Adaptive Endpoint Risk Assessment via Dynamic Monitoring Intervals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security monitoring and risk assessment approaches fail to effectively identify and adapt to anomalous or malicious user behavior, leading to inefficient resource utilization and potential security breaches, as they do not differentiate between varying risk levels of user interactions.
Innovation Solution
A method and system for adaptively assessing risk associated with an endpoint by determining a risk level, selecting a monitoring interval, collecting and processing user behavior data, and comparing current risk scores to historical scores to adjust monitoring and security policies dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If indiscriminate security monitoring is applied to all user behavior, then security coverage is improved, but resource utilization efficiency deteriorates
Solution Approach 1:
The patent applies different monitoring intensities and risk assessment levels to different users and behaviors based on their specific risk profiles. High-risk users receive intensified monitoring while low-risk users receive standard monitoring, optimizing resource allocation across the system.
Solution Approach 2:
The monitoring system dynamically adjusts its intensity and resource allocation based on real-time risk assessments. When anomalous behavior is detected, the system automatically increases monitoring for that specific user or behavior pattern, rather than maintaining static uniform monitoring across all users.
2Stability of the object's composition
If uniform security policies are applied to all user behavior, then policy consistency is improved, but detection of anomalous behavior deteriorates
Solution Approach 1:
The patent segments users into different risk categories and applies tailored security policies to each segment. This allows the system to maintain overall policy consistency while implementing differentiated monitoring and response strategies for high-risk versus low-risk users.
Solution Approach 2:
The system changes monitoring parameters such as sampling frequency, data collection depth, and alert thresholds based on user risk profiles. High-risk users experience more intensive monitoring with lower thresholds for triggering security events, while low-risk users experience lighter monitoring.
3Measurement precision
If risk assessment is performed continuously for all users, then detection accuracy is improved, but system overhead deteriorates
Solution Approach 1:
The patent performs continuous risk assessment only for users who exhibit anomalous behavior or fall into high-risk categories, rather than continuously monitoring all users. This partial application of intensive monitoring significantly reduces system overhead while maintaining high detection accuracy for problematic cases.
Solution Approach 2:
The system uses feedback from initial risk assessments to dynamically adjust monitoring intensity. Users who trigger risk thresholds receive intensified continuous monitoring, while those who do not trigger thresholds receive periodic or reduced monitoring, optimizing the balance between detection accuracy and system overhead.
Data Source
AI summary
A method, system and computer-usable medium for adaptively assessing risk associated with an endpoint, comprising: determining a risk level corresponding to an entity associated with an endpoint; selecting a frequency and a duration of an endpoint monitoring interval; collecting user behavior to collect user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint; processing the user behavior to generate a current risk score for the entity; comparing the current risk score of the user to historical risk scores to determine whether a risk score of a user has changed; and changing the risk score of the user to the current risk score when the risk score of the user has changed.


