Anomalous User Behavior Risk Metric Calculation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for detecting anomalous behavior in data users are inefficient and delay the identification of high-risk activities, allowing cyber threats to go unmitigated due to the complexity of analyzing large volumes of data and distinguishing between benign and malicious behaviors.
Innovation Solution
A method and system that quantify risk associated with anomalous user behavior by tracking behavioral factors, calculating surprisal values, dynamic weights, and generating a risk metric to flag high-risk users and trigger security actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional manual analysis methods are used to detect anomalous user behavior, then security analysts can investigate security incidents with accumulated tools, but the process becomes time-consuming and inefficient when dealing with large volumes of data, allowing threats to go unmitigated
Solution Approach 1:
The patent replaces manual mechanical analysis by security analysts with an automated computer-based system that uses machine learning models and algorithms to detect anomalous user behavior, thereby eliminating time-consuming manual investigation while maintaining or improving detection accuracy
Solution Approach 2:
The patent introduces an intermediary automated analysis system that processes user behavior data between the data sources and security analysts, using surfisal calculations and risk metrics to filter and prioritize anomalies, reducing the time burden on analysts while improving detection precision
2Reliability
If the number of data users and data assets under observation increases, then comprehensive monitoring coverage is improved, but the complexity of detecting anomalous behavior increases exceptionally
Solution Approach 1:
The patent segments the complex detection problem into manageable components by analyzing individual user behavior patterns separately, calculating surfisal for specific behavioral factors, and evaluating each user's anomaly score independently, which allows the system to scale to large numbers of users without proportionally increasing overall system complexity
Solution Approach 2:
The patent changes the approach from analyzing complex multi-dimensional user behaviors to evaluating specific behavioral factors with calculated surfisal values and risk metrics, transforming the complexity management by parameterizing user behavior into measurable indicators that can be processed efficiently
3Measurement precision
If forensic investigation tools are used after security incidents are discovered, then detailed analysis of security incidents is possible, but cybercriminals have already accomplished their objectives and retrieved valuable information
Solution Approach 1:
The patent implements preliminary action by continuously monitoring and analyzing user behavior in real-time before security incidents occur, using automated anomaly detection to identify suspicious activities early, which enables preventive response rather than post-incident forensic analysis, thereby stopping cybercriminals before they can accomplish their objectives
Solution Approach 2:
The patent establishes a feedback loop where user behavior is continuously monitored, anomalous patterns are detected through automated analysis, and alerts are generated in real-time, creating a continuous improvement system that learns from new data and adjusts detection parameters, enabling timely response before threats materialize into full incidents
Data Source
AI summary
A system, method, and computer-readable medium for determining risk associated with anomalous behavior of a user on a computer network including receiving anomalous behavioral data corresponding to anomalous activity of the user on the computer network, determining surprisal values corresponding to one or more behavioral factors based on one or more of: one or more probabilities corresponding to one or more current values or one or more characteristics of the one or more behavioral factors, determining one or more dynamic weights corresponding to the one or more behavioral factors based at least in part on the one or more current values and historically expected values of the one or more behavioral factors for the user, and determining a risk metric corresponding to the anomalous activity of the user based on the surprisal values, the one or more dynamic weights, and static weights assigned to the one or more behavioral factors.


