Insider Threat Detection via Network Connectivity Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems struggle to detect insider threats effectively, as they are designed to address external threats and lack the capability to monitor human-driven malicious behavior within internal networks, where traffic volume and complexity hinder anomaly detection.
Innovation Solution
An insider threat detection system that constructs a connectivity graph from metadata describing internal network communications to identify clusters of hosts (communities) and establish baseline behavior patterns, allowing for real-time detection of abnormal behavior without the need for monitoring software on each host.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If perimeter solutions (firewalls or Intrusion Prevention Systems) are deployed to detect threats, then external threats can be blocked, but insider threats occurring inside the network cannot be detected
Solution Approach 1:
The patent transitions from perimeter-based detection (external boundary) to internal network behavior analysis by constructing connectivity graphs that map relationships between hosts. This dimensional shift enables detection of insider threats by analyzing communication patterns within the network rather than focusing solely on external boundaries.
Solution Approach 2:
The patent introduces connectivity graphs as an intermediary structure that mediates between raw network traffic data and threat detection. These graphs capture host relationships and behavioral patterns, serving as a bridge that enables comprehensive insider threat detection without requiring direct monitoring of all internal communications.
2Measurement precision
If sensors are installed on individual hosts to monitor malicious behavior, then detection accuracy improves, but system complexity and cost increase significantly
Solution Approach 1:
The patent extracts essential behavioral characteristics from individual host activities and consolidates them into connectivity graphs. Instead of monitoring every detail on each host, the system extracts key connectivity and communication patterns, significantly reducing complexity while maintaining detection effectiveness.
Solution Approach 2:
The patent merges individual host monitoring requirements into a unified connectivity graph framework. By combining data from multiple hosts into relationship graphs and communities, the system achieves comprehensive monitoring without the complexity of deploying and maintaining separate sensors on each host.
3Ease of manufacture
If pre-programmed rules or heuristics are used to detect known scenarios, then implementation is straightforward, but the system cannot detect novel or unknown threats
Solution Approach 1:
The patent implements dynamic baseline behavior profiles that automatically adapt to changing network conditions and host behaviors. Instead of static pre-programmed rules, the system continuously learns normal behavior patterns and adjusts detection thresholds, enabling detection of both known and novel threats while maintaining ease of deployment.
Solution Approach 2:
The patent changes the detection parameters from fixed rule-based thresholds to dynamic behavioral baselines derived from connectivity graphs. By measuring deviations from learned normal behavior patterns rather than checking against static rules, the system achieves both ease of implementation and adaptability to new threat types.
4Adaptability or versatility
If broad rights are granted to internal hosts for operational flexibility, then network functionality improves, but detection of anomalous and malicious behavior becomes much harder
Solution Approach 1:
The patent implements feedback mechanisms where connectivity graphs continuously monitor host behaviors and compare them against established baseline patterns. This feedback loop enables the system to distinguish between legitimate operational variations (due to broad host rights) and truly anomalous malicious behaviors, maintaining both operational flexibility and detection capability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system for identifying insider threats within an organization is provided. The approach constructs an internal connectivity graph to identify communities of hosts/users, and checks for abnormal behavior relative to past behaviors.