Probabilistic Insider Threat Detection via Dynamic Behavior Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing insider threat detection systems are inflexible, require pre-defined rules and models, and struggle to adapt to uncertainties and fluctuations in normal behavior, leading to false alarms and inability to detect unknown threats.

Innovation Solution

A probabilistic programming-based system that learns normal behavior patterns automatically, adapts to changes, and computes anomaly scores without pre-defined rules, using dynamic models to identify deviations in user activities across multiple attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If pre-defined rules and models are used for insider threat detection, then the detection process is simple and straightforward, but the system cannot adapt to uncertainties and fluctuations in normal behavior, leading to false alarms and inability to detect unknown threats

Engineering Contradiction:
Improveadaptability to behavior fluctuationsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic probabilistic programming models that continuously learn and adapt to changing normal behavior patterns. The system transitions from static pre-defined rules to dynamic models that evolve with organizational behavior, allowing it to accommodate fluctuations and uncertainties in user activities while maintaining detection effectiveness.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically learns and adjusts probability distributions and parameters from observed behavior data. Instead of using fixed thresholds and rules, the model dynamically updates its understanding of normal behavior by changing its internal parameters based on accumulated evidence, enabling adaptation to new patterns without manual reconfiguration.

Inventive Principle:
Principle #35Parameter changes

2Extent of automation

If pre-defined rules and models are used for insider threat detection, then the deployment process is straightforward, but the system requires manual configuration and cannot learn organizational-specific patterns automatically

Engineering Contradiction:
Improveautomatic pattern learningVSAvoiddeployment time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The system performs self-configuration by automatically learning organizational behavior patterns from observed data. The probabilistic programming model autonomously adapts to the specific organizational context without requiring manual setup or customization, enabling the organization to deploy the system immediately and have it learn its unique patterns over time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system is designed with pre-configured probabilistic programming frameworks and detection methodologies that are ready to deploy. These preliminary configurations include the structural model for behavior analysis, which then automatically populates organization-specific parameters through learning, eliminating the need for time-consuming custom model building.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If static Bayesian networks are used for insider threat detection, then the model structure is stable and easy to maintain, but the model cannot reflect fluctuations and changes in normal activities

Engineering Contradiction:
Improvemodel stabilityVSAvoid responsiveness to behavior changes
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static Bayesian network into a dynamic probabilistic programming model that continuously updates its probability distributions and parameters. The model maintains structural stability through its Bayesian framework while allowing its internal representations of normal behavior to evolve dynamically, reflecting both model stability and behavioral adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements continuous feedback loops where observed behavior data is constantly fed back into the probabilistic model to update its understanding of normal patterns. This feedback mechanism allows the model to maintain stability through controlled adaptation, adjusting its parameters based on accumulated evidence while preserving the core detection framework.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20230269264A1Probabilistic evidence based insider threat detection and reasoning
Publication Date: 2023.08.24 VIRGINIA TECH INTELLECTUAL PROPERTIES INC
  • US20230269264A1 patent drawing
  • US20230269264A1 patent drawing
  • US20230269264A1 patent drawing

AI summary

The main enabler of the technology is the probabilistic programming based computation strategies that have an outstanding ability to handle uncertainties in discovering anomalous patterns. This new capability to handle uncertainties is particularly relevant for detecting insider threats, as there are usually no clearly defined rules and policies. An insider's behaviors would deviate from normally distributed events and actions in various aspects. The probabilistic model detects this deviation and explains the computational path of the deviation. The result interpretation unit enables organizations to investigate the causes with high accuracy, avoiding costly and embarrassing false alarms. The technology detects and ranks abnormal events. This ranking capability helps prioritize follow-up manual investigation.