User Working Time Modeling via Authentication Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user modeling approaches in enterprises fail to accurately detect after-hour activity, which can indicate compromised accounts or malware infections, due to their reliance on location-based assumptions and the expense of deploying agents on end-point devices.

Innovation Solution

A method that collects and analyzes authentication events to create a temporal model of user activity, generating alerts for inconsistent activity and assigning risk scores to detect potentially harmful after-hour activity within an enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If location-based assumptions are used to model user working hours, then the modeling approach is simple to implement, but the accuracy of detecting after-hour activity is poor

Engineering Contradiction:
Improveease of implementationVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent introduces authentication events as an intermediary data source between user activity and the modeling system. Instead of directly using location-based assumptions, the system collects authentication events (login/logout timestamps) from the enterprise network as intermediate evidence to infer actual working hours, thereby improving detection accuracy while maintaining implementation simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a temporal model that copies and represents user activity patterns based on authentication events rather than physical location data. This virtual copy of user behavior patterns allows accurate detection of after-hour activity without requiring physical monitoring devices

Inventive Principle:
Principle #26Copying

2Measurement precision

If agents are installed on all end-point devices to collect login and log-off timestamps, then the accuracy of user activity modeling is improved, but the deployment cost and complexity increase

Engineering Contradiction:
Improvemodeling accuracyVSAvoiddeployment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the necessary authentication data from the enterprise network's existing authentication server infrastructure rather than installing collection agents on individual end-point devices. This extraction approach obtains login and log-off timestamps from a centralized location, maintaining modeling accuracy while eliminating the need for widespread device deployment

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system leverages the existing authentication server's multi-functionality, using it not only for authentication purposes but also as a data source for temporal modeling. This universal use of existing infrastructure provides accurate user activity data without adding separate collection systems to each device

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If existing user modeling approaches are used that assume standard working hours based on location, then the implementation is straightforward, but the detection of compromised accounts and malware is unreliable

Engineering Contradiction:
Improveoperational simplicityVSAvoidsecurity detection reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary action by collecting and analyzing authentication events over a training period to establish each user's actual temporal activity pattern before using the model for security detection. This preliminary modeling based on real authentication data rather than assumptions enables reliable detection of deviations indicating compromised accounts or malware

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously comparing actual authentication events against the learned temporal model and generating alerts when inconsistencies are detected. This feedback mechanism reliably identifies after-hour activity that may indicate security breaches while maintaining operational simplicity through automated anomaly detection

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9338187B1Modeling user working time using authentication events within an enterprise network
Publication Date: 2016.05.10 EMC IP HLDG CO LLC
  • US9338187B1 patent drawing
  • US9338187B1 patent drawing
  • US9338187B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for modeling user working time using authentication events within an enterprise network are provided herein. A method includes collecting multiple instances of activity within an enterprise network over a specified period of time, wherein said multiple instances of activity are attributed to a given device; creating a model based on said collected instances of activity, wherein said model comprises a temporal pattern of activity within the enterprise network associated with the given device; and generating an alert upon detecting an instance of activity within the enterprise network associated with the given device that is (i) inconsistent with the temporal pattern of the model and (ii) in violation of one or more security parameters.