WO2024263172A1 - Machine learning based unauthorized service account access detection system and method therefor - Google Patents
Machine learning based unauthorized service account access detection system and method therefor Download PDFInfo
- Publication number
- WO2024263172A1 WO2024263172A1 PCT/US2023/026162 US2023026162W WO2024263172A1 WO 2024263172 A1 WO2024263172 A1 WO 2024263172A1 US 2023026162 W US2023026162 W US 2023026162W WO 2024263172 A1 WO2024263172 A1 WO 2024263172A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- service
- account
- matrix
- probability
- login
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
Definitions
- Service accounts are highly privileged accounts created to perform automation of various services and applications.
- the automation of service accounts may be achieved by running a programming script to maintain the security of various downstream applications.
- use of the programming scripts may create a technical dependency on the configuration of the programming scripts and, if, for example, passwords are changed, backward compatibility issues may arise resulting in authentication failures and unnecessary system backup.
- service accounts are highly vulnerable to hackers and other nefarious actors. Therefore, a need exists to continuously monitor users that attempt to login to service accounts to prevent unauthorized access to the service accounts.
- a computer-implemented method includes receiving a service account login history associated with users of a service account, the service account login history being transformed to a service account login history probability matrix; generating a source-machine service-account matrix from the service account login history probability matrix; generating a service-account destination matrix from the service account login history probability matrix; and utilizing the source-machine service-account matrix and the serviceaccount destination matrix to generate a service-account-login-probability, the service-account- login-probability being utilized to indicate whether a service account login is unauthorized.
- FIG. 1 illustrates a block diagram of a system in accordance with some embodiments.
- FIG. 2 illustrates a block diagram of an unauthorized service account detection unit of the system in FIG. 1 in accordance with some embodiments.
- FIG. 3 A illustrates an example three-dimensional coordinate system utilized to describe an example service account login history probability matrix in accordance with some embodiments.
- FIG 3B illustrates example 2D plane representations of an example service account login history probability matrix in accordance with some embodiments.
- FIG. 3C illustrates a source-machine service-account matrix of the service account login history probability matrix of FIG. 3B with example probability values in accordance with some embodiments.
- FIG. 3D illustrates a service-account destination matrix of the service account login history probability matrix of FIG. 3B with example probability values in accordance with some embodiments.
- FIG. 4 is a flow diagram illustrating an unauthorized service account detection method in accordance with some embodiments.
- FIG. 5 illustrates an example utilization of the unauthorized service account detection method of FIG. 4 in accordance with some embodiments.
- FIG. 1 illustrates a block diagram of an exemplary system 100 for implementing embodiments consistent with the present disclosure.
- system 100 includes an input/output (IO) interface 101, processor/s 102, a storage interface 104, a network interface 103, and memory 105.
- system 100 may be, for example, a server, such as an authentication server or source machine utilized to implement the embodiments described herein.
- memory 105 may include an operating system (OS) 107, processes 120, and an unauthorized service account detection unit 140.
- OS operating system
- the unauthorized service account detection unit 140 is configured to implement an unauthorized service account detection method configured to detect an unauthorized service account login as described further herein.
- processors 102 may comprise at least one data processor for executing program components for dynamic resource allocation at run time.
- the processors 102 may include specialized processing units such as integrated system (bus) controllers, memory management control units, floating point units, graphics processing units, digital signal processing units, etc.
- the processors 102 may be disposed in communication with one or more input/output (I/O) devices (not shown) via an I/O interface 101.
- I/O input/output
- the I/O interface 101 may employ communication protocol s/methods such as, without limitation, audio, analog, digital, monoaural, RCA, stereo, IEEE-1394, serial bus, universal serial bus (USB), infrared, PS/2, BNC, coaxial, component, composite, digital visual interface (DVI), high-definition multimedia interface (HDMi), RF antennas, S-Video, VGA, IEEE 802.1 n /b/g/n/x, Bluetooth®, cellular (e.g., code-division multiple access (CDMA), high-speed packet access (HSPA+), global system for mobile communications (GSM), long-term evolution (LTE), WiMax®, or the like), etc.
- CDMA code-division multiple access
- HSPA+ high-speed packet access
- GSM global system for mobile communications
- LTE long-term evolution
- WiMax® or the like
- the system 100 may communicate with one or more VO devices.
- an input device may be an antenna, keyboard, mousejoystick, (infrared) remote control, camera, card reader, fax machine, dongle, biometric reader, microphone, touch screen, touchpad, trackball, stylus, scanner, storage device, transceiver, video device/source, etc.
