Unsupervised Anomaly Detection for User Behavior Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting internal information leakage in companies are inadequate as they rely on supervised learning, require a sufficient number of past incidents, and often result in false alarms due to threshold value settings, and impose resource burdens on PCs with additional agent programs.

Innovation Solution

A method using unsupervised learning to detect anomalies in document usage behavior by creating K clusters based on past behavior counters, comparing current and past patterns without the need for threshold settings, and leveraging existing agent software to monitor user behavior efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If supervised learning methods are used to detect information leakage, then detection accuracy can be improved with sufficient training data, but the system requires a sufficient number of past incident data which is rarely available and results in false alarms

Engineering Contradiction:
Improvedetection accuracyVSAvoidavailability of past incident data
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent inverts the traditional supervised learning approach by using unsupervised learning to detect anomalies without requiring labeled incident data. Instead of training the system to recognize known leakage patterns, the system learns normal behavior patterns and detects deviations from these patterns, effectively detecting information leakage without needing past incident data for training

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the fundamental parameter of the detection approach from supervised to unsupervised learning. This parameter change allows the system to operate effectively in data-scarce environments by learning behavioral patterns directly from normal user activities without requiring labeled incident data, thereby resolving the contradiction between detection accuracy and data availability

Inventive Principle:
Principle #35Parameter changes

2Difficulty of detecting and measuring

If additional agent software programs are installed to monitor user behavior, then detection capability is improved, but PC resources are burdened

Engineering Contradiction:
Improvebehavior monitoring capabilityVSAvoidPC resource consumption
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent makes the existing agent software perform multiple functions - not only its original security/anti-virus functions but also behavior monitoring for information leakage detection. By reusing the existing agent infrastructure and adding behavior analysis capabilities to it, the system improves detection capability without requiring additional dedicated monitoring software, thereby avoiding extra resource burden

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The existing agent software on user PCs serves itself by taking on additional monitoring responsibilities. Rather than installing new software, the system leverages the already-present agent programs to collect and report behavior data, allowing these agents to provide both their original functions and the new information leakage detection function without additional resource overhead

Inventive Principle:
Principle #25Self-service

3Reliability

If threshold values are set for behavior monitoring, then false alarms can be reduced, but the system requires careful threshold configuration and may miss subtle anomalies

Engineering Contradiction:
Improvefalse alarm rateVSAvoidthreshold configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic anomaly detection by continuously learning and adapting to user behavior patterns over time. Instead of using static threshold values that require manual configuration, the system dynamically adjusts what constitutes normal behavior based on ongoing observation, automatically adapting to changes in user habits and work patterns without requiring threshold reconfiguration

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where detected behaviors are continuously fed back into the learning model to refine behavior patterns. This feedback loop allows the system to automatically improve its detection accuracy over time by learning from both normal and anomalous behaviors, eliminating the need for manual threshold adjustment while maintaining low false alarm rates

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10657250B2Method and apparatus for detecting anomaly based on behavior-analysis
Publication Date: 2020.05.19 SAMSUNG SDS CO LTD
  • US10657250B2 patent drawing
  • US10657250B2 patent drawing
  • US10657250B2 patent drawing

AI summary

Provided are a method for detecting an anomaly based on behavior-analysis. The method comprises creating, by an apparatus for detecting an anomalous behavior of a user, K clusters, each cluster of the K clusters being created based on past behavior counters associated with one or more users, designating, by the apparatus, a cluster pattern of the each cluster of the K clusters, the cluster pattern indicating a representative behavior of the past behavior counters belonging to the each cluster, determining, by the apparatus, a past behavior pattern of a first user based on a first past behavior counters associated with the first user and the each cluster of the K clusters, obtaining, by the apparatus, a first current behavior counters associated with the first user based on monitoring information from an agent software program, the agent software program being installed on a computing device of the first user and monitoring behaviors associated with the first user, determining, by the apparatus, a current behavior pattern of the first user based on the first current behavior counters and the each cluster of the K clusters and detecting, by the apparatus, the anomalous behavior of the first user by comparing the past behavior pattern and the current behavior pattern of the first user.