Insider Threat Detection via User Group Access Pattern Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current file access control systems fail to effectively detect insider threats, leading to data breaches, as they become complex to manage with growing user and data volumes, and often hinder collaboration, resulting in significant data losses despite their implementation.
Innovation Solution
The system identifies user groups based on data object access patterns and generates a model to detect suspicious access requests by analyzing access data, distinguishing between normal and abnormal behavior within user groups and nearby groups, reducing false positives and maintaining high true positive rates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If file access control systems are implemented to prevent data breaches, then data security is improved, but the systems become complex to manage and hinder collaboration
Solution Approach 1:
The system automatically generates user groups and determines suspicious accesses without requiring manual configuration of access control rules. The computer system performs self-service by autonomously analyzing access patterns, identifying user groups based on data object access histories, and detecting suspicious behaviors, thereby eliminating the need for complex manual access control management while maintaining data security
Solution Approach 2:
The patent replaces traditional mechanical access control systems with an automated analysis system that uses algorithms to identify user groups and detect suspicious accesses. Instead of manually configuring and managing access control lists, the system substitutes mechanical rule-based controls with automated behavioral analysis, reducing management complexity while improving security monitoring
2Reliability
If traditional access control rules are enforced to protect sensitive data, then data protection is improved, but false positives increase and true threats are missed
Solution Approach 1:
The system changes the parameters used for threat detection from static access control rules to dynamic behavioral patterns. By analyzing access histories and identifying user groups based on similar access patterns, the system adapts detection parameters to actual user behavior, improving both data protection and detection accuracy while reducing false positives
Solution Approach 2:
The system performs preliminary analysis of access patterns to establish baseline user groups before detecting suspicious behaviors. By pre-identifying normal access patterns and user groups, the system can more accurately distinguish between legitimate and suspicious accesses, improving measurement precision in threat detection
Data Source
AI summary
Techniques for detecting suspicious file access requests indicative of potential insider threats are described. A suspicious access detection module (SADM) determines, based on access data describing a access requests issued on behalf of multiple users, groups of the users having similar patterns of accesses to folders, a set of the folders accessed by each of the user groups, and ones of the user groups that are to be considered nearby others of the user groups based on having a threshold amount of folder access similarities. The SADM causes an alert to be generated responsive to a determination that a subsequent access request is suspicious because it accesses a file of a folder that is not within the set of accessed folders of the issuing user's user group, and because the folder is not within the sets of accessed folders of any nearby user groups.


