ML Model Detecting Malicious SaaS Activity via Access Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The lack of communication between SaaS services used by an organization creates a security 'void' that can be exploited by malicious actors, and job titles often do not accurately reflect an individual's actual job role or changes in job responsibilities.

Innovation Solution

A machine learning model is trained using access information from SaaS management platforms to predict job titles and detect malicious activities by correlating access patterns with job roles, even across multiple SaaS services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If job titles are used to define responsibilities and authority, then clarity in the workplace is improved, but job titles do not accurately reflect actual job roles or changes in responsibilities

Engineering Contradiction:
Improveaccuracy of job title representationVSAvoidflexibility of job role changes
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary analysis of access patterns and user behavior before making job title assignments or updates. By pre-processing access data from multiple SaaS services and analyzing it through machine learning models, the system prepares accurate job role predictions in advance, ensuring that job titles reflect actual responsibilities before they are formally assigned or updated in the organization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where access patterns and user behaviors are monitored, analyzed, and used to update job title predictions over time. The machine learning models are retrained with new access data, creating a feedback mechanism that ensures job titles remain accurate and reflective of current responsibilities, automatically adapting to role changes without manual intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If SaaS services operate independently without communication, then service autonomy is maintained, but security vulnerabilities arise that can be exploited by malicious actors

Engineering Contradiction:
Improveservice autonomyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces a centralized machine learning-based analysis platform as an intermediary that receives access data from multiple independent SaaS services. This intermediary correlates access patterns across services without requiring the services themselves to communicate directly, maintaining their autonomy while enabling security analysis that spans across all services to detect malicious activities that would be invisible within individual services alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If access data from multiple SaaS services is collected and analyzed, then detection of malicious activities is improved, but data processing complexity increases

Engineering Contradiction:
Improvemalicious activity detection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system develops a universal machine learning framework that can process and analyze access data from multiple different SaaS services using a single, unified approach. The machine learning models are designed to handle diverse data formats and access patterns from various services through standardized processing pipelines, enabling multi-service analysis without requiring separate complex processing systems for each service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250133090A1Using machine learning to detect malicious activity based on information pertaining to accesses of data items
Publication Date: 2025.04.24 SEQUOIA BENEFITS & INSURANCE SERVICES LLC
  • US20250133090A1 patent drawing
  • US20250133090A1 patent drawing
  • US20250133090A1 patent drawing

AI summary

A machine learning model is trained using information pertaining to accesses of data items at a software-as-a-service (SaaS) management platform. A first training input is generated. The first training input includes first access data identifying a multiple data items accessed at the SaaS management platform by a subset of multiple user accounts associated with a client organization. A first target output is generated. The first target output indicates, for each of the subset of user accounts, whether an occurrence of malicious activity is detected at the SaaS management platform. The training data is provided to train the machine learning model on (i) a set of training inputs including the first training input, and (ii) a set of target outputs including the first target output.