- An output device may be a printer, fax machine, video display (e g., cathode ray tube (CRT), liquid crystal display (LCD), lightemitting diode (LED), plasma, Plasma display panel (PDP), Organic light-emitting diode display (OLED) or the like), audio speaker, etc.
- CTR cathode ray tube
- LCD liquid crystal display
- LED lightemitting diode
- PDP Plasma display panel
- OLED Organic light-emitting diode display
- the processors 102 may be disposed in communication with a communication network or other type of network via a network interface 103.
- the network interface 103 may communicate with the communication network.
- the network may include the system, a source machine, and a destination machine.
- the source machine may be a computer system configured to allow a user of the source machine to login or attempt to login to a service account.
- the destination machine may be a computer system that the user of the source machine is attempting to login into via system 100.
- each source machine and destination machine may be identified by a source machine identification (ID) or destination machine ID, respectively.
- the service account may be identified by a service account ID.
- the network interface 103 may employ connection protocols including, without limitation, direct connect, Ethernet (e.g., twisted pair 10/100/1000 Base T), transmission control protocol/Intemet protocol (TCP/IP), token ring, IEEE 802.11a/b/g/n/x, etc.
- the communication network may include, without limitation, a direct interconnection, e-commerce network, a peer to peer (P2P) network, local area network (LAN), wide area network (WAN), wireless network (e g., using Wireless Application Protocol), the internet, Wi-Fi®, etc.
- P2P peer to peer
- LAN local area network
- WAN wide area network
- wireless network e g., using Wireless Application Protocol
- the system 100 may communicate with the one or more service operators, service machines, and/or destination machines.
- the processors 102 may be disposed in communication with a memory 105 (e.g., RAM, ROM, etc.) via a storage interface 104.
- the storage interface 104 may connect to memory 105 including, without limitation, memory drives, removable disc drives, etc., employing connection protocols such as serial advanced technology attachment (SATA), Integrated Drive Electronics (IDE), IEEE- 1394, Universal Serial Bus (USB), fiber channel, Small Computer Systems interface (SCSI), etc.
- the memory drives may further include a drum, magnetic disc drive, magneto-optical drive, optical drive, Redundant Array of Independent Discs (RAID), solid-state memory devices, solid- state drives, etc.
- the memory 105 may store a collection of program or database components, including, without limitation, a user interface, an operating system 107, a web server, etc.
- the system 100 may store user/application data, such as the data, variables, records, etc. as described in this disclosure.
- databases may be implemented as fault-tolerant, relational, scalable, secure databases such as Oracle or Sybase.
- the operating system 107 may facilitate resource management and operation of the system 100.
- operating systems include, without limitation, APPLE® MACINTOSH® OS X®, UNIX®, UNIX-like system distributions (E.G., BERKELEY SOFTWARE DISTRIBUTION® (BSD), FREEBSD®, NETBSD®, OPENBSD, etc ), LINUX® DISTRIBUTIONS (E G., RED HAT®, UBUNTU®, KUBUNTU®, etc ), IBM®OS/2®, MICROSOFT® WINDOWS® (XP®, VISTA®/7/8, 10 etc ), APPLE® OS®, GOOGLETM ANDROIDTM, BLACKBERRY® OS, or the like.
- the system 100 may implement a web browser (not shown in the figures) stored program component.
- the web browser (not shown in the figures) may be a hypertext viewing application, such as MICROSOFT® INTERNET EXPLORER®, GOOGLETM CHROMETM, MOZILLA® FIREFOX®, APPLE® SAFARI®, etc.
- Secure web browsing may be provided using Secure Hypertext Transport Protocol (HTTPS), Secure Sockets Layer (SSL), Transport Layer Security (TLS), etc.
- Web browsers may utilize facilities such as AJAX, DHTML, ADOBE® FLASH®, JAVASCRIPT®, JAVA®, Application Programming Interfaces (APIs), etc.
- a computer-readable storage medium refers to any type of physical memory on which information or data readable by a processor may be stored.
- a computer-readable storage medium may store instructions for execution by one or more processors, including instructions for causing the processor(s) to perform steps or stages consistent with the embodiments described herein.
- the term “computer-readable medium” should be understood to include tangible items and exclude carrier waves and transient signals, e.g., non-transitory. Examples include Random Access Memory (RAM), Read-Only Memory (ROM), volatile memory, non-volatile memory, hard drives, Compact Disc (CD) ROMs, Digital Video Disc (DVDs), flash drives, disks, and any other known physical storage media.
- FIG. 2 illustrates a block diagram of an unauthorized service account detection unit 140 of FIG. 1 in accordance with some embodiments.
