Transaction-Based Intrusion Detection Using Behavioral Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems fail to utilize business intelligence and transactional behavior to detect malicious activity, particularly in cases where an attacker uses a legitimate user's credentials to access protected resources, as they primarily focus on technology-oriented characteristics rather than transactional data.

Innovation Solution

A system that analyzes current and past transactions to identify potential intrusions by forming transaction groups based on past behaviors and comparing them to current transactions, using a transaction analysis module and clustering module to detect deviations or similarities that indicate unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional intrusion detection systems use technology-oriented solutions focusing on characteristics of resources used for transactions, then they can detect attacks based on binary signatures and IP addresses, but they fail to detect malicious activity when attackers use legitimate user credentials

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidability to detect credential theft
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameters from technology-oriented characteristics (IP addresses, binary signatures) to transactional behavior parameters (transaction patterns, timing, sequences). This allows the system to detect intrusions even when attackers use legitimate credentials, because the behavioral parameters differ between authorized users and attackers impersonating users.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary layer (the intrusion detection system that analyzes transactional behavior) between the resource and the attacker. This intermediary monitors and analyzes transaction patterns without interfering with legitimate operations, enabling detection of malicious activity while maintaining normal system functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If conventional IDS monitor factors such as IP address ranges and binary signatures, then they can identify attack sources, but they do not utilize business intelligence or transactional behavior information

Engineering Contradiction:
Improveutilization of transactional informationVSAvoidsystem architecture
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent makes the intrusion detection system multi-functional by having it perform both traditional signature-based detection and transactional behavior analysis. This universal approach allows the system to utilize various types of information (technical characteristics and business intelligence) without requiring separate systems, thereby reducing information loss while managing complexity through integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges traditional intrusion detection capabilities with transactional behavior analysis into a single unified system. By combining these previously separate functions, the system can leverage both technology-oriented data and business intelligence simultaneously, improving detection accuracy without requiring multiple independent systems.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the system analyzes current transactions in real-time by comparing with past transaction groups, then it can detect intrusions effectively, but it requires processing and storing large amounts of transaction data

Engineering Contradiction:
Improveintrusion detection reliabilityVSAvoidtransaction data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and relevant features from transactional data for analysis, rather than processing the entire raw dataset. By identifying and focusing on key behavioral parameters and patterns, the system achieves reliable intrusion detection while reducing the computational burden and storage requirements associated with handling large volumes of transaction data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments transaction data into meaningful groups or clusters based on behavioral patterns, allowing the system to analyze representative samples rather than every individual transaction. This segmentation approach maintains detection reliability by focusing on characteristic patterns while significantly reducing the quantity of data that must be processed and stored.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8776228B2Transaction-based intrusion detection
Publication Date: 2014.07.08 CA TECH INC
  • US8776228B2 patent drawing
  • US8776228B2 patent drawing
  • US8776228B2 patent drawing

AI summary

Systems and methods are provided for intrusion detection. The systems and methods may include receiving transaction information related to one or more current transactions between a client entity and a resource server, accessing a database storing a plurality of transaction groups, analyzing the received transaction information with respect to information related to at least one of the plurality of transaction groups, and based on said analyzing, determining a possibility of an occurrence of an intrusion act at the resource server. The transaction groups may be formed based on a plurality of past transactions between a plurality of client entities and the resource server. Identity information of a user associated with the one or more current transactions may also be received along with the transaction information. The user may be associated with at least one of the plurality of transaction groups.