Network Graph Anomaly Detection for Enterprise Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in distinguishing between authorized and unauthorized access to their network systems, particularly in remote work scenarios, where illicit sources may mimic authorized user behavior, leading to potential data breaches.

Innovation Solution

A method utilizing network graphs to identify access anomalies by generating baseline and current profiles based on access data, comparing them to detect anomalies, and providing flagged access information to an authentication system for security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If remote access is permitted to enable flexible work arrangements, then employee productivity and work flexibility are improved, but the risk of unauthorized access and data breaches increases

Engineering Contradiction:
Improvework flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing a baseline network graph profile of authorized user behavior patterns before remote access occurs. This baseline includes normal access times, locations, devices, and network paths. When remote access attempts are made, the system compares them against this pre-established baseline to detect anomalies, enabling early detection of unauthorized access while maintaining flexible remote work policies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary anomaly detection system that sits between the remote access infrastructure and the enterprise network. This intermediary layer monitors and analyzes access patterns without interfering with legitimate remote work, acting as a mediator that allows flexible access while blocking unauthorized attempts by comparing real-time access data against established baseline profiles.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional authentication methods are used to verify user identity, then system simplicity is maintained, but the ability to detect sophisticated unauthorized access attempts deteriorates

Engineering Contradiction:
Improveauthentication system simplicityVSAvoidaccess security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system employs self-service authentication where the baseline network graph profile automatically serves as the reference standard for verifying access legitimacy. The system autonomously compares current access patterns against the baseline without requiring manual configuration of security rules or complex authentication policies, maintaining simplicity while enhancing detection capability through automated behavioral analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the authentication approach by changing from static credential verification to dynamic behavioral parameter analysis. Instead of relying solely on traditional authentication parameters (passwords, tokens), the system monitors multiple behavioral parameters including access timing, network paths, devices, and patterns, comparing them against baseline profiles to dynamically assess authentication legitimacy, thereby improving security without significantly increasing system complexity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive monitoring of access patterns is implemented to detect anomalies, then security detection accuracy is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system creates a simplified copy or representation of the enterprise network's normal access patterns in the form of a baseline network graph profile. This baseline copy captures essential behavioral characteristics without replicating the full complexity of the actual network infrastructure. By comparing current access attempts against this simplified baseline model rather than analyzing every raw network parameter, the system achieves high detection accuracy while maintaining manageable system complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11848952B2Systems and methods for identifying access anomalies using network graphs
Publication Date: 2023.12.19 AETNA INC
  • US11848952B2 patent drawing
  • US11848952B2 patent drawing
  • US11848952B2 patent drawing

AI summary

In some instances, the disclosure provides a method for identifying access anomalies using network graphs. The method comprises obtaining access data for an entity, generating a network graph baseline profile based on the plurality of data elements, generating a network graph current profile based on the plurality of data elements, generating comparison data based on comparing the plurality of baseline network graphs with the one or more current network graphs and comparing the plurality of baseline nodes and the plurality of baseline edges with the plurality of current nodes and the plurality of current edges, determining, based on the comparison data, anomaly data comprising one or more flagged network accesses to the enterprise system, and providing the anomaly data indicating the flagged network accesses to an authentication system.