- the unauthorized service account detection unit 140 is executable code configured to detect an unauthorized service account login to a service account on system 100.
- a service account is a type of user account that is used by services or applications on system 100 to interact with other systems or resources within a network.
- a service account login refers to the process or action of accessing or logging into a service account from, for example, a source machine or other computer system within a computer network or service account system.
- an authorized service account login allows a user of system 100 to gain access to the functionalities, resources, or permissions of the service account.
- detection of an unauthorized service account login is performed by the unauthorized service account detection unit 140 of system 100 in order to restrict access to service accounts by an unauthorized user of the unauthorized service account login.
- access to a service account using a service account login may be restricted by the service account system or by an administrator of the service account system that is notified of the unauthorized service account login.
- the unauthorized service account detection unit 140 includes a service account login collection unit 205 and a feature extraction and matrix generation unit 210.
- the feature extraction and matrix generation unit 210 includes a probability generation and replacement unit 220 and an authorization threshold comparison unit 230.
- the service account login collection unit 205 is executable code configured to collect service account login history associated with users of source machines and destination machines that access, login, or attempt to login into service accounts via system 100 (e.g., a service account system).
- the service account login history is collected by service account login collection unit 205 and transformed to a service account login history probability matrix by probability generation and replacement unit 220.
- the service account login history probability matrix is a three-dimensional matrix (3D) of probability values that indicate the probabilities of a user or users of a service account making a connection from a source machine to a destination machine based on, for example, the service account login history of the user or users.
- the probability values may range from, for example, 0 to 1 .
- the probability values in the service account login history probability matrix are identified using a service account identification (ID), a source machine ID, and a destination machine ID.
- ID service account identification
- the service account account ID a source machine ID
- a destination machine ID a destination machine ID
- the service account login history or service account login history matrix used to generate the service account login history probability matrix may be collected over a predetermined time period, such as, for example, sixty days, ninety days, or some other predetermined time period.
- the feature extraction and matrix generation unit 210 is executable code configured to utilize a service account login history probability matrix to determine whether a service account login by a user of system 100 is unauthorized.
- the feature extraction and matrix generation unit 210 includes probability generation and replacement unit 220 and authorization threshold comparison unit 230.
- the probability generation and replacement unit 220 is executable code configured to generate a service-account-login-probability that is utilized by the feature extraction and matrix generation unit 210 to determine whether a service account login by a user of system 100 is unauthorized.
- the probability generation and replacement unit 220 is configured to utilize a source-machine service-account matrix and a service-account destination matrix to generate the service-account-login-probability. In some embodiments, as described further herein, probability generation and replacement unit 220 utilizes machine learning based matrix factorization to generate the source-machine service-account matrix and the serviceaccount destination matrix that are used to generate the service-account-login-probability. In some embodiments, the service-account-login-probability is utilized by the feature extraction and matrix generation unit 210 to determine whether a service account login by a user of system 100 is unauthorized, described further herein with reference to FIG. 2. In some embodiments, the authorization threshold comparison unit 230 is executable code configured to utilize the serviceaccount-login-probability to determine whether a service account login is unauthorized.
- probability generation and replacement unit 220 of feature extraction and matrix generation unit 210 receives a service account login history matrix from service account login collection unit 205. In some embodiments, after receiving the service account login history matrix, probability generation and replacement unit 220 transforms the service account login history matrix into a service account login history probability matrix.
- the service account login history probability matrix is a 3D matrix of probability values that indicate the probabilities of a user of a service account making a connection from a source machine to a destination machine via system 100.
- the service account login history probability matrix may include missing entries or empty cells that do not have probability values in the service account login history probability matrix.
- the missing entries in the service account login history probability matrix may be caused by, for example, data collection or preprocessing issues during the collection of service account data by service account login collection unit 205.
- feature extraction and matrix generation unit 210 may utilize a machine learning algorithm that utilizes a matrix factorization model to fill the missing entries of the service account login history probability matrix.
- matrix factorization is a factorization technique utilized in, for example, machine learning applications, to fill missing entries in a matrix.
- matrix factorization is performed by the probability generation and replacement unit 220 by decomposing an original matrix (e g., a 2D matrix) into lowerdimensional representations and using the lower-dimensional representations to estimate the missing values in the original matrix, as described further herein.
- an original matrix e g., a 2D matrix
- the probability generation and replacement unit 220 of feature extraction and matrix generation unit 210 prior to performing matrix factorization operations, upon receipt of the service account login history probability matrix, performs unfolding or separation operations to separate the service account login history probability matrix into two 2D matrices.
