Adaptive Policy Security System for Dynamic User Behavior

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems are inadequate in dynamically adapting to user behavior, often resulting in either overly broad policies that block legitimate actions or failing to detect security threats in a timely manner.

Innovation Solution

An adaptive policy-based computer security method that monitors user behavior, triggers customized security policies based on specific actions, and adjusts policies by classifying actions as either security threats or false positives, implementing a tailored approach to block malicious activities while allowing legitimate ones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If broad security policies are implemented to detect and prevent security violations, then security coverage is improved, but legitimate user actions are blocked

Engineering Contradiction:
Improvesecurity coverageVSAvoidlegitimate user actions
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments broad security policies into multiple sub-policies, each addressing specific security concerns. Instead of applying a single broad policy that blocks all potentially suspicious actions, the system divides the policy space into targeted sub-policies that can be independently evaluated. This allows the system to maintain comprehensive security coverage while reducing false positives that block legitimate user actions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic policy adaptation by monitoring user behavior over time and adjusting policy enforcement accordingly. The system transitions from static broad policies to dynamic sub-policies that adapt to individual user patterns. This dynamic approach allows the system to maintain high security coverage for malicious activities while automatically accommodating legitimate user behaviors that were previously blocked.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If monitoring and analysis of user behavior is performed to distinguish threats from false positives, then security precision is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex task of threat detection into multiple independent sub-policies, each focusing on specific behavioral patterns or security concerns. This segmentation allows the system to analyze user behavior through multiple specialized lenses rather than requiring a single complex analysis engine, thereby improving detection precision while managing system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms where user behavior is continuously monitored, analyzed, and used to refine policy enforcement decisions. The system collects data on user actions, evaluates them against sub-policies, and uses the results to improve future detection accuracy. This feedback loop enhances measurement precision by learning from actual user behavior patterns while maintaining manageable complexity through iterative refinement rather than requiring overly complex upfront analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11044271B1Automatic adaptive policy based security
Publication Date: 2021.06.22 GEN DIGITAL INC
  • US11044271B1 patent drawing
  • US11044271B1 patent drawing
  • US11044271B1 patent drawing

AI summary

A method for implementing adaptive policy based computer security is described. In one embodiment, the method may include monitoring a behavior of a user on a computing device associated with the user, determining whether the user triggers one or more policy triggers associated with a broad policy or at least one sub-policy of the broad policy, or both, and upon determining the user triggers at least one policy trigger during the monitoring period, implementing a customized version of the broad policy on the computing device. In some cases, the method may include implementing the broad policy on the computing device upon determining the user does not trigger any of the one or more policy triggers. In other cases, the method may include triggering at least one of the policy triggers based at least in part on a requested action and determining whether the requested action includes a security threat.