ML-Based Bad Actor Detection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems are unable to detect network attacks in a timely manner, allowing bad actors to gain access to sensitive information and perform malicious activities such as data exfiltration or malware uploads, leading to increased resource consumption and network throughput reduction.

Innovation Solution

A machine learning-based system that analyzes user activity information to identify potential bad actors and network security threats, allowing for proactive measures to be taken before an attack occurs, using a combination of first and second machine learning models to filter user activity information and execute corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing network security systems are used, then network security monitoring is provided, but detection of network attacks occurs too late allowing bad actors to perform malicious activities

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of user behavior patterns and device interactions before malicious activities occur. By continuously monitoring and establishing baseline behavior profiles, the system can detect deviations that indicate potential attacks in advance, allowing preventive actions to be taken before data exfiltration or malware uploads happen.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system prepares security responses in advance by pre-identifying potential threats and establishing containment procedures. When suspicious behavior is detected, pre-configured security measures are immediately activated to cushion against the potential impact of the attack, reducing the window of vulnerability before formal detection and response.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If bad actors are allowed to perform malicious activities such as data exfiltration, then network security monitoring is maintained, but network resource consumption increases and throughput reduces

Engineering Contradiction:
Improvenetwork security monitoringVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system identifies and addresses potential security threats before they manifest as full-scale attacks. By detecting anomalous behavior patterns early in the attack lifecycle, the system can prevent malicious activities from consuming network resources, thereby maintaining both security monitoring capabilities and normal network throughput.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts potentially harmful malicious activities into beneficial security improvements. By analyzing attack patterns and behavior anomalies, the system learns from attempted attacks to improve its detection capabilities, turning what would be resource-consuming attacks into opportunities for enhancing overall network security and performance.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS12028363B2Detecting bad actors within information systems
Publication Date: 2024.07.02 BANK OF AMERICA CORP
  • US12028363B2 patent drawing
  • US12028363B2 patent drawing
  • US12028363B2 patent drawing

AI summary

A device that is configured to receive user activity information from a network device. The user activity information includes information about user interactions with the network device for a plurality of users. The device is further configured to input the user activity information into a machine learning model. The machine learning model is configured to receive user activity information and to output a set of bad actor candidates based on the user activity information. The set of bad actor candidates identifies one or more users from among the plurality of users. The device is further configured to receive the set of bad actor candidates from the machine learning model and to output the set of bad actor candidates.