- feature extraction and matrix generation unit 210 separates the service account login history probability matrix into a source-machine serviceaccount matrix and a service-account destination matrix.
- the sourcemachine service-account matrix is a 2D matrix of the probability values from the service account login history probability matrix associated with a user accessing a service account from a source machine.
- the service-account destination matrix is a 2D matrix of the probability values from the service account login history probability matrix associated with a user accessing a destination machine utilizing service account. Examples of a source-machine service-account matrix and a service-account destination matrix are described herein with reference to FIG. 3C and FIG. 3D, respectively.
- FIG. 3A illustrates an example three-dimensional coordinate system with x-y-z axis utilized to describe an example service account login history probability matrix.
- the x-axis is configured to represent a destination machine axis
- the y- axis is configured to represent a source machine axis
- the z-axis is configured to represent a service account axis.
- FIG. 3B illustrates example 2D plane representations of an example service account login history probability matrix with example probability values in accordance with some embodiments.
- the x-axis represents a destination machine axis and the y-axis represents a source machine axis.
- FIG. 3A illustrates an example three-dimensional coordinate system with x-y-z axis utilized to describe an example service account login history probability matrix.
- the x-axis is configured to represent a destination machine axis
- the y- axis is configured to represent a source machine axis
- the z-axis is configured to represent a service account
- FIG. 3B there are three service accounts illustrated, service account 1 (e.g., svc acc), service account 2 (e.g., svc acc2) and service account 3 (svc acc 3).
- FIG. 3C illustrates a source-machine service-account matrix of the service account login history probability matrix of FIG. 3B with example probability values in accordance with some embodiments. In some embodiments, the source-machine service-account matrix corresponds to service account 3 of FIG. 3B.
- FIG. 3D illustrates a service-account destination matrix of the service account login history probability matrix of FIG. 3B with example probability values in accordance with some embodiments. In some embodiments, the service-account destination matrix corresponds to service account 3 of FIG. 3B.
- the sourcemachine service-account matrix (as well as the service-account destination matrix), may be represented as an M x N matrix, where M represents the rows in the matrix and N represents the columns in the matrix.
- M represents the source machine (e.g., the source machine that the user logged in from) and N represents the service account ID (e.g., the service account that represents the user).
- N represents the destination machine (e.g., the destination machine that the user logged into utilizing the service account).
- probability generation and replacement unit 220 after probability generation and replacement unit 220 separates the service account login history probability matrix into the source-machine service-account matrix and the service-account destination matrix, probability generation and replacement unit 220 commences the process of utilizing machine learning based matrix factorization operations on both the source-machine service-account matrix and the service-account destination matrix to estimate the missing probability values in each matrix.
- probability generation and replacement unit 220 utilizes a machine learning algorithm that performs matrix factorization by decomposing the two 2D matrices (e.g., source-machine service-account matrix or service-account destination matrix) into lower-dimensional representations and using the representations to estimate the missing probability values in the source-machine service-account matrix and the service-account destination matrix.
- the 2D matrix represented as an M x N matrix
- the 2D matrix is represented as two matrices, an M x F matrix and F x N matrix, where F are features in each matrix.
- the feature extraction and feature extraction and matrix generation unit 210 performs two matrix factorization operations, a source-service account matrix factorization and a service-account destination matrix factorization.
- probability generation and replacement unit 220 trains a matrix factorization model to fdl the missing entries in the M x F and F x N matrices to attain the desired output, M x N (e.g., source-machine service-account matrix or service-account destination matrix).
- M x N e.g., source-machine service-account matrix or service-account destination matrix.
- the feature extraction and matrix generation unit 210 initializes the M x F and F x N matrices, which includes the feature factors in each matrix.
- the probability values in the missing entries are initialized with random probability values or with predefined probability values.
- the initialization method may vary depending on the specific implementation or algorithm being used during the matrix factorization operations.
- the elements of U and V are randomly initialized and the probability values may be drawn from a uniform distribution or a Gaussian distribution.
- the elements of U and V can be initialized with predefined values based on prior knowledge or domain expertise.
- the training process may update the elements in U and V based on the observed or actual values in the input matrix (e.g., source-machine service-account matrix or service-account destination matrix), iteratively optimizing the matrix factorization model to capture the underlying patterns and relationships in the source-machine service-account matrix and service-account destination matrix.
- the input matrix e.g., source-machine service-account matrix or service-account destination matrix
- probability generation and replacement unit 220 utilizes a loss function to measure the performance of the matrix factorization model.
