Malicious User Account Detection via Cross-Organization Pattern Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures are ineffective in detecting malicious user accounts created by attackers in cloud-based networks, as these accounts often go undetected by traditional security products, which consider such access as legitimate.
Innovation Solution
A system that collects data on new user account creations across multiple organizations, subscriptions, or customers, clusters user names based on similarities, and evaluates the probability of malicious activity, generating an alert if the probability falls below a predetermined threshold.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security products are used to detect malicious user accounts, then the system operates with standard security measures, but malicious accounts go undetected and are considered legitimate
Solution Approach 1:
The patent combines data from multiple sources including user account creation events, sign-in events, and threat intelligence feeds into a unified risk assessment model. This merging of diverse data streams enables more reliable detection of malicious accounts by analyzing patterns across different dimensions rather than relying on single-source traditional security products.
Solution Approach 2:
The system transitions from traditional single-dimension security checking to multi-dimensional analysis by incorporating temporal patterns, geographic information, device fingerprints, and behavioral analytics. This dimensional expansion allows the system to detect malicious accounts that would appear legitimate under traditional security measures.
2Measurement precision
If data is collected across multiple organizations and subscriptions to improve detection, then detection capability improves, but data privacy and security requirements increase
Solution Approach 1:
The patent extracts and analyzes only the specific data elements necessary for detection (user account patterns, sign-in behaviors, device characteristics) while excluding sensitive personal information. This selective extraction enables precise detection across multiple organizations without collecting or storing unnecessary private data that would increase privacy risks.
Solution Approach 2:
The system uses anonymized identifiers and aggregated pattern data as intermediaries between multiple organizations. Instead of directly sharing or collecting sensitive user data, the system processes information through anonymization layers that preserve detection capability while minimizing privacy exposure.
3Reliability
If user name patterns are analyzed to identify malicious accounts, then false positives are minimized, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary clustering and pattern matching on user account data during off-peak periods or in parallel processing streams. By pre-processing and organizing data into patterns before actual detection queries, the system reduces the computational burden during real-time detection, thereby minimizing processing time while maintaining low false positive rates.
Solution Approach 2:
The patent replaces traditional mechanical pattern matching with machine learning models and probabilistic algorithms that can efficiently evaluate complex user name patterns and behavioral data. This substitution enables the system to analyze sophisticated patterns with lower computational overhead compared to brute-force mechanical comparison methods.
Data Source
AI summary
A system is provided for detecting creation of malicious user accounts. The system includes a processor, a memory, and an application including instructions configured to: collect data corresponding to creation of new user accounts, where the new user accounts are associated with at least two distinct organizations, at least two distinct subscriptions, or at least two distinct customers, and where each of the new user accounts has a user name; determine properties based on the data and for a group of similar ones of the user names; evaluate the properties of the new user accounts corresponding to the group of similar ones of the user names and determine whether a probability for the new user accounts to be created having the group of similar ones of the user names is less than a predetermined threshold, and generate an alert based on a result of the evaluation of the properties.


