User Account Compromise Detection via Behavioral Baseline Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large networks with tens of thousands of user accounts face challenges in maintaining the sanctity of private information due to the complexity of monitoring network interactions and detecting compromised user accounts, making them vulnerable to malicious access.

Innovation Solution

A system that determines user compromise scores by analyzing network actions, comparing them to average and historical behavior, and providing interactive interfaces for administrators to identify and review potentially compromised accounts, thereby enhancing network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security measures (firewalls, encryption, access control) are implemented, then basic network security is improved, but the system remains vulnerable to compromised user accounts and sophisticated attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidmalicious access through compromised accounts
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and establishing baseline behavior patterns for each user account before attacks occur. It proactively identifies anomalies and potential compromises by comparing current actions against historical baselines, enabling early detection and response to security threats before they can cause significant harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously analyzing user behavior patterns and providing real-time alerts when anomalous activities are detected. The system feeds back compromise scores and behavior anomalies to security administrators, enabling dynamic adjustment of security responses based on observed patterns rather than static rules.

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If comprehensive monitoring of all user accounts is implemented, then detection capability is improved, but system complexity and resource requirements increase significantly

Engineering Contradiction:
Improveuser account compromise detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system applies local quality by creating individualized behavior baselines for each user account rather than applying uniform monitoring rules. Each user's normal behavior patterns, access times, and interaction methods are customized and stored as unique baselines, allowing the system to detect anomalies specific to each account while reducing false positives from generic monitoring approaches.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system utilizes parameter changes by dynamically calculating compromise scores based on multiple behavioral parameters (login times, access patterns, resource usage). These scores change continuously as new data is collected, allowing the system to adapt its detection sensitivity and prioritize monitoring resources on accounts showing increasing anomaly levels rather than uniformly monitoring all accounts at maximum intensity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If detailed analysis of all user account behaviors is performed, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvecompromise detection accuracyVSAvoidreview and analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments the monitoring task by dividing user behavior analysis into distinct components: baseline establishment, real-time anomaly detection, and detailed investigation. The baseline capture phase collects comprehensive data during normal operation, the detection phase quickly compares current actions against stored baselines to generate compromise scores, and the investigation phase provides detailed analysis only for accounts flagged as potentially compromised, reducing overall processing time while maintaining accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by performing full detailed analysis only on user accounts that exceed compromise score thresholds, rather than analyzing all accounts equally. The majority of accounts receive lightweight monitoring that quickly compares actions against baselines, while only those showing significant anomalies trigger comprehensive detailed review, optimizing the balance between detection accuracy and processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11470102B2Anomalous network monitoring, user behavior detection and database system
Publication Date: 2022.10.11 PALANTIR TECHNOLOGIES INC
  • US11470102B2 patent drawing
  • US11470102B2 patent drawing
  • US11470102B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for network monitoring, user account compromise determination, and user behavior database system. The system monitors network actions of user accounts including user account access across multitudes of network accessible systems, determines user account transitions, and determines different types of high-risk user behavior indicative of compromise. Network actions can be obtained from generated information by the network accessible systems, and correlated across additional data sets including contextual ones. User interfaces are generated describing network actions of user accounts, and are configured for user interaction, which cause generation of updated user interfaces and access to electronic data sources to determine information relevant to the user interaction.