Security Profile Generation Using Weighted Actor Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems face challenges in generating security profiles for newly discovered actors within computing environments, as they lack previous behavior data to define expected behavior, and often apply the same expected behavior to all members of a group, failing to customize profiles based on each actor's unique position in the network.

Innovation Solution

The method involves creating a weighted graph that connects new actors to other actors, using this graph to generate customized security behavior profiles based on the actor's position, and detecting anomalies by comparing actual behavior against the defined profile, with remedial actions taken when deviations are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If security systems use generic expected behavior for all actors, then system complexity is reduced, but security monitoring precision deteriorates

Engineering Contradiction:
Improvesecurity profile management complexityVSAvoidanomaly detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by creating customized security behavior profiles for each actor based on their specific position in the organizational hierarchy. Instead of using a single generic profile for all actors, the system generates location-specific profiles that reflect the unique expected behaviors of actors at different positions (e.g., HR department vs. Engineering department), thereby improving anomaly detection precision without requiring overly complex manual configuration for each actor.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary action by automatically generating security behavior profiles for new actors before they begin their activities. When a new actor is detected in the computing environment, the system proactively creates their security profile by analyzing their position in the organizational graph and copying behavior patterns from similar existing actors, enabling immediate security monitoring without waiting for historical behavior data to accumulate.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If security systems create customized profiles for each actor position, then anomaly detection precision improves, but device complexity increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsecurity profile management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies copying by generating security behavior profiles for new actors through copying and adapting profiles from existing actors with similar positions in the organizational hierarchy. The system identifies actors at comparable hierarchical levels and job functions, copies their behavior patterns, and adjusts them to fit the new actor's specific context. This approach enables customized profile creation without requiring complex manual configuration for each new actor.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system applies universality by creating a reusable organizational graph structure that captures hierarchical relationships and job function categories. This universal framework serves multiple purposes: it enables automatic profile generation, supports position-based customization, and provides a scalable foundation for onboarding new actors. The same organizational graph structure is used across the entire enterprise, making the system manageable despite the customization it enables.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If security systems lack behavior data for new actors, then system operation is simpler, but security profile reliability deteriorates

Engineering Contradiction:
Improvenew actor onboarding simplicityVSAvoidsecurity profile reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies self-service by enabling the security system to automatically generate behavior profiles for new actors without requiring manual input or historical data from the new actor themselves. The system autonomously analyzes the organizational graph, identifies comparable existing actors, copies their behavior patterns, and creates a functional security profile immediately upon detecting the new actor's presence in the computing environment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The organizational graph serves as an intermediary that bridges the gap between existing actors and new actors. Instead of requiring direct behavior data from the new actor (which doesn't exist yet), the system uses the organizational graph as a mediator to transfer behavior patterns from comparable existing actors to the new actor's profile. This intermediary structure enables reliable profile generation while maintaining ease of operation for new actor onboarding.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9798876B1Systems and methods for creating security profiles
Publication Date: 2017.10.24 GEN DIGITAL INC
  • US9798876B1 patent drawing
  • US9798876B1 patent drawing
  • US9798876B1 patent drawing

AI summary

A computer-implemented method for creating security profiles may include (1) identifying, within a computing environment, a new actor as a target for creating a new security behavior profile that defines expected behavior for the new actor, (2) identifying a weighted graph that connects the new actor as a node to other actors, (3) creating, by analyzing the weighted graph, the new security behavior profile based on the new actor's specific position within the weighted graph, (4) detecting a security anomaly by comparing actual behavior of the new actor within the computing environment with the new security behavior profile that defines expected behavior for the new actor, and (5) performing, by a computer security system, a remedial action in response to detecting the security anomaly. Various other methods, systems, and computer-readable media are also disclosed.