Insider Threat Detection via User Group Access Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current file access control systems fail to effectively detect insider threats, leading to data breaches, as they become cumbersome to manage with growing user and data volumes, and often hinder collaboration, resulting in false alarms and reduced security efficacy.

Innovation Solution

The system identifies user groups based on data object and resource group access patterns, generating models to detect suspicious access requests by analyzing user group similarities and resource group associations, reducing false positives and maintaining high true positive rates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional file access control systems are used to prevent data breaches, then security coverage is provided, but the systems become cumbersome to manage with growing user and data volumes and generate false alarms

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidaccess control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments users into groups based on their access patterns to data objects and resource groups. Instead of managing individual user permissions, the system creates user groups with similar access behaviors, thereby reducing management complexity while maintaining security coverage. This segmentation allows the system to handle growing user volumes more efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces user group profiles as intermediaries between individual users and the access control system. These profiles aggregate access patterns and serve as mediators for detecting suspicious behavior. By using user group profiles as intermediaries, the system reduces false alarms and improves detection accuracy without increasing management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict access control rules are enforced to detect insider threats, then security detection capability is improved, but collaboration is hindered and false alarms increase

Engineering Contradiction:
Improveinsider threat detection capabilityVSAvoidcollaboration efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent dynamically adjusts access control policies based on user group profiles and similarity metrics. Instead of enforcing static strict rules, the system adapts its detection sensitivity based on the behavioral patterns of user groups. This dynamic approach maintains security detection capability while reducing false alarms that would otherwise hinder collaboration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters used for access control from individual user permissions to user group behavioral patterns. By analyzing access patterns, resource group associations, and user similarities, the system adjusts its detection parameters to distinguish between legitimate collaborative behavior and suspicious insider threats, thereby maintaining collaboration efficiency while improving threat detection.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If individual user access monitoring is performed to detect suspicious requests, then detection precision is achieved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesuspicious access detection precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges individual user monitoring into user group profile analysis. Instead of tracking each user separately, the system combines access patterns of similar users into group profiles, thereby maintaining detection precision while reducing system complexity. The user group profiles aggregate behavioral data, reducing the overall monitoring burden.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates user group profiles that serve multiple functions: they represent individual users, capture collective behavioral patterns, enable similarity-based detection, and reduce false alarms. This multi-functionality allows the system to maintain high detection precision without proportionally increasing complexity, as the same profiles are used for multiple detection purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11750627B2Insider threat detection utilizing user group to data object and/or resource group access analysis
Publication Date: 2023.09.05 IMPERVA INC
  • US11750627B2 patent drawing
  • US11750627B2 patent drawing
  • US11750627B2 patent drawing

AI summary

Techniques for detecting suspicious data object access requests indicative of potential insider threats are described. A suspicious access detection module (SADM) determines, based on access data describing a access requests issued on behalf of multiple users, groups of the users having similar patterns of accesses to resource groups, a set of the resource groups accessed by each of the user groups, and ones of the user groups that are to be considered nearby others of the user groups based on having a threshold amount of resource group access similarities. The SADM causes an alert to be generated responsive to a determination that a subsequent access request is suspicious because it accesses a data object of a resource group that is not within the set of accessed resource groups of the issuing user's user group, and because the resource group is not within the sets of accessed resource groups of any nearby user groups.