Insider Threat Detection via Role-Based Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies inadequately manage and monitor suspicious data access activities in enterprise networks, leading to potential unauthorized data access and theft, as they lack effective methods to determine and mitigate insider threats.

Innovation Solution

A system that employs a Traffic Capture/Analysis Module (TCAM) and a Data Access Verification Module (DAVM) to analyze network traffic, trigger verification rules based on suspicious activity, and selectively contact appropriate users within the enterprise for verification, ensuring that the verification is conducted by individuals with the necessary knowledge to assess the legitimacy of the activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current monitoring technologies are used to detect suspicious data access activity, then basic network security monitoring is maintained, but the ability to accurately determine and mitigate insider threats is insufficient

Engineering Contradiction:
Improveaccuracy of insider threat detectionVSAvoidcomplexity of verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the verification process into distinct components: a Traffic Capture/Analysis Module (TCAM) that monitors network traffic and identifies suspicious activity, and a Data Access Verification Module (DAVM) that executes verification protocols. This segmentation allows each module to specialize in specific tasks, improving detection accuracy while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary verification system that acts as a mediator between network traffic monitoring and threat response. The DAVM serves as an intermediary layer that captures traffic metadata, analyzes it against verification rules, and triggers appropriate responses without requiring direct intervention in the core network infrastructure, thus improving reliability while controlling complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive verification rules are implemented to cover all insider threat scenarios, then detection accuracy improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improvecoverage of insider threat scenariosVSAvoidcomplexity of verification rules
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements verification rules selectively based on the suspiciousness of detected activity. Rather than applying comprehensive verification to all network traffic, the DAVM captures metadata and applies verification rules only when the TCAM identifies suspicious patterns, such as unusual data access behaviors or anomalies. This partial action approach ensures coverage of threat scenarios while avoiding unnecessary complexity and resource consumption for normal traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The verification system applies different levels of verification intensity and different rule sets based on the specific characteristics of the detected suspicious activity. The DAVM analyzes traffic metadata and triggers appropriate verification rules tailored to the specific threat scenario, rather than applying a uniform verification process to all cases. This local quality approach improves threat detection coverage while managing system complexity through context-aware rule application.

Inventive Principle:
Principle #3Local quality

3Speed

If real-time analysis of all network traffic is performed to detect suspicious activity, then detection speed improves, but system resource consumption increases

Engineering Contradiction:
Improvespeed of suspicious activity detectionVSAvoidcomputational resources for traffic analysis
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system extracts only the essential metadata from network traffic that is relevant for detecting insider threats, rather than analyzing the complete raw traffic data. The TCAM captures traffic metadata including source/destination addresses, ports, protocols, and data volumes, which are then analyzed by the DAVM. This extraction approach enables fast detection of suspicious activity patterns while significantly reducing computational resource consumption compared to analyzing all network traffic in detail.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10382464B2Data access verification for enterprise resources
Publication Date: 2019.08.13 IMPERVA INC
  • US10382464B2 patent drawing
  • US10382464B2 patent drawing
  • US10382464B2 patent drawing

AI summary

According to one embodiment, a method in a computing device for responding to a determination that a verification with a user is desired responsive to detection of activity indicative of a possible insider threat is described. The method includes selecting a target role and a target user for the verification based on an activity context and an enterprise context repository, the selecting including selecting the target role from a plurality of target roles based on the activity context and optionally the enterprise context repository and selecting a target user in the selected target role based on the enterprise context repository. The method further includes causing a verification request to be sent to the selected target user; and generating an alert when a verification result indicates that the activity is indicative of the possible insider threat.