User Behavior Attribution from Multi-Source Telemetry Logs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in attributing user behavior across multiple technical telemetry sources, as attackers often target low-risk assets to gain access to critical enterprise assets, making it difficult to monitor and secure internal networks effectively.
Innovation Solution
A method and system that collect and analyze log data from various telemetry sources, such as endpoint security applications, network logs, and identity management systems, to generate behavior attributes and create graphs representing user interactions, allowing for the estimation of security integrity by comparing user behavior to baseline activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If log data is collected from multiple telemetry sources to improve user behavior attribution accuracy, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The system segments the complex task of behavior attribution into distinct functional modules: a data collection module that gathers logs from multiple telemetry sources (endpoint security applications, network devices, cloud-based systems), a data processing module that extracts and normalizes activity data, and a behavior analysis module that generates behavior attributes. This segmentation allows each module to handle specific aspects of the complex process independently, improving measurement precision while managing system complexity through modular architecture.
Solution Approach 2:
The system introduces intermediary components including a standardized data format layer that mediates between diverse telemetry sources and the analysis engine, and a behavior attribute model that serves as an intermediary representation between raw log data and security decisions. These intermediaries simplify the integration of multiple data sources and reduce the complexity of cross-referencing information from different telemetry systems.
2Reliability
If comprehensive log data is collected from multiple sources to detect unusual activities, then security integrity is improved, but loss of time increases
Solution Approach 1:
The system performs preliminary actions by pre-defining behavior baselines for users and devices before security incidents occur. During normal operation, the system continuously collects and analyzes log data to establish what constitutes typical behavior patterns. When security events occur, the system compares them against these pre-established baselines, enabling rapid detection without requiring time-consuming analysis of all historical data, thus improving security integrity while reducing processing time.
Solution Approach 2:
The system applies partial action by focusing computational resources on analyzing only the specific subset of log data most relevant to detecting unusual activities, rather than processing all collected data uniformly. The behavior analysis module selectively examines activity data that deviates from established patterns, allowing the system to maintain high security integrity while minimizing the time lost to processing irrelevant data volumes.
3Reliability
If behavior attributes are generated and compared to reference behavior attributes to estimate security integrity, then reliability is improved, but loss of information increases
Solution Approach 1:
The system applies local quality by generating behavior attributes that capture specific, localized aspects of user and device behavior rather than attempting to represent all possible behaviors uniformly. Each behavior attribute focuses on particular dimensions of activity (e.g., access patterns, communication behaviors, application usage) with appropriate detail levels tailored to that specific aspect. This allows the system to maintain high reliability in security integrity estimation for each behavior dimension while minimizing information loss by not forcing all behaviors into a single oversimplified model.
Data Source
AI summary
Systems and methods for attributing user behavior from multiple technical telemetry sources are provided. An example method includes determining that the user has logged into the computing device, in response of the determination, collecting log data from a plurality of telemetry sources associated with the computing device, extracting, from the log data, activity data concerning activities of the computing device, analyzing the activity data to determine that the activity data are attributed to the user, generating, based on the activity data, behavior attributes of the user, associating the behavior attributes with a unique identifier of the computing device, and estimating security integrity of the computing device based on a comparison of the behavior attributes to reference behavior attributes. The reference behavior attributes include further behavior attributes determined using log data of at least one further computing device associated with the user.


