Anomalous User Behavior Risk Metric Calculation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for detecting anomalous behavior in data users are inefficient and delay the identification of high-risk activities, allowing cyber threats to go unmitigated due to the complexity of analyzing large volumes of data and distinguishing between benign and malicious behaviors.

Innovation Solution

A method and system that quantify risk associated with anomalous user behavior by tracking behavioral factors, calculating surprisal values, dynamic weights, and generating a risk metric to flag high-risk users and trigger security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional manual analysis methods are used to detect anomalous user behavior, then security analysts can investigate security incidents with accumulated tools, but the process becomes time-consuming and inefficient when dealing with large volumes of data, allowing threats to go unmitigated

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis by security analysts with an automated computer-based system that uses machine learning models and algorithms to detect anomalous user behavior, thereby eliminating time-consuming manual investigation while maintaining or improving detection accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary automated analysis system that processes user behavior data between the data sources and security analysts, using surfisal calculations and risk metrics to filter and prioritize anomalies, reducing the time burden on analysts while improving detection precision

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the number of data users and data assets under observation increases, then comprehensive monitoring coverage is improved, but the complexity of detecting anomalous behavior increases exceptionally

Engineering Contradiction:
Improvemonitoring coverageVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex detection problem into manageable components by analyzing individual user behavior patterns separately, calculating surfisal for specific behavioral factors, and evaluating each user's anomaly score independently, which allows the system to scale to large numbers of users without proportionally increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the approach from analyzing complex multi-dimensional user behaviors to evaluating specific behavioral factors with calculated surfisal values and risk metrics, transforming the complexity management by parameterizing user behavior into measurable indicators that can be processed efficiently

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If forensic investigation tools are used after security incidents are discovered, then detailed analysis of security incidents is possible, but cybercriminals have already accomplished their objectives and retrieved valuable information

Engineering Contradiction:
Improveincident analysis precisionVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by continuously monitoring and analyzing user behavior in real-time before security incidents occur, using automated anomaly detection to identify suspicious activities early, which enables preventive response rather than post-incident forensic analysis, thereby stopping cybercriminals before they can accomplish their objectives

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback loop where user behavior is continuously monitored, anomalous patterns are detected through automated analysis, and alerts are generated in real-time, creating a continuous improvement system that learns from new data and adjusts detection parameters, enabling timely response before threats materialize into full incidents

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11792218B2Method, apparatus, and computer-readable medium for determining risk associated with anomalous behavior of a user on a computer network
Publication Date: 2023.10.17 INFORMATICA CORP
  • US11792218B2 patent drawing
  • US11792218B2 patent drawing
  • US11792218B2 patent drawing

AI summary

A system, method, and computer-readable medium for determining risk associated with anomalous behavior of a user on a computer network including receiving anomalous behavioral data corresponding to anomalous activity of the user on the computer network, determining surprisal values corresponding to one or more behavioral factors based on one or more of: one or more probabilities corresponding to one or more current values or one or more characteristics of the one or more behavioral factors, determining one or more dynamic weights corresponding to the one or more behavioral factors based at least in part on the one or more current values and historically expected values of the one or more behavioral factors for the user, and determining a risk metric corresponding to the anomalous activity of the user based on the surprisal values, the one or more dynamic weights, and static weights assigned to the one or more behavioral factors.