User Clustering for Access Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise network security systems face challenges in providing effective protection due to the growing size and diversity of host devices, and conventional credential-based authentication techniques often fail to detect and remediate access anomalies effectively, especially against sophisticated attacks like APTs, leading to inaccurate user clustering and risk assessment.

Innovation Solution

The method involves performing an affinity propagation clustering operation to identify similar users based on their behavior and access patterns, determining risk by comparing users within a cluster, and controlling access to computerized resources accordingly, using processing circuitry and memory to execute program code that receives and analyzes user information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional credential-based authentication techniques are used, then implementation is simple and resources are conserved, but detection precision of access anomalies is insufficient against sophisticated attacks

Engineering Contradiction:
Improvedetection precision of access anomaliesVSAvoidcomplexity of authentication system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces affinity propagation clustering as an intermediary mechanism between credential verification and access decision-making. This clustering system groups users based on behavioral similarities and compares individual user behavior against cluster norms, providing an additional layer of anomaly detection without completely replacing the traditional authentication system. The clustering analysis acts as a mediator that enhances detection precision while maintaining a manageable system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces purely credential-based mechanical authentication with a more sophisticated behavioral analysis system. Instead of relying solely on static credentials, the system substitutes mechanical verification with dynamic behavioral pattern recognition through affinity propagation clustering, which analyzes user actions, timing, and patterns to detect anomalies that credential-based systems miss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If users are clustered based on organizational structure (e.g., same department), then clustering is easy to implement, but clustering accuracy deteriorates due to different projects and resource access

Engineering Contradiction:
Improveclustering accuracyVSAvoidcomplexity of clustering algorithm
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces organizational-structure-based clustering with affinity propagation clustering, a computational algorithm that automatically discovers user groups based on behavioral similarities. This substitution transforms the clustering approach from a static, rule-based system to a dynamic, data-driven system that accurately groups users by actual behavior patterns rather than organizational assignments, significantly improving clustering accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameters used for clustering from organizational attributes (department, title) to behavioral parameters (access patterns, timing, resource usage). By transforming the input parameters from static organizational data to dynamic behavioral data, the system achieves more accurate clustering that reflects actual user similarities and differences in resource access behavior.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If network security system processes all security alerts centrally, then comprehensive analysis is achieved, but processing speed and responsiveness deteriorate due to limited resources

Engineering Contradiction:
Improvecomprehensive security analysisVSAvoidprocessing speed of security alerts
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent segments the security analysis function by introducing affinity propagation clustering that pre-groups users into behavioral clusters. This segmentation allows the system to process security alerts more efficiently by comparing user behavior against pre-established cluster norms rather than analyzing each alert in complete isolation or requiring full centralized re-analysis. The clustering structure enables faster, more targeted security assessments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary clustering of users based on their normal behavioral patterns before security incidents occur. This preliminary action creates pre-computed behavioral baselines and cluster norms that accelerate real-time security alert processing. When security events occur, the system can quickly compare against pre-established cluster behavior patterns rather than performing comprehensive analysis from scratch, improving processing speed while maintaining comprehensive analysis capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10721236B1Method, apparatus and computer program product for providing security via user clustering
Publication Date: 2020.07.21 EMC IP HLDG CO LLC
  • US10721236B1 patent drawing
  • US10721236B1 patent drawing
  • US10721236B1 patent drawing

AI summary

There are disclosed herein a technique for use in security. In at least one embodiment, the technique comprises receiving information relating to users and performing an affinity propagation clustering operation in connection with the information to identify a cluster of similar users. Further, the technique determines a risk in connection with a user in the cluster by comparing the user to one or more other users in the cluster. Still further, based on the risk in connection with the user, the technique controls access by the user to a computerized resource.