Multi-Context ML Anomaly Detection for File-Less Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional perimeter defenses for corporate IT networks are failing to effectively identify and counter 'file-less' attacks, as they do not account for human behavior and are not well-suited to detect subtle nuances in user behavior indicative of attacker control.

Innovation Solution

A computer-implemented method using machine learning to create baseline models of normal user behavior across multiple contexts, detecting anomalies by comparing new events to these models, and initiating remedial actions when anomalies are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter defenses are used, then network security is maintained through established boundaries, but detection of subtle user behavior anomalies indicative of file-less attacks is ineffective

Engineering Contradiction:
Improvedetection effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical perimeter defense mechanisms with a machine learning-based behavioral analysis system. Instead of relying on static boundary controls, the system uses multi-context machine learning models to dynamically analyze user behavior patterns, event sequences, and contextual relationships to detect anomalies indicative of file-less attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the detection parameters from static perimeter-based controls to dynamic behavioral metrics. It monitors and analyzes multiple parameters including user interaction patterns, event timing, sequence of operations, and contextual relationships, transforming the detection approach from boundary-based to behavior-based parameters.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multi-context machine learning models are implemented, then detection precision for subtle behavior nuances is improved, but computational complexity and data processing requirements increase

Engineering Contradiction:
Improvebehavior anomaly detection precisionVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex detection task into multiple independent context models (user context, device context, network context, temporal context). Each context model processes specific aspects of behavior independently, allowing parallel computation and reducing the complexity of any single model while maintaining high overall detection precision through integrated analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds contextual dimensions to the analysis by creating multi-layered baseline models that incorporate user-specific, device-specific, network-specific, and temporal contexts. This dimensional expansion allows the system to detect subtle anomalies that would be invisible in single-dimension analysis, improving precision without requiring exponentially more computational resources.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If user-centric detection techniques are applied, then identification of attacker control is improved, but processing time and resource requirements increase

Engineering Contradiction:
Improveattacker detection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously building and maintaining baseline behavioral models for each user across multiple contexts. These pre-computed baselines capture normal user behavior patterns, device usage, network interactions, and temporal patterns, enabling rapid real-time anomaly detection without requiring intensive processing during actual security events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The machine learning models perform self-service by automatically adapting to individual user behaviors and updating baselines continuously. The system learns and adjusts to legitimate user patterns autonomously, reducing the need for manual configuration and enabling rapid detection of deviations from established baselines without requiring extensive processing resources during operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11558408B2Anomaly detection based on evaluation of user behavior using multi-context machine learning
Publication Date: 2023.01.17 EMC IP HLDG CO LLC
  • US11558408B2 patent drawing
  • US11558408B2 patent drawing
  • US11558408B2 patent drawing

AI summary

Methods, apparatus, and processor-readable storage media for evaluating cyber attacker behavior using machine learning to identify anomalies are provided herein. An example method includes obtaining, based on events associated with changes in one or more of a registry and a computer process, baseline models comprising a user context representing normal behavior for a first subset of features associated with the events with respect to a given user, an inverse context that represents normal behavior for at least one feature with respect to a particular value of one or more features in the first subset, and a global context representing a behavior of the features across the plurality of users; detecting a new event attributable to the given user; calculating a score for the new event using one or more of the baseline models; and determining that the new event is an anomaly in response to the score satisfying a threshold.