3D Network Anomaly Dashboards for Rapid Pattern Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional user behavior analysis (UBA) struggles to identify critical behavior anomalies across large enterprise networks with hundreds to thousands of users, as generalized organizational rules fail to detect deviations in typical yet potentially malicious patterns, making it difficult for security analysts to rapidly discover and react to threats.
Innovation Solution
A digital fingerprinting (DFP) workflow using artificial intelligence and machine learning to generate fine-grained, unsupervised behavior models for each account, analyzing day-to-day activities to identify user-specific anti-patterns, with tunable parameters for customizable threat detection and explainability, and deploying models at various granularities to reduce false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional generalized organizational rules are used for user behavior analysis, then the system is simple to implement, but it fails to detect deviations in typical yet potentially malicious patterns across large enterprise networks
Solution Approach 1:
The patent segments the enterprise network into multiple organizational units (OUs) and creates separate behavior models for each OU. This allows the system to analyze user behavior at a granular level while maintaining manageability. Each OU gets its own baseline model trained on historical data, enabling precise detection of anomalies specific to that unit without requiring a single complex model for the entire enterprise.
Solution Approach 2:
The patent introduces a hierarchical dimension to the analysis by implementing models at multiple levels: individual user level, organizational unit level, and enterprise level. This multi-dimensional approach allows the system to detect anomalies that might be invisible at any single level, improving detection accuracy while distributing computational complexity across multiple manageable models.
2Measurement precision
If fine-grained behavior models are generated for each account using AI/ML, then anomaly detection accuracy improves, but the computational complexity and resource requirements increase
Solution Approach 1:
Instead of creating one complex enterprise-wide model, the system segments modeling into multiple smaller OU-level models and user-level models. Each model is trained on relevant historical data for its specific scope, making them computationally manageable while collectively providing comprehensive coverage. This segmentation reduces the complexity of individual models while maintaining high detection accuracy through aggregated insights.
Solution Approach 2:
The system performs preliminary action by pre-training baseline behavior models for each organizational unit using historical data before actual threat detection begins. These pre-trained models establish normal behavior patterns in advance, so when real-time analysis is needed, the system only needs to compare current behavior against established baselines rather than performing full analysis from scratch, reducing computational complexity during operation.
3Reliability
If comprehensive analysis of every account login and application activity is performed, then detection capability improves, but the ability to rapidly identify critical behavior anomalies for security analysts deteriorates due to information overload
Solution Approach 1:
The system extracts and focuses on the most critical anomalies by comparing user behavior against OU-level baseline models. Instead of presenting all detected deviations to analysts, the system identifies and extracts only those anomalies that represent significant deviations from established patterns, filtering out noise and presenting a prioritized list of critical threats that require immediate attention.
Solution Approach 2:
The patent implements local quality by creating behavior models tailored to each specific organizational unit's characteristics rather than applying a uniform enterprise-wide model. Each OU model learns the specific normal behavior patterns of its users, allowing the system to detect anomalies with high precision relevant to that local context. This reduces false positives and ensures analysts receive high-quality, context-relevant alerts.
4Adaptability or versatility
If generalized organizational rules are used, then false positives are reduced through simple rule-based detection, but the system cannot detect novel threats that deviate from established patterns
Solution Approach 1:
The system implements dynamics by using machine learning models that continuously adapt to changing user behavior patterns. Unlike static rule-based systems, these models learn from historical data and evolve their understanding of normal behavior over time. This allows the system to detect novel threats that deviate from established patterns while maintaining reliability through continuous adaptation to legitimate behavior changes.
Solution Approach 2:
The patent applies parameter changes by training models on historical behavior data to establish dynamic baselines for each organizational unit. These baselines capture the normal range of behavior parameters for each OU, allowing the system to detect anomalies when behavior falls outside these dynamically determined parameters. This approach provides both versatility in detecting various threat types and reliability through statistically grounded detection thresholds.
Data Source
AI summary
Technologies for generating a graphical user interface (GUI) dashboard with a three-dimensional (3D) grid of unit cells are described. An anomaly statistic can be determined for a set of records. A subset of network address identifiers can be identified and sorted according to the anomaly statistic. The subset can have higher anomaly statistics than other network address identifiers. There can be a maximum number in the subset. The GUI dashboard is generated with unit cells organized by the subset of network address identifiers as rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights. Each unit cell is a colored, 3D visual object representing a composite score of anomaly scores associated with zero or more network access events corresponding to the respective network address identifier at the respective time interval. The GUI dashboard is rendered on a display.


