principle:
Principle #26Copying

2Productivity

If extensive access is granted to users for operational efficiency, then productivity is improved, but security vulnerability increases due to potential insider threats

Engineering Contradiction:
Improveoperational efficiencyVSAvoidnetwork vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors user collaboration patterns, generates anomaly scores, and triggers security actions when thresholds are exceeded, allowing the organization to maintain extensive user access while automatically detecting and responding to insider threats that could exploit such access

Inventive Principle:
Principle #23Feedback

3Loss of time

If automated detection systems are implemented, then detection speed and timeliness are improved, but system complexity increases due to collaboration graphs and anomaly scoring

Engineering Contradiction:
Improvedetection timelinessVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent creates a multi-functional system where the collaboration graph technology serves multiple purposes: modeling user behavior, detecting anomalies, identifying insider threats, and triggering security actions, thereby justifying the increased system complexity through its broad applicability and effectiveness in resolving the timeliness problem

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10341373B2Automatically detecting insider threats using user collaboration patterns
Publication Date: 2019.07.02 CA TECH INC
  • US10341373B2 patent drawing
  • US10341373B2 patent drawing
  • US10341373B2 patent drawing

AI summary

Automatically detecting insider threats using user collaboration patterns. In one embodiment, a method may include identifying collaborative access of one or more network resources in a network between a target user using a target network device and other users using other network devices in the network during multiple prior time periods and during a current time period, generating prior collaboration graphs for the prior time periods, generating an average collaboration graph by combining the prior collaboration graphs, generating a current collaboration graph for the current time period, generating an anomaly score by comparing the current collaboration graph to the average collaboration graph, determining that the collaborative access of the one or more network resources during the current time period is anomalous by determining that the anomaly score exceeds a threshold, and, in response to the anomaly score exceeding the threshold, performing a security action on the target network device.