Real-time Malicious Activity Detection via Data-Object Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems fail to effectively detect and prevent malicious activity in real-time, particularly as malicious users employ sophisticated methods to obscure their identities and motives, leading to unauthorized access and potential harm.
Innovation Solution
A detection system that receives user requests, determines associated data objects, generates data-object networks to confirm user identities, and uses behavioral information and machine-learning models to assess the likelihood of anomalous activity, allowing or denying access based on predefined thresholds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control systems are used, then implementation is simple, but they cannot detect sophisticated malicious activity in real-time
Solution Approach 1:
The system segments the analysis by creating separate data-object networks for different data objects (user, device, entity, etc.) and then combining them. Each network definition is independently structured with nodes and relationships, allowing modular processing and analysis of complex access requests without overwhelming system complexity.
Solution Approach 2:
The patent introduces a new dimensional approach by representing access control data as interconnected networks rather than traditional flat structures. Each data object becomes a network of nodes with relationships, adding spatial and relational dimensions to the analysis, enabling detection of sophisticated malicious patterns that traditional systems miss.
2Measurement precision
If data-object networks are generated and combined to resolve user identity, then detection precision improves, but processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-defining data-object network structures, node types, and relationship patterns before actual access requests are processed. This preparation enables faster real-time analysis when requests arrive, as the framework is already in place to quickly instantiate and combine relevant networks without building from scratch.
3Reliability
If behavioral information and multiple data objects are analyzed, then anomaly detection accuracy improves, but computational resources increase
Solution Approach 1:
The system extracts only the relevant data objects and their network definitions needed for each specific access request analysis. Rather than processing all available behavioral information and data objects uniformly, it selectively extracts and combines only those networks corresponding to objects in the request, reducing computational overhead while maintaining detection accuracy.
Data Source
AI summary
Malicious activity can be detected and prevented in real-time or otherwise. For example, a system of the present disclosure can receive a request from a user to obtain access to an entity, determine data objects based on the request, and access data-object network definitions corresponding to the determined data objects. The system can also receive a profile for the user indicating behavioral information relating to the user. The system can then determine a likelihood that the request is associated with malicious activity based on (i) the data objects, (ii) the profile, and (iii) the data-object network definitions. The system can allow or deny the user access to the entity based on the likelihood that the request is associated with malicious activity.


