User Profiling for Insider Threat Detection via Search Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions focus on anomalies from the victim's side and fail to effectively monitor potential insiders based on their internet search patterns, leading to inefficiencies in detecting and preventing insider threats.

Innovation Solution

A method for user profiling that captures and analyzes internet search patterns and forensics of search keywords to assess risk dimensions such as knowledge/skill, intent, accessibility, and reputation, allowing for the identification and prediction of potential insider threats by classifying users and designating suspicious profiles based on statistical analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anomaly detection methods are used to detect insider threats, then detection capability is provided, but false alarm rate increases significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments user behavior analysis into multiple dimensions including search pattern analysis, keyword forensics, user profiling, and behavioral baseline establishment. By dividing the detection process into these specialized components, the system achieves more precise threat detection with reduced false alarms compared to traditional single-method anomaly detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameters of detection by shifting from generic anomaly detection to specific behavioral parameter analysis including search frequency, keyword patterns, browsing behavior metrics, and temporal activity patterns. This parameter transformation enables more accurate distinction between legitimate and malicious activities.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If user profiling based on multiple behavior dimensions is implemented, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal user profiling system that handles multiple behavior dimensions (search patterns, keyword analysis, browsing behavior, temporal patterns) through a unified framework. This multi-functional approach consolidates various detection methods into a single coherent system, managing complexity while maintaining high detection accuracy across different threat types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-service by automatically establishing behavioral baselines, profiling users, and detecting anomalies without requiring manual configuration for each user. The automated baseline establishment and continuous learning mechanisms reduce operational complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #25Self-service

3Reliability

If proactive monitoring of potential attackers is implemented, then prevention capability is enhanced, but resource consumption increases

Engineering Contradiction:
Improveprevention capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by establishing behavioral baselines and creating user profiles before attacks occur. The system proactively monitors search patterns and keywords to identify potential threats in advance, enabling prevention rather than just detection. This advance preparation reduces the need for intensive real-time analysis of all user activities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial monitoring by focusing computational resources on specific high-risk indicators such as particular keyword patterns, search frequency anomalies, and behavioral deviations from established baselines. Rather than analyzing all user activities equally, the system selectively monitors partial aspects that are most indicative of insider threats, reducing overall resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8375452B2Methods for user profiling for detecting insider threats based on internet search patterns and forensics of search keywords
Publication Date: 2013.02.12 CHECK POINT SOFTWARE TECH LTD
  • US8375452B2 patent drawing
  • US8375452B2 patent drawing
  • US8375452B2 patent drawing

AI summary

Disclosed are methods for user profiling for detecting insider threats including the steps of: upon a client application sending a request for a link, extracting at least one search keyword from a search session associated with the request; classifying the link into at least one classification; determining whether at least one classification is a monitored classification; capturing search elements of search sessions associated with the monitored classification; acquiring usage data from the search elements to create a user profile associated with a user's search behavior; and performing a statistical analysis, on a search frequency for the monitored classification, on user profiles associated with many users. Preferably, the method includes: designating a profile as suspicious based on the statistical analysis exceeding a pre-determined threshold value, wherein the pre-determined threshold value is based on an expected search frequency for the profile and each respective grade for at least one risk-assessment dimension.