Synthetic Insider Attack Data Generation with GANs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer networks face challenges in identifying insider attacks, which are relatively rare and difficult to detect due to the scarcity of data, leading to a high number of false positives and low detection accuracy.

Innovation Solution

Generate synthetic insider attack data using Generative Adversarial Networks (GANs) to augment the available data, combining actual insider attack images with context images to create additional synthetic images, thereby training a more accurate insider attack detection model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If actual insider attack data is used to train detection models, then detection accuracy improves, but the scarcity of insider attack data limits model training effectiveness

Engineering Contradiction:
Improvedetection accuracyVSAvoidamount of training data
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent uses Generative Adversarial Networks (GANs) to create synthetic copies of insider attack data. The generator network produces artificial attack samples that mimic real attack patterns, while the discriminator network evaluates their authenticity. This copying approach multiplies the available training data without requiring additional real attacks to occur.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent modifies various parameters of the synthetic data generation process, including noise levels, attack vectors, and contextual variations. By changing these parameters during training, the system generates diverse attack scenarios that improve model robustness while maintaining the core characteristics of insider threats.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional detection methods are used, then false positives occur frequently, but advanced synthetic data training reduces false positives

Engineering Contradiction:
Improvefalse positive rateVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces synthetic attack data as an intermediary between real attack data and the detection model. This intermediate training layer helps the model learn distinguishing features of attacks versus legitimate user behavior, reducing false positives when deployed on real data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary training with synthetic data before deploying the model on real data. This preliminary action prepares the model to recognize attack patterns and differentiate them from normal behavior, reducing false positives in production.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If more insider attack data is collected, then training quality improves, but insider attacks are rare events making data collection difficult

Engineering Contradiction:
Improvetraining qualityVSAvoiddata collection efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

Instead of waiting to collect more real attack data through time and monitoring, the system copies existing attack patterns through GAN synthesis. This approach achieves data multiplication without requiring prolonged data collection periods or encountering additional rare attack events.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary data generation using available attack samples before actual detection deployment. This preliminary action creates a sufficient training dataset in advance, eliminating the need for extended data collection periods.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250232032A1Systems and methods for generating synthetic data representing insider attacks
Publication Date: 2025.07.17 FORTINET INC
  • US20250232032A1 patent drawing
  • US20250232032A1 patent drawing
  • US20250232032A1 patent drawing

AI summary

Systems, methods, devices, and apparatus are discussed for generating data that appears to be an insider attack.