Intrusion Detection via User Behavior Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network security systems are inflexible, complex, and resource-intensive, often failing to detect unauthorized intrusions in real-time due to outdated rule-based systems that require frequent maintenance and cannot adapt to changing user behavior.

Innovation Solution

A system and method that continuously monitor and compare user interactions against established behavior profiles to detect unauthorized access by analyzing user activities in real-time, using a monitoring module, comparing module, and validator to identify whether the current user is the authorized user, and triggering alerts for potential intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based features are used in security systems, then the system can detect intrusions, but the system becomes inflexible and requires frequent upgrading and maintenance

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidflexibility to changing user behavior
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic adaptation by continuously learning user behavior patterns and updating profiles without requiring manual rule updates. The system automatically adjusts its detection criteria based on observed user behavior, transforming from a static rule-based system to a dynamic learning system that adapts to changing circumstances.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where user behavior patterns are continuously monitored, evaluated, and used to refine future detection decisions. The learning process uses feedback from observed behavior to adjust and improve intrusion detection accuracy over time, allowing the system to adapt to evolving user habits and detection needs.

Inventive Principle:
Principle #23Feedback

2Reliability

If rule-based features and expert systems are used, then intrusion detection can be performed, but the system becomes highly complex and requires substantial CPU capacity

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex rule evaluation logic and replaces it with a simplified profile comparison mechanism. By taking out the intricate rule-based decision tree and substituting it with behavior profile matching, the system maintains detection accuracy while significantly reducing computational complexity and CPU requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameters used for intrusion detection from complex multi-condition rule evaluations to simplified behavior pattern comparisons. By transforming the detection approach to focus on characteristic behavior parameters rather than exhaustive rule checking, the system achieves the same detection reliability with lower computational complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If thresholds and rules are updated regularly to maintain effectiveness, then detection accuracy improves, but the system requires frequent maintenance and human expert intervention

Engineering Contradiction:
Improvedetection effectivenessVSAvoidmaintenance requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically learning and adapting to user behavior patterns without requiring human expert intervention. It autonomously updates its detection profiles based on observed behavior, eliminating the need for manual rule maintenance while maintaining high detection effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary learning and profile establishment during normal operation, preparing adaptation mechanisms in advance. By continuously pre-learning user behavior patterns and maintaining updated profiles, the system is ready to detect intrusions effectively without requiring subsequent manual updates or maintenance interventions.

Inventive Principle:
Principle #10Preliminary action

4Speed

If continuous monitoring of user activity is performed, then real-time intrusion detection is achieved, but the system load increases

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoidCPU load
Core Design Contradiction:
SpeedVSPower

Solution Approach 1:

The patent applies partial action by monitoring and analyzing only the most relevant behavior patterns and characteristics rather than all possible user activities. By focusing on key behavioral indicators and using selective monitoring, the system achieves real-time detection capability while minimizing unnecessary CPU processing load.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2069993B1Security system and method for detecting intrusion in a computerized system
Publication Date: 2016.03.09 BEHAVIOMETRICS
  • EP2069993B1 patent drawingFigure 1
  • EP2069993B1 patent drawingFigure 2
  • EP2069993B1 patent drawing

AI summary

In detecting the identity of a person currently using a computer (100) and in particular for detecting whether the person is the intended or authorized user of the computer previously established user patterns of users as stored in a database (4) are matched, in comparators (9), with data of the person's interactions through the computer. The interactions are detected by a monitoring module (2) that in testing modules (7) can process data of the interactions and storing them in buffers (8) to be used by the comparators. Such data can include data of interactions that happen directly after each other and can also include one or more time characteristic of each detected interaction.