Insider Threat Detection via Role-Based Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies inadequately manage and monitor suspicious data access activities in enterprise networks, leading to potential unauthorized data access and theft, as they lack effective methods to determine and mitigate insider threats.
Innovation Solution
A system that employs a Traffic Capture/Analysis Module (TCAM) and a Data Access Verification Module (DAVM) to analyze network traffic, trigger verification rules based on suspicious activity, and selectively contact appropriate users within the enterprise for verification, ensuring that the verification is conducted by individuals with the necessary knowledge to assess the legitimacy of the activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current monitoring technologies are used to detect suspicious data access activity, then basic network security monitoring is maintained, but the ability to accurately determine and mitigate insider threats is insufficient
Solution Approach 1:
The system segments the verification process into distinct components: a Traffic Capture/Analysis Module (TCAM) that monitors network traffic and identifies suspicious activity, and a Data Access Verification Module (DAVM) that executes verification protocols. This segmentation allows each module to specialize in specific tasks, improving detection accuracy while managing complexity through modular design.
Solution Approach 2:
The patent introduces an intermediary verification system that acts as a mediator between network traffic monitoring and threat response. The DAVM serves as an intermediary layer that captures traffic metadata, analyzes it against verification rules, and triggers appropriate responses without requiring direct intervention in the core network infrastructure, thus improving reliability while controlling complexity.
2Reliability
If comprehensive verification rules are implemented to cover all insider threat scenarios, then detection accuracy improves, but system complexity and resource consumption increase
Solution Approach 1:
The system implements verification rules selectively based on the suspiciousness of detected activity. Rather than applying comprehensive verification to all network traffic, the DAVM captures metadata and applies verification rules only when the TCAM identifies suspicious patterns, such as unusual data access behaviors or anomalies. This partial action approach ensures coverage of threat scenarios while avoiding unnecessary complexity and resource consumption for normal traffic.
Solution Approach 2:
The verification system applies different levels of verification intensity and different rule sets based on the specific characteristics of the detected suspicious activity. The DAVM analyzes traffic metadata and triggers appropriate verification rules tailored to the specific threat scenario, rather than applying a uniform verification process to all cases. This local quality approach improves threat detection coverage while managing system complexity through context-aware rule application.
3Speed
If real-time analysis of all network traffic is performed to detect suspicious activity, then detection speed improves, but system resource consumption increases
Solution Approach 1:
The system extracts only the essential metadata from network traffic that is relevant for detecting insider threats, rather than analyzing the complete raw traffic data. The TCAM captures traffic metadata including source/destination addresses, ports, protocols, and data volumes, which are then analyzed by the DAVM. This extraction approach enables fast detection of suspicious activity patterns while significantly reducing computational resource consumption compared to analyzing all network traffic in detail.
Data Source
AI summary
According to one embodiment, a method in a computing device for responding to a determination that a verification with a user is desired responsive to detection of activity indicative of a possible insider threat is described. The method includes selecting a target role and a target user for the verification based on an activity context and an enterprise context repository, the selecting including selecting the target role from a plurality of target roles based on the activity context and optionally the enterprise context repository and selecting a target user in the selected target role based on the enterprise context repository. The method further includes causing a verification request to be sent to the selected target user; and generating an alert when a verification result indicates that the activity is indicative of the possible insider threat.


