Real-time Malicious Activity Detection via Data-Object Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems fail to effectively detect and prevent malicious activity in real-time, particularly as malicious users employ sophisticated methods to obscure their identities and motives, leading to unauthorized access and potential harm.

Innovation Solution

A detection system that receives user requests, determines associated data objects, generates data-object networks to confirm user identities, and uses behavioral information and machine-learning models to assess the likelihood of anomalous activity, allowing or denying access based on predefined thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are used, then implementation is simple, but they cannot detect sophisticated malicious activity in real-time

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the analysis by creating separate data-object networks for different data objects (user, device, entity, etc.) and then combining them. Each network definition is independently structured with nodes and relationships, allowing modular processing and analysis of complex access requests without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional approach by representing access control data as interconnected networks rather than traditional flat structures. Each data object becomes a network of nodes with relationships, adding spatial and relational dimensions to the analysis, enabling detection of sophisticated malicious patterns that traditional systems miss.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If data-object networks are generated and combined to resolve user identity, then detection precision improves, but processing time increases

Engineering Contradiction:
Improveidentity resolution accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining data-object network structures, node types, and relationship patterns before actual access requests are processed. This preparation enables faster real-time analysis when requests arrive, as the framework is already in place to quickly instantiate and combine relevant networks without building from scratch.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If behavioral information and multiple data objects are analyzed, then anomaly detection accuracy improves, but computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts only the relevant data objects and their network definitions needed for each specific access request analysis. Rather than processing all available behavioral information and data objects uniformly, it selectively extracts and combines only those networks corresponding to objects in the request, reducing computational overhead while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10726123B1Real-time detection and prevention of malicious activity
Publication Date: 2020.07.28 SAS INSTITUTE INC
  • US10726123B1 patent drawing
  • US10726123B1 patent drawing
  • US10726123B1 patent drawing

AI summary

Malicious activity can be detected and prevented in real-time or otherwise. For example, a system of the present disclosure can receive a request from a user to obtain access to an entity, determine data objects based on the request, and access data-object network definitions corresponding to the determined data objects. The system can also receive a profile for the user indicating behavioral information relating to the user. The system can then determine a likelihood that the request is associated with malicious activity based on (i) the data objects, (ii) the profile, and (iii) the data-object network definitions. The system can allow or deny the user access to the entity based on the likelihood that the request is associated with malicious activity.