Ontology-Based Packet Tracking for Reliable UEBA Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user and entity behavior analytics (UEBA) systems are ineffective due to compromised or manipulated authentication logs from NTLM, Kerberos, and SAML/OAuth2 protocols, leading to false positives and negatives in threat detection and response, necessitating a system to verify authentication integrity and leverage observability for accurate cybersecurity analysis.
Innovation Solution
A system and method utilizing an ontological engine to create industry-specific ontologies, tag and track network packets, and compute risk scores based on data utilization tracking information and UEBA data, ensuring the integrity and validity of authentication objects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If authentication logs from NTLM, Kerberos, and SAML/OAuth2 protocols are used for UEBA systems, then the system can perform behavior analytics and threat detection, but the logs may be compromised or manipulated leading to false positives and negatives
Solution Approach 1:
The patent introduces an intermediary validation layer between authentication protocols and UEBA systems. This intermediary verifies authentication log integrity through cryptographic validation and anomaly detection before logs are consumed by UEBA systems, preventing compromised logs from causing false positives or negatives while maintaining threat detection productivity
Solution Approach 2:
The system implements feedback mechanisms where UEBA analysis results are fed back to validate authentication log integrity. When anomalies or false positives occur, the system traces back to verify log authenticity, creating a closed-loop validation system that continuously improves reliability without sacrificing detection capability
2Measurement precision
If comprehensive data characterization and utilization tracking is implemented across the enterprise network, then the fidelity of security analysis is improved, but the system complexity and resource requirements increase
Solution Approach 1:
The patent segments data characterization and tracking into modular components distributed across network infrastructure elements. Each segment handles specific data types or network zones independently, allowing comprehensive monitoring through organized divisions rather than monolithic complexity, thereby maintaining high analysis fidelity with manageable system architecture
Solution Approach 2:
The system implements universal data collection mechanisms that serve multiple security functions simultaneously. The same data characterization infrastructure supports threat detection, compliance auditing, and forensic analysis, reducing overall system complexity by eliminating redundant specialized systems while maintaining comprehensive security analysis capability
Data Source
AI summary
A system and method for comprehensive data utilization and tracking comprising an ontological engine which in some embodiments is configured to create and curate various industry-specific ontologies which can be used to provide deeper context to an enterprise's network traffic and data transmission. The system and method further comprise a tagging and tracking engine configured to inspect network packets, apply a first tag associated with an authentication object, apply a second tag associated with an identified ontology, and track the tagged packets as they traverse the enterprise network, generating data utilization tracking information as the packets move through the network. A scoring engine may leverage the data utilization tracking information in combination with user entity and behavior data to compute a risk score associated with data utilization on the enterprise network.


