Computer Intrusion Detection via User Profile Deviation Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems for computer networks are inadequate in detecting intrusions and misuses in real-time, as they rely on passive audit capabilities that cannot operate effectively against rapid cyber threats and internal unauthorized access.

Innovation Solution

A system comprising an agent manager, data analyzer, and comparator that collects and summarizes computer performance parameters to generate user profiles, allowing for real-time comparison and prompt action against deviations from established criteria, thereby detecting and responding to potential intrusions and misuses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passive audit capabilities are used to collect security information, then the system can maintain simple architecture, but real-time detection capability is lost

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing computer performance parameters continuously in the background before intrusions occur. User profiles are established through preliminary analysis of normal operation patterns, enabling real-time detection without adding complexity to the core security architecture. The agent collects parameters proactively rather than reactively auditing after events occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A software agent acts as an intermediary between the computer system and the security analysis system. This agent collects computer performance parameters and transmits them to the analysis system, which generates user profiles and detects intrusions. This intermediary approach enables real-time detection capability while keeping the main system architecture simple, as the agent handles the complexity of continuous monitoring and parameter collection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If computer performance parameters are continuously collected and analyzed, then intrusion detection accuracy improves, but system resource consumption increases

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by selectively analyzing specific computer performance parameters rather than all possible system events. The software agent collects a focused set of parameters (CPU usage, memory usage, disk activity, network activity) that are most indicative of intrusions, rather than exhaustively monitoring every system function. This selective approach maintains high detection accuracy while reducing resource consumption compared to comprehensive monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary analysis to establish user profiles representing normal operation patterns before actual intrusion detection begins. This preliminary phase creates a baseline that enables the system to detect deviations without requiring continuous intensive analysis of all parameters. Once the profile is established, the system can efficiently compare current parameters against the profile with reduced computational overhead.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If user profiles representing steady-state operation are generated, then the system can detect unusual patterns, but the initial setup time and data collection period increase

Engineering Contradiction:
Improveunusual pattern detection reliabilityVSAvoidinitial setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary data collection and analysis to generate user profiles that represent normal steady-state operation. During this preliminary phase, the software agent collects computer performance parameters and the analysis system processes this data to establish baseline patterns. This preliminary action enables reliable unusual pattern detection once the profile is complete, while the initial setup time is minimized through efficient data collection and processing algorithms that can establish accurate profiles relatively quickly.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8201249B2Steady state computer intrusion and misuse detection
Publication Date: 2012.06.12 NORTHROP GRUMMAN SYSTEMS CORP
  • US8201249B2 patent drawing
  • US8201249B2 patent drawing
  • US8201249B2 patent drawing

AI summary

A system and method provide for detecting intrusion and misuse of a computer in a computer network. The system includes an agent manager that directs actions of software agents to collect computer performance parameters from the computer, and a data analyzer that summarizes the collected computer performance parameters and generates a user profile. The system further includes a comparator that compares the summarized computer performance data and the user profile and generates a prompt based on a set of criteria related to the computer performance data and the user profile.