- the loss function is configured to quantify the discrepancy between the estimated probability values and the actual probability values in the M x N matrix (e.g., from the factorized matrices M x F and F x N).
- the loss function may be, for example, a mean squared error (MSE), mean absolute error (MAE), or other loss function.
- the actual execution of the loss function occurs during the training process when the matrix factorization model iteratively updates the factorized matrices M x F and F x N to minimize the loss function.
- feature extraction and matrix generation unit 210 trains the matrix factorization model utilizing a machine learning optimization algorithm.
- the optimization algorithm may be, for example, a stochastic gradient descent (SGD), alternating least squares (ALS), or any other suitable optimization algorithm configured to be utilized to iteratively update the elements in M x F and F x N.
- probability generation and replacement unit 220 utilizes the factorized matrices M x F (e.g., matrix U) and F x N (e.g., matrix V) to estimate the missing values (e.g., missing entries) in the M x N matrix (e.g., matrix R).
- M x F e.g., matrix U
- F x N e.g., matrix V
- R, U, and V to represent M x F, F x N, and M x N, respectively, are utilized for explanation purposes.
- probability generation and replacement unit 220 computes the dot product of the corresponding row in U (e.g., M x F) and column in V (e.g., F x N), which provides an estimation of the missing entry (e.g., missing probability value) in R.
- the weights, denoted as W are used to scale the contribution of each feature factor to the prediction.
- the prediction for an entry r_ij in the matrix R may be computed by the probability generation and replacement unit 220 as follows:
- W_k represents the weight associated with the k-th feature factor
- U_ik denotes the i-th user's strength of association with the k-th feature factor
- V_kj represents the j -th item's strength of association with the k-th feature factor.
- the weights W_k are learned by optimizing the loss function using the aforementioned optimization algorithms or techniques, such as stochastic gradient descent. In some embodiments, by updating the weights iteratively, the model learns to assign appropriate importance to different feature factors, capturing the underlying patterns and relationships in the data.
- the optimization process involves iterating through the actual probability values and adjusting the corresponding elements in M x F and F x N to improve the fit between the estimated and actual probability values.
- matrix factorization decomposes the input matrix R into matrices U and V and the weights W are used to scale the contribution of feature factors in U and V in predicting the missing entries (e.g., missing probability values) in R.
- feature extraction and matrix generation unit 210 evaluates the performance of the matrix factorization model by comparing the estimated values with the actual values in the matrix. In some embodiments, feature extraction and matrix generation unit 210 utilizes standard evaluation metrics to assess the accuracy and quality of the filled-in missing probability values. In some embodiments, feature extraction and matrix generation unit 210 refines the matrix factorization model by adjusting hyperparameters, such as the number of feature factors, and, if necessary, and repeats the training process to further improve the results.
- the matrix factorization model may estimate the missing probability values by computing the values through the dot product of the corresponding rows in U and V.
- feature extraction and matrix generation unit 210 utilizes the source-machine service-account matrix or service-account destination matrix to determine whether a service account login (e.g., a new service account login) by a user of the system 100 is unauthorized.
- a service account login e.g., a new service account login
- feature extraction and matrix generation unit 210 determines whether a service account login by a user of the system 100 is unauthorized by generating a service-account-login-probability based on the source-machine service-account matrix and the service-account destination matrix and comparing the service-account-login-probability to an authorization threshold value.
- probability generation and replacement unit 220 calculates the service-account-login-probability by utilizing the product of the sourcemachine service-account matrix and the service-account destination matrix (e.g., multiplying the source-machine service-account matrix by the service-account destination matrix to compute service-account-login-probability).
- each probability in the resulting matrix corresponds to the service-account-login-probability of the corresponding service account login (e.g., new service account login).
- authorization threshold comparison unit 230 compares the service-account-login-probability value to the authorization threshold value.
- the authorization threshold value may be, for example, a value indicative of the service account login being authorized, such as, 0.7, 0.8, or some other a value that is indicative of the service account login being authorized.
- the authorization threshold comparison unit 230 compares the service-account-login-probability value to the authorization threshold value by determining whether the service-account-login-probability value is less than, equal to, or greater than the authorization threshold value.
- the service account login (e.g., new service account login) is considered authorized by the feature extraction and matrix generation unit 210.
- the service account login is considered not authorized by the feature extraction and matrix generation unit 210.
- the service account login may be restricted by the service account system or by an administrator of the service account system that is notified of the unauthorized service account login.
- FIG. 4 is a flow diagram illustrating an unauthorized service account detection method 400 in accordance with some embodiments.
