ML-Based UEBA System for Network Security Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Human operators in network security are prone to errors, there is a shortage of security experts, and existing security measures are often reactive and lag behind threats, leading to inaccurate classifications and a poor user experience.

Innovation Solution

Implementing a Machine Learning (ML)-based User and Entity Behavior Analysis (UEBA) system that combines multiple ML models, including a user grouping model, an orchestration model, behavior models, and an active learning model, to identify normal and abnormal user behavior, detect malicious insiders, and provide proactive security insights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If human operators perform security classification, then security expertise is applied, but accuracy is reduced due to human errors and insufficient expert availability

Engineering Contradiction:
Improveclassification accuracyVSAvoidsecurity expert availability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables automated self-service through ML models that independently perform behavior analysis, user grouping, and anomaly detection without requiring human security experts for each classification decision. The orchestration model automatically orchestrates multiple ML models to deliver accurate security classifications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual human classification is replaced with automated ML-based classification systems. The patent substitutes human operators with machine learning models including user grouping models, behavior models, and orchestration models that process security data automatically, eliminating human error and scaling beyond expert availability constraints.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional security measures are used, then implementation is straightforward, but security posture remains reactive and behind threats

Engineering Contradiction:
Improvesecurity postureVSAvoidresponse time to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously analyzing user behavior patterns and establishing baselines of normal activity before threats occur. The ML models proactively identify anomalies and potential security risks, enabling security teams to take preventive actions before actual breaches happen, transitioning from reactive to proactive security posture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where ML models analyze security events, learn from outcomes, and refine their behavior analysis capabilities. This feedback mechanism enables the system to adapt to new threats and improve detection accuracy over time, maintaining an up-to-date security posture that evolves with emerging threats.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple security alerts are generated, then comprehensive monitoring is achieved, but alert fatigue reduces effectiveness

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidalert management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges multiple ML models including user grouping models, behavior models, and orchestration models into a unified analysis framework. This consolidation integrates various security monitoring functions into a coordinated system that reduces redundant alerts while maintaining comprehensive monitoring coverage through synergistic model interactions.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20210392146A1Machine Learning-based user and entity behavior analysis for network security
Publication Date: 2021.12.16 ZSCALER INC
  • US20210392146A1 patent drawing
  • US20210392146A1 patent drawing
  • US20210392146A1 patent drawing

AI summary

Systems and methods include utilizing a grouping model to identify a function of a user of a tenant; utilizing one or more behavior models to identify normal behavior and abnormal behavior of the user based on the function; and utilizing an orchestration model with a plurality of rules to score one or more of current and historical behavior of the user, based on the one or more behavior models; and utilizing an active learning model to improve the efficiency of the orchestration model The systems and methods can further include causing a security technique based on the score. The systems and methods can further include providing feedback based on the score to the one or more behavior models.