MUMBAI, India, Sept. 28 -- Intellectual Property India has published a patent application (202611100028 A) filed by Mr. Muruganantham Angamuthu on August 19, 2026, for Ai-Based Behavioral Threat Detection And Prevention System For Enterprise Resource Planning Environments.
Inventor includes Mr. Muruganantham Angamuthu.
The application for the patent was published on September 25, 2026, under issue no. 39/2026.
Abstract: The present invention is directed to systems and methods for securing a digital operational environment that manages financial accounting, human capital administration, supply chain coordination, procurement, inventory, and customer processes. In particular, the present invention is directed to an artificial intelligence threat detection and prevention system for an enterprise resource planning environment. Enterprise resource planning environments are often characterized by a diverse set of modules and databases that facilitate the storage, retrieval, aggregation, and processing of critical transaction, personnel, and operational data and may be subject to a variety of threats ranging from external intrusion attempts to non-malicious errors originating from authorized users. Enterprise resource planning environments are becoming increasingly important to the continued operations of organizations. These environments may provide consolidated data and data processing across different business functions. Consolidation can create concentrated areas of risk that are challenging to secure using traditional rule-based, signature-based, and perimeter defense methodologies. In particular, threats that utilize insider knowledge, compromise authorized accounts, establish privilege escalation channels, manipulate processes, and exfiltrate data in subtle ways can create significant exposure to business loss and reputational harm. The invention provides an artificial intelligence-based solution that addresses the limitations of conventional approaches by providing a behavioral threat detection solution for enterprise resource planning environments. The invention employs a system and method that utilizes artificial intelligence to detect anomalous behavior patterns of users, applications, processes, and interactions within the enterprise resource planning environment. In one embodiment, a data collection and feature extraction module collects and aggregates streams of data indicative of authentication events, transactions, database records, application programming interface requests, session records, file access records, and network traffic internal to the enterprise resource planning environment. The streams are processed to normalize the data and extract features that encode temporal patterns, hierarchical relationships, and dependencies, with the resulting data being provided to a group of artificial intelligence models. The group of artificial intelligence models can include supervised learning models that utilize data indicative of known events, unsupervised learning models that utilize data indicative of known events, and sequence learning models that utilize data indicative of known events. The invention determines baseline behavioral patterns from the data by utilizing an abstraction that captures individual, role, process, and entity relationship behavioral patterns. Individual behavioral patterns can encode patterns of activity for individual users, including elements such as login hours and activity, modules accessed, transaction rates and volume, data access patterns, and common sequences of operations. Role behavioral patterns capture the expected behavior of groups of individuals, enabling the identification of anomalous behavior for individuals based on group behavior as well as deviations from previously observed behavior patterns for groups. Process behavioral patterns encode process-level expectations, capturing deviations in process flows that could indicate unauthorized data access or privilege escalation. Entity relationship behavioral patterns capture the relationships between users, records, and processes to identify behavior patterns that deviate from the expected relationships that could indicate data or process abuse. If anomalous behavior patterns are detected by any of the artificial intelligence models, the system can analyze the detected patterns to determine if the patterns indicate a potential security concern. The analysis can include determining a risk level associated with the anomalous behavior patterns, including evaluating the impact to the business if an unauthorized event were to occur and taking into account the entity associated with the anomalous behavior. Additionally, the analysis can include determining a confidence level for the detected pattern as an indicator of an actual security event. In embodiments, the system includes an explainability module that aids in providing actionable insight by presenting natural language descriptions of anomalous behavior patterns detected by the system, improving analyst situational awareness and reducing alert fatigue. The invention provides a variety of prevention mechanisms for mitigating or eliminating the impact of potentially unauthorized events. Prevention mechanisms can include issuing warnings to relevant users or administrators, restricting or terminating sessions associated with an event, quarantining transactions for later analysis, rolling back transactions, and responding to events based on pre-configured incident response playbooks. The warning level of such alerts can be determined based on the risk level of the event, with higher severity events triggering alerts that prompt immediate administrator intervention. Additionally, the prevention mechanisms of the invention can be implemented in a manner that does not cause unnecessary disruption to enterprise operations by providing granular controls for responding to anomalous events based on a variety of risk factors. The invention has an architecture that allows it to be deployed in a manner that facilitates securing enterprise resource planning environments that includes deploying lightweight agents to capture the data streams described above. The data can then be processed and analyzed using centralized analytics components that include the artificial intelligence models and behavioral pattern repository that can be implemented in a variety of infrastructures, including on-premises systems, private cloud environments, and hybrid combinations. In addition, the analytics components can include continuous learning components that allow the artificial intelligence models to update the behavioral pattern repository based on the data collected from enterprise resource planning environments as described above. This allows the invention to learn from events that occur in the enterprise resource planning environment as well as updates from administrators to refine and update the detected patterns, reducing false positives and improving the overall accuracy of the system. One particular advantage of the invention over conventional systems and methods is that it enables the detection of threats that utilize legitimate access to systems and data. Conventional enterprise resource planning systems are often subject to attacks that leverage authorized accounts to access data and modify configurations in ways that are challenging to distinguish from legitimate user activity. These attacks are challenging to detect using conventional rule-based systems, especially since they do not always follow easily identifiable patterns. By detecting anomalous behaviors that differ from user and process behavioral patterns, the invention is able to identify such threats even at early stages before significant damage or data exfiltration occurs. Additionally, the use of a variety of artificial intelligence models enables the system to be effective against threats utilizing a diverse range of attack vectors, including those that employ traditional perimeter-based attack surfaces and more sophisticated insider attacks that seek to compromise critical processes and data. The invention also recognizes the importance of protecting the privacy of users while analyzing data to detect potentially unauthorized events. In particular, the invention can employ a variety of data privacy technologies to reduce the exposure of user data during the analysis, including the use of differential privacy algorithms in the analysis of data, federated learning approaches that enable the training of artificial intelligence models using data from multiple enterprises while reducing the risk of exposing private data, and encrypted computation. By analyzing data while protecting such data using well- established data privacy technologies, the invention reduces exposure of such data to potential data privacy risks that may arise from analyzing data in conventional centralized data warehouses. The invention operates in an enterprise resource planning environment where it observes the enterprise resource planning data streams, learns and builds behavioral pattern models during periods of known legitimate activity, and continually updates and refines such patterns based on the data streams. The system can use administrator- specified assets and process policies to ensure that higher priority assets and processes receive additional scrutiny when anomalous behavior patterns are observed. Using the described elements, the invention provides behavioral-based threat detection and prevention capabilities that protect enterprise resource planning environments from a variety of attack types. In embodiments, the system can be configured to operate across enterprise resource planning environments, analyzing behavior patterns in one or more such environments while enabling the correlation of data and behaviors observed across different environments to detect coordinated attacks. Additionally, information derived by the invention can be provided in the form of packages of risk intelligence that can be consumed by other security information and event management systems while preserving the ability to analyze behaviors specific to enterprise resource planning environments. The system can therefore provide significant benefits by leveraging the advantages of specialized analysis of enterprise resource planning environments while enabling broader enterprise-level analysis. The invention provides an artificial intelligence driven threat detection and prevention system that significantly improves the ability to secure enterprise resource planning environments, including detecting threats that conventional rule-based and signature-based systems are unable to detect. The invention provides a system that reduces the volume of alerts and enables faster response to threats, improving the security posture of enterprise resource planning environments without disrupting the operations of the business processes managed by such environments.
Disclaimer: Curated by HT Syndication.