- the unauthorized service account detection method 400 is a method utilized by unauthorized service account detection unit 140 of FIG. 2 to detect an unauthorized service account login by a user of system 100.
- the method, process steps, or stages illustrated in the figures may be implemented as an independent routine or process, or as part of a larger routine or process. Note that each process step or stage depicted may be implemented as an apparatus that includes a processor executing a set of instructions, a method, or a system, among other embodiments.
- the unauthorized service account detection unit 140 is configured to perform the unauthorized service account detection method 400 in accordance with some embodiments.
- probability generation and replacement unit 220 of feature extraction and matrix generation unit 210 receives a service account login history matrix from service account login collection unit 205. In some embodiments, after receiving the service account login history matrix, probability generation and replacement unit 220 transforms the service account login history matrix into a service account login history probability matrix. In some embodiments, after transforming the service account login history information into the service account login history probability matrix, operation 420 proceeds to operation 430.
- probability generation and replacement unit 220 generates a source-machine service-account matrix from the service account login history probability matrix. In some embodiments, at operation 440, probability generation and replacement unit 220 generates a service-account destination matrix from the service account login history probability matrix. In some embodiments, as stated previously, the probability generation and replacement unit 220 generates the source-machine service-account matrix and the service-account destination matrix by utilizing unfolding operations configured to separate the service account login history probability into the source-machine service-account matrix and the service-account destination matrix (illustrated by way of example in FIG. 3C and FIG. 3D, respectively). In some embodiments, after generating the source-machine service-account matrix and the service-account destination matrix, operation 440 proceeds to operation 450.
- probability generation and replacement unit 220 generates estimated probability values to replace the values in the missing entries of the sourcemachine service-account matrix and the service-account destination matrix.
- probability generation and replacement unit 220 utilizes machine learning based matrix factorization (e.g., source-machine service-account matrix factorization and the service-account destination matrix factorization) to generate and replace the values in the missing entries of the source-machine service-account matrix and the serviceaccount destination matrix.
- operation 450 proceeds to operation 460.
- probability generation and replacement unit 220 utilizes the source-machine service-account matrix and the service-account destination matrix to generate a service-account-login-probability.
- the service-account-login-probability is generated by performing product operations between the source-machine service-account matrix and the service-account destination matrix after performing the machine learning based matrix factorization operations (e.g., source-machine service-account matrix factorization and the service-account destination matrix factorization).
- the probability generation and replacement unit 220 performs the matrix operations on both the source-machine service-account matrix and the service-account destination matrix in order to update the missing entries of the source-machine service-account matrix and the service-account destination matrix with estimated probability values.
- operation 460 proceeds to operation 470.
- authorization threshold comparison unit 230 of feature extraction and matrix generation unit 210 utilizes the service-account-login-probability to indicate whether a service account login is unauthorized.
- the authorization threshold comparison unit 230 compares the service-account-login-probability with an authorization threshold value. Tn some embodiments, when the authorization threshold comparison unit 230 determines that the service-account-login-probability value is equal to or greater than the authorization threshold value, the service account login associated serviceaccount-login-probability value is considered authorized by the feature extraction and matrix generation unit 210.
- FIG. 5 illustrates an example implementation of the unauthorized service account detection method of FIG. 4 in accordance with some embodiments.
- the service-account- login-probability calculated by the probability generation and replacement unit 220 is 0.64.
- authorization threshold comparison unit 230 determines that the service-account-login-probability is greater than the authorization threshold value, and thus the service account login attempt is deemed authorized by the feature extraction and matrix generation unit 210.
- an unsupervised learning approach may be utilized by the feature extraction and matrix generation unit 210 to group users of service machines into distinct groups based on user data related to service account access.
- the feature extraction and matrix generation unit 210 may be configured to utilize a grouping algorithm that utilizes the user data (representative of, for example, the users of service machines) to group the users into distinct groups (e.g., grouped users or clusters).
- the distinct groups may be utilized by the probability generation and replacement unit 220 to replace the missing probability values with the estimated probability values.
- users of service machines may be grouped into a data scientist group or other distinct group.
- the service accounts associated with the data scientist group may only be accessible to service account users belonging to the data scientist group.
- a service account user may not be authorized to access service accounts affiliated with the data scientist group unless the service account user is a member of the data scientist group and thus, the service account may not be recommended or accessible to, for example, a user interface (UI) developer or a user experience (UX) developer.
- UI user interface
- UX user experience
- the unsupervised grouping algorithm that may be utilized by the feature extraction and matrix generation unit 210 to generate the group of users is based on a feature matrix (e.g., a service account feature matrix, etc.), and may be, for example, a k-means clustering algorithm.
