Insider Threat Detection via Network Connectivity Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems struggle to detect insider threats effectively, as they are designed to address external threats and lack the capability to monitor human-driven malicious behavior within internal networks, where traffic volume and complexity hinder anomaly detection.

Innovation Solution

An insider threat detection system that constructs a connectivity graph from metadata describing internal network communications to identify clusters of hosts (communities) and establish baseline behavior patterns, allowing for real-time detection of abnormal behavior without the need for monitoring software on each host.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter solutions (firewalls or Intrusion Prevention Systems) are deployed to detect threats, then external threats can be blocked, but insider threats occurring inside the network cannot be detected

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddetection scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from perimeter-based detection (external boundary) to internal network behavior analysis by constructing connectivity graphs that map relationships between hosts. This dimensional shift enables detection of insider threats by analyzing communication patterns within the network rather than focusing solely on external boundaries.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces connectivity graphs as an intermediary structure that mediates between raw network traffic data and threat detection. These graphs capture host relationships and behavioral patterns, serving as a bridge that enables comprehensive insider threat detection without requiring direct monitoring of all internal communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If sensors are installed on individual hosts to monitor malicious behavior, then detection accuracy improves, but system complexity and cost increase significantly

Engineering Contradiction:
Improvebehavior detection accuracyVSAvoidmonitoring infrastructure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts essential behavioral characteristics from individual host activities and consolidates them into connectivity graphs. Instead of monitoring every detail on each host, the system extracts key connectivity and communication patterns, significantly reducing complexity while maintaining detection effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges individual host monitoring requirements into a unified connectivity graph framework. By combining data from multiple hosts into relationship graphs and communities, the system achieves comprehensive monitoring without the complexity of deploying and maintaining separate sensors on each host.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of manufacture

If pre-programmed rules or heuristics are used to detect known scenarios, then implementation is straightforward, but the system cannot detect novel or unknown threats

Engineering Contradiction:
Improvesystem implementationVSAvoidthreat detection coverage
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic baseline behavior profiles that automatically adapt to changing network conditions and host behaviors. Instead of static pre-programmed rules, the system continuously learns normal behavior patterns and adjusts detection thresholds, enabling detection of both known and novel threats while maintaining ease of deployment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection parameters from fixed rule-based thresholds to dynamic behavioral baselines derived from connectivity graphs. By measuring deviations from learned normal behavior patterns rather than checking against static rules, the system achieves both ease of implementation and adaptability to new threat types.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If broad rights are granted to internal hosts for operational flexibility, then network functionality improves, but detection of anomalous and malicious behavior becomes much harder

Engineering Contradiction:
Improvenetwork operational flexibilityVSAvoidanomaly detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where connectivity graphs continuously monitor host behaviors and compare them against established baseline patterns. This feedback loop enables the system to distinguish between legitimate operational variations (due to broad host rights) and truly anomalous malicious behaviors, maintaining both operational flexibility and detection capability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3215944B1A system for implementing threat detection using daily network traffic community outliers
Publication Date: 2021.07.07 VECTRA NETWORKS
  • EP3215944B1 patent drawingFigure 1
  • EP3215944B1 patent drawingFigure 2
  • EP3215944B1 patent drawingFigure 3

AI summary

A method and system for identifying insider threats within an organization is provided. The approach constructs an internal connectivity graph to identify communities of hosts/users, and checks for abnormal behavior relative to past behaviors.