Insider Threat Prediction via Behavioral Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in detecting insider threats as they often require intrusive monitoring and struggle to differentiate between authorized and malicious activities, allowing savvy insiders to evade detection.

Innovation Solution

An electronic security system comprising a forensic data source, a threat prediction module, and a data collection module that collects and analyzes subject data from various sources using machine learning methods to generate an insider threat output, including a threat score, and transmits it to an analyst terminal for response execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusive monitoring systems are used to detect insider threats, then detection capability is improved, but employee privacy and system usability deteriorate

Engineering Contradiction:
Improveinsider threat detection capabilityVSAvoidsystem intrusiveness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary analysis layer that processes employee behavior data without requiring direct intrusive monitoring of sensitive communications. The system uses behavioral analytics as a mediator to detect insider threats by analyzing patterns in authorized activities rather than monitoring private communications directly, thus maintaining detection capability while reducing intrusiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical intrusion-based monitoring (direct surveillance of communications and actions) with automated behavioral analytics that process data through algorithmic analysis. This substitution allows the system to detect threats through pattern recognition in behavioral data without requiring the same level of direct intrusion as traditional monitoring systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive data collection is implemented to identify insider threats, then detection accuracy is improved, but system complexity and resource requirements worsen

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the data collection and analysis process into distinct modular components: data collection from multiple sources, behavioral pattern analysis, threshold evaluation, and alert generation. This segmentation allows comprehensive data collection to be managed through organized modules, reducing system complexity while maintaining detection accuracy through structured processing of behavioral indicators

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If traditional IT security systems are used, then data protection is provided, but detection of savvy insider threats deteriorates

Engineering Contradiction:
Improvedata protection capabilityVSAvoidinsider threat detection effectiveness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent inverts the traditional security approach by not focusing on detecting malicious actions directly, but rather on identifying behavioral patterns that precede or accompany insider threats. Instead of monitoring for suspicious activities, the system analyzes authorized behaviors for anomalies that indicate potential threats, effectively detecting insiders by what they normally do rather than by what they try to do

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP4210278A1Method and system for electronic insider threat prediction
Publication Date: 2023.07.12 MAGNET FORENSICS INC
  • EP4210278A1 patent drawingFigure 1
  • EP4210278A1 patent drawingFigure 2
  • EP4210278A1 patent drawingFigure 3~4

AI summary

A system and associated method for insider threat prediction. The system includes a forensic data source, a threat prediction module, and a data collection module, wherein the data collection module is configured to collect subject data of a subject from the forensic data source, and transmit the subject data to the threat prediction module, wherein the threat prediction module is configured to receive subject data from the data collection module and analyze subject data to generate an insider threat output characterizing the insider threat level of the subject.