Predictive Security Model for Off-Premises Storage Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The heterogeneity of data sources in off-premises storage, such as cloud storage, makes it complex to create an efficient baseline for anomaly and malfunctioning detection, leading to high false-positive rates and potential vulnerabilities due to ignored alerts for rarely accessed accounts.

Innovation Solution

A method and system for classifying off-premises transactions using a security model learned from transaction data associated with on-premises storage, which is adapted based on activity detected on off-premises storage, reducing false positives by dynamically creating a predictive security model for anomaly detection without requiring substantial investment in complex models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex predictive security models are built for off-premises storage anomaly detection, then detection accuracy may improve, but system complexity and resource requirements increase substantially

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidmodel complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by training the predictive security model on on-premises storage data first, then applying this pre-trained model to off-premises storage anomaly detection. This intermediary training phase allows the model to learn from richer data sources without requiring complex model architecture for the actual off-premises detection task.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the predictive security model trained on on-premises data and applies it to off-premises storage. Instead of building a new complex model for off-premises storage, the system copies and reuses the model structure and learned patterns from the on-premises environment, significantly reducing complexity requirements.

Inventive Principle:
Principle #26Copying

2Device complexity

If hand-crafted rules or simple baselines are used for security anomaly detection, then system complexity is reduced, but false positive rates increase and detection precision deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidanomaly detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary action by pre-training the predictive security model on on-premises storage transaction data before deploying it to off-premises storage. This preliminary training phase allows the model to learn accurate patterns and baselines in advance, improving detection precision when applied to the actual off-premises environment without requiring complex real-time processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses self-service by automatically learning security patterns and adapting the predictive model based on monitored transactions from off-premises storage. Instead of relying on manually crafted rules, the model autonomously improves its detection precision by learning from actual transaction data, reducing false positives without increasing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If security models are adapted based on detected activity on off-premises storage, then detection accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidmodel adaptation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic action by adapting the predictive security model at intervals based on monitored transactions rather than continuously in real-time. The model is updated periodically with new transaction data from off-premises storage, maintaining detection accuracy while avoiding the continuous computational overhead of real-time adaptation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3465515B1Classifying transactions at network accessible storage
Publication Date: 2021.11.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3465515B1 patent drawingFigure 1
  • EP3465515B1 patent drawingFigure 2
  • EP3465515B1 patent drawingFigure 3

AI summary

A computerized method of classifying network accessible storage transactions at network accessible storage. The method comprises obtaining an client predictive security model for anomaly or malfunctioning detection, the client predictive security model is dynamically created by an analysis of a plurality of client transactions made to access target data stored in an client computing device, monitoring a plurality of network accessible storage transactions made to access a replica of the target data when the replica is stored in an network accessible storage, and classifying at least some of the plurality of network accessible storage transactions based on the client predictive security model.