Insider Threat Detection via User Behavior Vector Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current insider threat management systems face challenges in efficiently detecting and addressing insider user behavior threats within multitenant software as a service (SaaS) environments, as they often require significant infrastructure and resources to process and analyze large amounts of user activity data effectively.
Innovation Solution
A computer-implemented method and system that compares user behavior within a tenant to other users' behavior, generating a sampled activity matrix, clustering users based on similarity, assigning activity weights, and computing behavior vectors to identify deviations beyond a threshold, triggering notifications for potential threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional insider threat management systems process and analyze large amounts of user activity data, then detection accuracy is improved, but infrastructure complexity and operational cost increase
Solution Approach 1:
The system segments user activity data into activity-sets grouped by time windows, and further segments the analysis by creating separate sampled activity matrices for each user. This segmentation allows the system to process large amounts of data in manageable chunks, reducing infrastructure complexity while maintaining detection accuracy through localized analysis of user behaviors within specific time periods
Solution Approach 2:
The system applies partial action by sampling user activity data to create sampled activity matrices rather than processing all data at full resolution. This selective processing approach reduces the computational burden on infrastructure while still capturing sufficient behavioral patterns for accurate threat detection, avoiding the need for overly complex systems
2Reliability
If the system processes large amounts of user activity data to detect insider threats, then detection reliability is improved, but processing time and operational cost increase
Solution Approach 1:
The system performs preliminary actions by pre-processing user activity data into activity-sets and creating sampled activity matrices before the actual threat detection process. This preliminary organization of data into structured formats with assigned weights enables faster processing during detection, reducing overall processing time while maintaining high reliability through comprehensive analysis
Solution Approach 2:
The system changes parameters by transforming raw user activity data into normalized behavior vectors through sampling and weighting processes. This parameter transformation converts complex, time-consuming raw data analysis into more efficient vector comparisons, reducing processing time while preserving detection reliability through maintained behavioral pattern recognition
3Measurement precision
If the system analyzes user behavior in detail to identify threats, then detection precision is improved, but system resource consumption increases
Solution Approach 1:
The system extracts only the necessary information from large volumes of user activity data by creating sampled activity matrices that capture essential behavioral patterns. This extraction process identifies and isolates critical behavioral features for threat detection while discarding redundant information, reducing system resource consumption while maintaining high detection precision through focused analysis of meaningful patterns
Data Source
AI summary
A computer method detect internal user behavior threats by recording user activity data at endpoints on a computer network associated with a tenant, generating a sampled activity matrix for each user, grouping users from the tenant into clusters based on similarity, assigning a user activity weight to each activity-set, creating a ranked list of the user activity-sets for all users within the tenant, computing a user behavior vector for each respective one of the users in the tenant, and comparing the user behavior vector for a particular one of the users in the tenant to other users in the tenant to determine whether the user behavior vector indicates that the user behavior deviates beyond a threshold amount from the other users in the tenant, and, if so, creating an internal user behavior threat notification that may, for example, prompt a real world response.


