Multi-Dimensional Visualization for Unauthorized User Action Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack effective methods to detect and prevent unauthorized user actions, particularly in scenarios where sensitive data is transmitted or accessed across various local and remote sources, posing a risk to confidential information.
Innovation Solution
A system that identifies and monitors objects and user events, maps them to separate hyperplanes in a multi-dimensional visualization, applies forces to detect malicious user movements, and executes security commands to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional monitoring methods are used to track user actions, then system simplicity is maintained, but detection precision of unauthorized actions deteriorates
Solution Approach 1:
The patent transforms user action monitoring from traditional flat logging into a multi-dimensional visualization space where objects represent users, events, and data. By mapping these elements into dimensional space with multiple hyperplanes, the system enables sophisticated detection of unauthorized actions through spatial relationships and patterns that would be invisible in traditional monitoring approaches.
Solution Approach 2:
The patent introduces an intermediary visualization layer between raw user actions and security detection. This intermediate representation maps users, events, and data into a shared dimensional space, allowing complex security analysis to be performed on the transformed data while keeping the underlying monitoring system relatively simple.
2Reliability
If comprehensive user actions are monitored to improve security, then security reliability is improved, but loss of time for processing increases
Solution Approach 1:
The patent performs preliminary mapping of users, events, and data into the dimensional visualization space in advance. This pre-processing organizes the data structure so that when security events need to be detected, the system can quickly query spatial relationships and patterns without having to process raw logs from scratch, thereby reducing real-time processing time while maintaining comprehensive monitoring.
Solution Approach 2:
The patent replaces traditional mechanical log-analysis methods with a field-based dimensional modeling approach. By representing users, events, and data as objects in a continuous dimensional space with associated fields, the system enables more efficient querying and pattern recognition compared to sequential log processing, reducing the time penalty of comprehensive monitoring.
3Difficulty of detecting and measuring
If multi-dimensional visualization is applied to map user actions, then detection capability is improved, but device complexity increases
Solution Approach 1:
The patent segments the complex dimensional visualization into separate hyperplanes, each dedicated to specific types of objects (users, events, data). This segmentation allows the system to manage complexity by organizing the visualization into manageable, specialized layers rather than attempting to display all information in a single undifferentiated space.
Solution Approach 2:
The patent creates a universal dimensional visualization framework that can represent multiple types of security-relevant objects (users, events, data) within the same spatial system. This multi-functional approach allows a single visualization infrastructure to handle diverse monitoring needs, reducing overall system complexity compared to maintaining separate specialized systems for each object type.
Data Source
AI summary
In some examples, a system or detecting unauthorized user actions can include a processor to identify a plurality of objects and at least one user event to be monitored. The processor can also map the plurality of objects and the at least one user event to separate hyperplanes of a multi-dimensional visualization and apply at least one force to the plurality of objects. Additionally, the processor can detect as malicious user based on a movement of at least one of the objects as a result of applying the at least one force, and execute a security command to prevent the malicious user from accessing data.


