Logon Data Anomaly Detection for Low-Visibility Threats
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems in cloud-based SaaS environments struggle to detect sophisticated, under-the-radar attacks that gradually attempt to gain access, as they rely on rule-based monitoring that is inadequate for complex and evolving threat vectors.
Innovation Solution
A framework utilizing unsupervised machine learning models to establish baselines of network activity, combined with expert feedback for tagging rules, identifies anomalous behavior and adapts to new threats by learning from login data, enabling detection of both known and unknown attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rule-based monitoring is used to detect security threats, then the system is easy to implement and understand, but it fails to detect sophisticated, under-the-radar attacks that gradually attempt to gain access
Solution Approach 1:
The patent replaces rule-based monitoring (mechanical system) with machine learning models that automatically learn patterns from data. The ML models substitute the rigid, pre-defined rules with adaptive, data-driven detection mechanisms that can identify sophisticated attacks without manual rule configuration.
Solution Approach 2:
The system implements self-service through automated ML model training and deployment. The platform automatically trains models on organizational login data, optimizes detection parameters, and updates threat detection capabilities without requiring manual intervention from security analysts, thereby improving reliability while managing complexity.
2Measurement precision
If traditional security systems monitor network activity, then they can identify obvious threats, but they cannot detect attacks that remain below activity levels required to trigger alerts
Solution Approach 1:
The system uses feedback loops where ML models continuously learn from detected anomalies and organizational context. The models receive feedback from security analysts about false positives and negatives, automatically adjusting detection thresholds and parameters to improve precision while adapting to the organization's specific patterns.
Solution Approach 2:
The patent dynamically changes detection parameters based on organizational context and learned patterns. Instead of fixed thresholds, the system adjusts sensitivity parameters, time windows, and anomaly criteria based on the specific organization's login patterns and threat landscape, making detection easier while maintaining precision.
3Adaptability or versatility
If machine learning models are used to identify anomalous activity, then the system can detect novel attack patterns, but false positives may increase without proper contextual understanding
Solution Approach 1:
The system segments the anomaly detection process into multiple specialized ML models, each focusing on specific aspects of login behavior. By dividing the detection task across multiple models (e.g., one for temporal patterns, another for geographic anomalies), the system maintains high adaptability to various attack types while reducing false positives through specialized focus.
Solution Approach 2:
The patent introduces organizational context as an intermediary layer between raw anomaly detection and final threat classification. This intermediary contextualizes anomalies within the organization's specific patterns, culture, and operational norms, allowing the system to maintain versatility in detecting novel attacks while filtering out false positives through contextual understanding.
Data Source
AI summary
This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.