- a k-means clustering algorithm or k-means grouping algorithm is a clustering algorithm used to partition data into k distinct clusters based on similarity or distance metrics.
- K-means is an iterative algorithm that aims to minimize the within-cluster sum of squares by iteratively updating cluster assignments.
- the service accounts are clustered into K groups based on a variance (e.g., a minimum or closest variance) between each member of each group.
- a variance e.g., a minimum or closest variance
- the service account login may be matched initially with the clustered groups and, then the weights are assigned by the probability generation and replacement unit 220 in a group that matches the service account (e.g., the same group of the service account).
- a computer-implemented method includes receiving a service account login history associated with users of a service account, the service account login history being transformed to a service account login history probability matrix; generating a sourcemachine service-account matrix from the service account login history probability matrix; generating a service-account destination matrix from the service account login history probability matrix; and utilizing the source-machine service-account matrix and the serviceaccount destination matrix to generate a service-account-login-probability, the service-account- login-probability being utilized to indicate whether a service account login is unauthorized.
- the service account login history probability matrix is a three-dimensional (3D) probability matrix.
- the computer-implemented method further includes separating the service account login history probability matrix into the source-machine service-account matrix and the service-account destination matrix.
- the computer-implemented method further includes performing a source-machine service account matrix factorization of the source-machine service-account matrix and a service-account destination matrix factorization of the service-account destination matrix.
- the computer-implemented method further includes utilizing the source-machine service account matrix factorization to estimate source-machine service account matrix probability values in the source-machine service-account matrix
- the computer-implemented method further includes utilizing the service-account destination matrix factorization to estimate service-account destination matrix probability values in the service-account destination matrix. [0057] Tn some embodiments, the computer-implemented method further includes multiplying the source-machine service-account matrix that has been updated with estimated source-machine service account matrix probability values and the service-account destination matrix that has been updated with estimated service-account destination matrix probability values to ascertain the service-account-login-probability.
- the service-account-login- probability is utilized to determine whether the service account login is authorized by comparing the service-account-login-probability to an authorization threshold value.
- the service-account-login- probability is generated based upon a k-means grouping algorithm.
- a system includes a processor; and a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium including code that: receives a service account login history matrix associated with users of a service account, the service account login history matrix being transformed to a service account login history probability matrix; generates a source-machine service-account matrix from the service account login history probability matrix; generates a service-account destination matrix from the service account login history probability matrix; and utilizes the source-machine service-account matrix and the service-account destination matrix to generate a service-account- login-probability, the service-account-login-probability being utilized to indicate whether a service account login is unauthorized.
- the code separates the service account login history probability matrix into the source-machine service-account matrix and the service-account destination matrix. [0062] Tn some embodiments of the system, the code performs a source-machine service account matrix factorization of the source-machine service-account matrix and a service-account destination matrix factorization of the service-account destination matrix.
- the code utilizes the source-machine service account matrix factorization to estimate source-machine service account matrix probability values in the source-machine service-account matrix.
- the code utilizes the service-account destination matrix factorization to estimate service-account destination matrix probability values in the service-account destination matrix.
- the code multiplies the source-machine serviceaccount matrix that has been updated with estimated source-machine service account matrix probability values and the service-account destination matrix that has been updated with estimated service-account destination matrix probability values to ascertain the service-account- login-probability.
- the code determines whether the service account login is authorized by comparing the service-account-login-probability to an authorization threshold value.
- the service-account-login-probability is generated based upon a k-means grouping algorithm.
- a computer-implemented method includes ascertaining a sourcemachine service-account matrix probability; ascertaining a service-account destination matrix probability; multiplying the source-machine service-account matrix probability by the serviceaccount destination matrix probability to ascertain a service-account-login-probability; and utilizing the service-account-login-probability to determine whether to report an unauthorized service account login.
- the source-machine serviceaccount matrix probability is ascertained utilizing a source-machine service account matrix factorization of a source-machine service-account matrix.
- the service-account destination matrix probability is ascertained utilizing a service-account destination matrix factorization of a service-account destination matrix.
- the embodiments described herein improve upon other computer systems by receiving a service account login history associated with users of a service account, the service account login history being transformed to a service account login history probability matrix; generating a source-machine service-account matrix from the service account login history probability matrix; generating a service-account destination matrix from the service account login history probability matrix; and utilizing the source-machine service-account matrix and the service-account destination matrix to generate a service-account-login-probability, the service-account-login-probability being utilized to indicate whether a service account login is unauthorized.
