Dynamic Threat Perception for Adaptive Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in real-time detection of anomalous access requests and insider threats due to the inability of static security rules to adapt to evolving threats and the high volume of user activity, leading to potential unauthorized access to resources.

Innovation Solution

A system that employs dynamic policies and behavior models to analyze security events in real-time, generating threat perception scores to allow, challenge, or deny access based on user behavior and policy compliance, using a distributed environment with agents, access management, and threat detection systems to monitor and manage user access effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security rules are used to monitor user access, then the system structure is simple and easy to implement, but the system cannot adapt to evolving threats and high volume user activity, leading to failed anomaly detection

Engineering Contradiction:
Improveadaptability to evolving threatsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security rules that automatically adapt to changing user behavior patterns and threat landscapes. The system continuously learns from historical access data and updates security policies in real-time, transforming static security configurations into dynamic, self-adjusting rules that evolve with emerging threats without requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs machine learning algorithms that enable automatic threat detection and anomaly identification without constant human intervention. The security system self-adjusts by continuously analyzing user behavior patterns, automatically updating risk assessments, and dynamically modifying access controls based on learned patterns, reducing the need for manual security rule management.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive monitoring of all user access requests is implemented, then threat detection capability is improved, but the processing time and computational resources increase significantly

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies risk-based monitoring that focuses computational resources on high-risk access requests rather than uniformly analyzing all requests. By assessing risk levels dynamically and intensively monitoring only those requests that exceed predetermined risk thresholds, the system achieves comprehensive threat detection capability while processing the majority of low-risk requests quickly with minimal computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements differentiated monitoring strategies that apply varying levels of analysis to different user access patterns. High-risk users or access types receive comprehensive real-time analysis, while low-risk patterns receive streamlined processing. This localized quality approach ensures thorough threat detection where needed while maintaining fast processing for routine operations.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If real-time analysis of user behavior is performed, then anomaly detection accuracy is improved, but the computational load and system resource consumption increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary analysis by pre-processing user behavior data and establishing baseline patterns in advance. Historical access patterns are analyzed beforehand to create user-specific profiles and normal behavior ranges, so that real-time anomaly detection can compare current requests against pre-computed baselines rather than analyzing all historical data in real-time, significantly reducing computational load during critical detection phases.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically adjusts analysis parameters and thresholds based on contextual factors such as user role, time of day, and risk level. The system changes the depth and granularity of behavior analysis adaptively, increasing precision when risks are detected while reducing parameter complexity during normal operations, thereby optimizing the balance between detection accuracy and computational resource consumption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11265329B2Mechanisms for anomaly detection and access management
Publication Date: 2022.03.01 ORACLE INT CORP
  • US11265329B2 patent drawing
  • US11265329B2 patent drawing
  • US11265329B2 patent drawing

AI summary

The present disclosure relates generally to threat detection, and more particularly, to techniques for managing user access to resources in an enterprise environment. Some aspects are directed to the concept of managing access to a target resource based on a threat perception of a user that is calculated using a rule or policy based risk for the user and a behavior based risk for the user. Other aspects are directed to preventing insider attacks in a system based on a threat perception for each user logged into the system that is calculated using a rule or policy based risk for each user and a behavior based risk for each user. Yet other aspects are directed to providing a consolidated view of users, applications being accessed by users, and the threat perception, if any, generated for each of the users.