Network Security Risk Assessment via Dynamic User Behavior Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems struggle to detect security risks for unknown attack patterns and cannot differentiate between legitimate and impersonated users, as they require predefined attacker behavior patterns.

Innovation Solution

A system that builds behavior models for users based on their interactions, comparing user events to these models to calculate a risk assessment, incorporating factors like client devices, server access, resource usage, time patterns, geo-location, and threat intelligence to identify anomalies and assign risk scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If predefined attacker behavior patterns are used for security detection, then the system can detect known attack patterns, but it cannot detect unknown attack patterns or impersonated users

Engineering Contradiction:
Improvedetection capability for unknown attack patternsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically adapts its detection approach by transitioning from static predefined patterns to dynamic behavior modeling. Behavior models are continuously updated based on observed user activities, allowing the system to adapt to both known and unknown attack patterns while maintaining manageable complexity through automated learning processes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the detection parameters from fixed attack signatures to flexible behavior metrics. By monitoring multiple parameters such as login times, accessed resources, device identifiers, and activity patterns, the system can detect deviations from normal behavior regardless of whether the attack pattern is previously known, resolving the contradiction between detection versatility and system complexity

Inventive Principle:
Principle #35Parameter changes

2Productivity

If administrators manually build queries against IT databases to determine security risks, then they can detect specific predefined risks, but they cannot detect risks outside predefined patterns and require significant time and effort

Engineering Contradiction:
Improvesecurity risk detection efficiencyVSAvoidcomprehensive security coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs self-service by automatically building and executing behavior models without requiring administrator intervention for each detection scenario. The automated system continuously monitors user behavior, updates behavior models, and generates risk assessments, significantly improving productivity while maintaining comprehensive security coverage through continuous automated analysis

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where detection results and observed behaviors continuously refine the behavior models. This automated feedback mechanism ensures both high productivity through automation and comprehensive reliability by continuously adapting to new threat patterns and user behaviors without manual reconfiguration

Inventive Principle:
Principle #23Feedback

3Speed

If the system monitors all user events and compares them to behavior models in real-time, then it can detect security risks promptly, but it consumes significant computational resources

Engineering Contradiction:
Improvereal-time risk detection speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring by focusing computational resources on events that deviate from established behavior models rather than analyzing every single user event in equal detail. By identifying and deeply analyzing only the anomalous events while efficiently processing normal events, the system achieves real-time detection speed with reduced computational resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10803183B2System, method, and computer program product for detecting and assessing security risks in a network
Publication Date: 2020.10.13 EXABEAM INC
  • US10803183B2 patent drawing
  • US10803183B2 patent drawing
  • US10803183B2 patent drawing

AI summary

The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.