Intrusion Detection via User Behavior Profiling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer network security systems are inflexible, complex, and resource-intensive, often failing to detect unauthorized intrusions in real-time due to outdated rule-based systems that require frequent maintenance and cannot adapt to changing user behavior.
Innovation Solution
A system and method that continuously monitor and compare user interactions against established behavior profiles to detect unauthorized access by analyzing user activities in real-time, using a monitoring module, comparing module, and validator to identify whether the current user is the authorized user, and triggering alerts for potential intrusions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rule-based features are used in security systems, then the system can detect intrusions, but the system becomes inflexible and requires frequent upgrading and maintenance
Solution Approach 1:
The patent implements dynamic adaptation by continuously learning user behavior patterns and updating profiles without requiring manual rule updates. The system automatically adjusts its detection criteria based on observed user behavior, transforming from a static rule-based system to a dynamic learning system that adapts to changing circumstances.
Solution Approach 2:
The system incorporates feedback mechanisms where user behavior patterns are continuously monitored, evaluated, and used to refine future detection decisions. The learning process uses feedback from observed behavior to adjust and improve intrusion detection accuracy over time, allowing the system to adapt to evolving user habits and detection needs.
2Reliability
If rule-based features and expert systems are used, then intrusion detection can be performed, but the system becomes highly complex and requires substantial CPU capacity
Solution Approach 1:
The patent extracts the complex rule evaluation logic and replaces it with a simplified profile comparison mechanism. By taking out the intricate rule-based decision tree and substituting it with behavior profile matching, the system maintains detection accuracy while significantly reducing computational complexity and CPU requirements.
Solution Approach 2:
The system changes the parameters used for intrusion detection from complex multi-condition rule evaluations to simplified behavior pattern comparisons. By transforming the detection approach to focus on characteristic behavior parameters rather than exhaustive rule checking, the system achieves the same detection reliability with lower computational complexity.
3Reliability
If thresholds and rules are updated regularly to maintain effectiveness, then detection accuracy improves, but the system requires frequent maintenance and human expert intervention
Solution Approach 1:
The system performs self-service by automatically learning and adapting to user behavior patterns without requiring human expert intervention. It autonomously updates its detection profiles based on observed behavior, eliminating the need for manual rule maintenance while maintaining high detection effectiveness.
Solution Approach 2:
The system performs preliminary learning and profile establishment during normal operation, preparing adaptation mechanisms in advance. By continuously pre-learning user behavior patterns and maintaining updated profiles, the system is ready to detect intrusions effectively without requiring subsequent manual updates or maintenance interventions.
4Speed
If continuous monitoring of user activity is performed, then real-time intrusion detection is achieved, but the system load increases
Solution Approach 1:
The patent applies partial action by monitoring and analyzing only the most relevant behavior patterns and characteristics rather than all possible user activities. By focusing on key behavioral indicators and using selective monitoring, the system achieves real-time detection capability while minimizing unnecessary CPU processing load.
Data Source
Figure 1
Figure 2
AI summary
In detecting the identity of a person currently using a computer (100) and in particular for detecting whether the person is the intended or authorized user of the computer previously established user patterns of users as stored in a database (4) are matched, in comparators (9), with data of the person's interactions through the computer. The interactions are detected by a monitoring module (2) that in testing modules (7) can process data of the interactions and storing them in buffers (8) to be used by the comparators. Such data can include data of interactions that happen directly after each other and can also include one or more time characteristic of each detected interaction.