Insider Threat Detection via User Behavior Vector Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current insider threat management systems face challenges in efficiently detecting and addressing insider user behavior threats within multitenant software as a service (SaaS) environments, as they often require significant infrastructure and resources to process and analyze large amounts of user activity data effectively.

Innovation Solution

A computer-implemented method and system that compares user behavior within a tenant to other users' behavior, generating a sampled activity matrix, clustering users based on similarity, assigning activity weights, and computing behavior vectors to identify deviations beyond a threshold, triggering notifications for potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional insider threat management systems process and analyze large amounts of user activity data, then detection accuracy is improved, but infrastructure complexity and operational cost increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidinfrastructure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments user activity data into activity-sets grouped by time windows, and further segments the analysis by creating separate sampled activity matrices for each user. This segmentation allows the system to process large amounts of data in manageable chunks, reducing infrastructure complexity while maintaining detection accuracy through localized analysis of user behaviors within specific time periods

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by sampling user activity data to create sampled activity matrices rather than processing all data at full resolution. This selective processing approach reduces the computational burden on infrastructure while still capturing sufficient behavioral patterns for accurate threat detection, avoiding the need for overly complex systems

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If the system processes large amounts of user activity data to detect insider threats, then detection reliability is improved, but processing time and operational cost increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-processing user activity data into activity-sets and creating sampled activity matrices before the actual threat detection process. This preliminary organization of data into structured formats with assigned weights enables faster processing during detection, reducing overall processing time while maintaining high reliability through comprehensive analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by transforming raw user activity data into normalized behavior vectors through sampling and weighting processes. This parameter transformation converts complex, time-consuming raw data analysis into more efficient vector comparisons, reducing processing time while preserving detection reliability through maintained behavioral pattern recognition

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the system analyzes user behavior in detail to identify threats, then detection precision is improved, but system resource consumption increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts only the necessary information from large volumes of user activity data by creating sampled activity matrices that capture essential behavioral patterns. This extraction process identifies and isolates critical behavioral features for threat detection while discarding redundant information, reducing system resource consumption while maintaining high detection precision through focused analysis of meaningful patterns

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250005145A1Detecting insider user behavior threats by comparing a current (latest) user activity to user activities of others
Publication Date: 2025.01.02 GOLDMAN SACHS BANK USA
  • US20250005145A1 patent drawing
  • US20250005145A1 patent drawing
  • US20250005145A1 patent drawing

AI summary

A computer method detect internal user behavior threats by recording user activity data at endpoints on a computer network associated with a tenant, generating a sampled activity matrix for each user, grouping users from the tenant into clusters based on similarity, assigning a user activity weight to each activity-set, creating a ranked list of the user activity-sets for all users within the tenant, computing a user behavior vector for each respective one of the users in the tenant, and comparing the user behavior vector for a particular one of the users in the tenant to other users in the tenant to determine whether the user behavior vector indicates that the user behavior deviates beyond a threshold amount from the other users in the tenant, and, if so, creating an internal user behavior threat notification that may, for example, prompt a real world response.