Insider Threat Detection via User Group Access Patterns
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current file access control systems fail to effectively detect insider threats, leading to data breaches, as they become cumbersome to manage with growing user and data volumes, and often hinder collaboration, resulting in false alarms and reduced security efficacy.
Innovation Solution
The system identifies user groups based on data object and resource group access patterns, generating models to detect suspicious access requests by analyzing user group similarities and resource group associations, reducing false positives and maintaining high true positive rates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional file access control systems are used to prevent data breaches, then security coverage is provided, but the systems become cumbersome to manage with growing user and data volumes and generate false alarms
Solution Approach 1:
The patent segments users into groups based on their access patterns to data objects and resource groups. Instead of managing individual user permissions, the system creates user groups with similar access behaviors, thereby reducing management complexity while maintaining security coverage. This segmentation allows the system to handle growing user volumes more efficiently.
Solution Approach 2:
The patent introduces user group profiles as intermediaries between individual users and the access control system. These profiles aggregate access patterns and serve as mediators for detecting suspicious behavior. By using user group profiles as intermediaries, the system reduces false alarms and improves detection accuracy without increasing management complexity.
2Reliability
If strict access control rules are enforced to detect insider threats, then security detection capability is improved, but collaboration is hindered and false alarms increase
Solution Approach 1:
The patent dynamically adjusts access control policies based on user group profiles and similarity metrics. Instead of enforcing static strict rules, the system adapts its detection sensitivity based on the behavioral patterns of user groups. This dynamic approach maintains security detection capability while reducing false alarms that would otherwise hinder collaboration.
Solution Approach 2:
The patent changes the parameters used for access control from individual user permissions to user group behavioral patterns. By analyzing access patterns, resource group associations, and user similarities, the system adjusts its detection parameters to distinguish between legitimate collaborative behavior and suspicious insider threats, thereby maintaining collaboration efficiency while improving threat detection.
3Measurement precision
If individual user access monitoring is performed to detect suspicious requests, then detection precision is achieved, but system complexity and processing overhead increase
Solution Approach 1:
The patent merges individual user monitoring into user group profile analysis. Instead of tracking each user separately, the system combines access patterns of similar users into group profiles, thereby maintaining detection precision while reducing system complexity. The user group profiles aggregate behavioral data, reducing the overall monitoring burden.
Solution Approach 2:
The patent creates user group profiles that serve multiple functions: they represent individual users, capture collective behavioral patterns, enable similarity-based detection, and reduce false alarms. This multi-functionality allows the system to maintain high detection precision without proportionally increasing complexity, as the same profiles are used for multiple detection purposes.
Data Source
AI summary
Techniques for detecting suspicious data object access requests indicative of potential insider threats are described. A suspicious access detection module (SADM) determines, based on access data describing a access requests issued on behalf of multiple users, groups of the users having similar patterns of accesses to resource groups, a set of the resource groups accessed by each of the user groups, and ones of the user groups that are to be considered nearby others of the user groups based on having a threshold amount of resource group access similarities. The SADM causes an alert to be generated responsive to a determination that a subsequent access request is suspicious because it accesses a data object of a resource group that is not within the set of accessed resource groups of the issuing user's user group, and because the resource group is not within the sets of accessed resource groups of any nearby user groups.


