Malicious User Account Detection via Cross-Organization Pattern Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures are ineffective in detecting malicious user accounts created by attackers in cloud-based networks, as these accounts often go undetected by traditional security products, which consider such access as legitimate.

Innovation Solution

A system that collects data on new user account creations across multiple organizations, subscriptions, or customers, clusters user names based on similarities, and evaluates the probability of malicious activity, generating an alert if the probability falls below a predetermined threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security products are used to detect malicious user accounts, then the system operates with standard security measures, but malicious accounts go undetected and are considered legitimate

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines data from multiple sources including user account creation events, sign-in events, and threat intelligence feeds into a unified risk assessment model. This merging of diverse data streams enables more reliable detection of malicious accounts by analyzing patterns across different dimensions rather than relying on single-source traditional security products.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system transitions from traditional single-dimension security checking to multi-dimensional analysis by incorporating temporal patterns, geographic information, device fingerprints, and behavioral analytics. This dimensional expansion allows the system to detect malicious accounts that would appear legitimate under traditional security measures.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If data is collected across multiple organizations and subscriptions to improve detection, then detection capability improves, but data privacy and security requirements increase

Engineering Contradiction:
Improvedetection precisionVSAvoidprivacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and analyzes only the specific data elements necessary for detection (user account patterns, sign-in behaviors, device characteristics) while excluding sensitive personal information. This selective extraction enables precise detection across multiple organizations without collecting or storing unnecessary private data that would increase privacy risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses anonymized identifiers and aggregated pattern data as intermediaries between multiple organizations. Instead of directly sharing or collecting sensitive user data, the system processes information through anonymization layers that preserve detection capability while minimizing privacy exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If user name patterns are analyzed to identify malicious accounts, then false positives are minimized, but processing time and computational resources increase

Engineering Contradiction:
Improvefalse positive rateVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary clustering and pattern matching on user account data during off-peak periods or in parallel processing streams. By pre-processing and organizing data into patterns before actual detection queries, the system reduces the computational burden during real-time detection, thereby minimizing processing time while maintaining low false positive rates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical pattern matching with machine learning models and probabilistic algorithms that can efficiently evaluate complex user name patterns and behavioral data. This substitution enables the system to analyze sophisticated patterns with lower computational overhead compared to brute-force mechanical comparison methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10320833B2System and method for detecting creation of malicious new user accounts by an attacker
Publication Date: 2019.06.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10320833B2 patent drawing
  • US10320833B2 patent drawing
  • US10320833B2 patent drawing

AI summary

A system is provided for detecting creation of malicious user accounts. The system includes a processor, a memory, and an application including instructions configured to: collect data corresponding to creation of new user accounts, where the new user accounts are associated with at least two distinct organizations, at least two distinct subscriptions, or at least two distinct customers, and where each of the new user accounts has a user name; determine properties based on the data and for a group of similar ones of the user names; evaluate the properties of the new user accounts corresponding to the group of similar ones of the user names and determine whether a probability for the new user accounts to be created having the group of similar ones of the user names is less than a predetermined threshold, and generate an alert based on a result of the evaluation of the properties.