Tensor Model for Abnormal User Behavior Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud platform systems face significant security threats due to abnormal user behavior, which existing methods struggle to detect effectively, leading to potential data theft and malicious attacks.

Innovation Solution

The implementation of a tensor model-based system that generates a behavioral profile for users, adapts based on user feedback, and performs security actions to protect against abnormal behavior, integrating feedback to refine the model and reduce false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing detection methods are used to identify abnormal user behavior, then security threats can be detected, but the false positive rate is high and evolving malicious attacks are missed

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where user responses to alerts are collected and used to continuously refine the tensor model. The model adapts by incorporating feedback signals that indicate whether detected abnormal behaviors were true positives or false positives, thereby improving detection precision while reducing false positive rates over time

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent employs tensor factorization techniques that dynamically adjust model parameters based on incoming user behavior data and feedback. The system changes detection thresholds and behavioral patterns by updating tensor decompositions, allowing it to adapt to evolving malicious attacks while maintaining reliable detection accuracy

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If traditional security methods are applied, then some security threats are detected, but evolving malicious attacks cannot be effectively identified

Engineering Contradiction:
Improveability to detect evolving attacksVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent creates a dynamic detection system where the tensor model continuously evolves by incorporating new user behavior data and feedback. The system adapts its detection criteria in real-time, allowing it to identify evolving malicious attacks while maintaining precision through iterative refinement based on actual attack patterns observed in the cloud environment

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If a static detection model is used, then implementation is simpler, but the system cannot adapt to new attack patterns

Engineering Contradiction:
Improvemodel implementation simplicityVSAvoidadaptability to new attacks
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a self-service detection system where the tensor model automatically refines itself through feedback from user responses. The system performs self-adjustment by incorporating new data patterns and attack signatures without requiring manual reconfiguration, maintaining implementation simplicity while achieving continuous adaptation to new threats

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11075933B1Abnormal user behavior detection
Publication Date: 2021.07.27 CA TECH INC
  • US11075933B1 patent drawing
  • US11075933B1 patent drawing
  • US11075933B1 patent drawing

AI summary

A method for detecting and protecting against abnormal user behavior is described. The method may include generating a tensor model based on a set of user information within a temporal period. The tensor model may include a behavioral profile associated with a user of a set of users. In some examples, the method may include determining that a behavior associated with the user of the set of users is abnormal based on the tensor model, adapting the tensor model based on feedback from an additional user of a set of additional users different from the set of users, and performing a security action on at least one computing device to protect against the abnormal user behavior based on the adapting.