- the practical application of embodiments described herein aim to address challenges presented using other computer systems (e.g., lack of speed, costeffectiveness, etc.) by introducing embodiments described herein to indicate whether a service account is unauthorized.
- the practical application of the embodiments optimizes existing processes, resulting in superior outcomes with increased speed, precision, and/or costeffectiveness.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Debugging And Monitoring (AREA)
Abstract
Description
Claims
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/US2023/026162 WO2024263172A1 (en) | 2023-06-23 | 2023-06-23 | Machine learning based unauthorized service account access detection system and method therefor |
| EP23741213.5A EP4732172A1 (en) | 2023-06-23 | 2023-06-23 | Machine learning based unauthorized service account access detection system and method therefor |
| CN202380097847.3A CN121058019A (en) | 2023-06-23 | 2023-06-23 | Unauthorized Service Account Access Detection System and Method Based on Machine Learning |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/US2023/026162 WO2024263172A1 (en) | 2023-06-23 | 2023-06-23 | Machine learning based unauthorized service account access detection system and method therefor |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024263172A1 true WO2024263172A1 (en) | 2024-12-26 |
Family
ID=87245653
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2023/026162 Ceased WO2024263172A1 (en) | 2023-06-23 | 2023-06-23 | Machine learning based unauthorized service account access detection system and method therefor |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4732172A1 (en) |
| CN (1) | CN121058019A (en) |
| WO (1) | WO2024263172A1 (en) |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20180124082A1 (en) * | 2016-10-20 | 2018-05-03 | New York University | Classifying logins, for example as benign or malicious logins, in private networks such as enterprise networks for example |
-
2023
- 2023-06-23 WO PCT/US2023/026162 patent/WO2024263172A1/en not_active Ceased
- 2023-06-23 CN CN202380097847.3A patent/CN121058019A/en active Pending
- 2023-06-23 EP EP23741213.5A patent/EP4732172A1/en active Pending
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20180124082A1 (en) * | 2016-10-20 | 2018-05-03 | New York University | Classifying logins, for example as benign or malicious logins, in private networks such as enterprise networks for example |
Also Published As
| Publication number | Publication date |
|---|---|
| CN121058019A (en) | 2025-12-02 |
| EP4732172A1 (en) | 2026-04-29 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20220006828A1 (en) | System and user context in enterprise threat detection | |
| US10067760B2 (en) | System and method for classifying and resolving software production incidents | |
| US20260119647A1 (en) | Connecting natural and security language in the embedding space for better threat hunting and incident response | |
| US12323462B2 (en) | Identifying legitimate websites to remove false positives from domain discovery analysis | |
| US10885167B1 (en) | Intrusion detection based on anomalies in access patterns | |
| US11403305B2 (en) | Performing data mining operations within a columnar database management system | |
| US11816188B2 (en) | Weakly supervised one-shot image segmentation | |
| WO2021035193A1 (en) | Active learning via a sample consistency assessment | |
| US20170178026A1 (en) | Log normalization in enterprise threat detection | |
| US20160127388A1 (en) | Similarity search and malware prioritization | |
| US20170178025A1 (en) | Knowledge base in enterprise threat detection | |
| CN116034402A (en) | Deterministic Learning for Video Scene Detection | |
| CN110392046B (en) | Method and device for detecting abnormity of network access | |
| WO2021183151A1 (en) | Cross-example softmax and/or cross-example negative mining | |
| US11200145B2 (en) | Automatic bug verification | |
| Ouared et al. | DeepCM: Deep neural networks to improve accuracy prediction of database cost models | |
| US20220004528A1 (en) | Dynamic Transformation Code Prediction and Generation for Unavailable Data Element | |
| JP2024540956A (en) | Techniques for assessing bias in trained models | |
| US10320636B2 (en) | State information completion using context graphs | |
| US20230067285A1 (en) | Linkage data generator | |
| EP4732172A1 (en) | Machine learning based unauthorized service account access detection system and method therefor | |
| US12106407B2 (en) | Systems and methods for generating a single-index model tree | |
| US11263388B2 (en) | Method and system for dynamically generating summarised content for visual and contextual text data | |
| US20220309384A1 (en) | Selecting representative features for machine learning models | |
| WO2024044081A1 (en) | System and method for performing device isolation in an authentication network |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23741213 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2023741213 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2023741213 Country of ref document: EP Effective date: 20260123 |
|
| ENP | Entry into the national phase |
Ref document number: 2023741213 Country of ref document: EP Effective date: 20260123 |
|
| ENP | Entry into the national phase |
Ref document number: 2023741213 Country of ref document: EP Effective date: 20260123 |