Logon Data Anomaly Detection for Low-Visibility Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems in cloud-based SaaS environments struggle to detect sophisticated, under-the-radar attacks that gradually attempt to gain access, as they rely on rule-based monitoring that is inadequate for complex and evolving threat vectors.

Innovation Solution

A framework utilizing unsupervised machine learning models to establish baselines of network activity, combined with expert feedback for tagging rules, identifies anomalous behavior and adapts to new threats by learning from login data, enabling detection of both known and unknown attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based monitoring is used to detect security threats, then the system is easy to implement and understand, but it fails to detect sophisticated, under-the-radar attacks that gradually attempt to gain access

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces rule-based monitoring (mechanical system) with machine learning models that automatically learn patterns from data. The ML models substitute the rigid, pre-defined rules with adaptive, data-driven detection mechanisms that can identify sophisticated attacks without manual rule configuration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements self-service through automated ML model training and deployment. The platform automatically trains models on organizational login data, optimizes detection parameters, and updates threat detection capabilities without requiring manual intervention from security analysts, thereby improving reliability while managing complexity.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If traditional security systems monitor network activity, then they can identify obvious threats, but they cannot detect attacks that remain below activity levels required to trigger alerts

Engineering Contradiction:
Improveanomaly detection precisionVSAvoiddetection difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The system uses feedback loops where ML models continuously learn from detected anomalies and organizational context. The models receive feedback from security analysts about false positives and negatives, automatically adjusting detection thresholds and parameters to improve precision while adapting to the organization's specific patterns.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent dynamically changes detection parameters based on organizational context and learned patterns. Instead of fixed thresholds, the system adjusts sensitivity parameters, time windows, and anomaly criteria based on the specific organization's login patterns and threat landscape, making detection easier while maintaining precision.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If machine learning models are used to identify anomalous activity, then the system can detect novel attack patterns, but false positives may increase without proper contextual understanding

Engineering Contradiction:
Improvethreat detection adaptabilityVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the anomaly detection process into multiple specialized ML models, each focusing on specific aspects of login behavior. By dividing the detection task across multiple models (e.g., one for temporal patterns, another for geographic anomalies), the system maintains high adaptability to various attack types while reducing false positives through specialized focus.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces organizational context as an intermediary layer between raw anomaly detection and final threat classification. This intermediary contextualizes anomalies within the organization's specific patterns, culture, and operational norms, allowing the system to maintain versatility in detecting novel attacks while filtering out false positives through contextual understanding.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260006036A1Detecting security threats from logon data
Publication Date: 2026.01.01 WELLS FARGO BANK NA
  • US20260006036A1 patent drawing
  • US20260006036A1 patent drawing
  • US20260006036A1 patent drawing

AI summary

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.