Adaptive Risk Policy Generation from Organizational Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing risk detection systems face challenges in adapting quickly to unique customer data and attack types, leading to potential losses during the learning period of risk engines, with generic policies resulting in high false positives and requiring significant customer effort to create proprietary rules.
Innovation Solution
A data-driven method for generating adaptive policies by identifying relevant features, calculating probabilities, and determining intervention rates to detect risk-related events, which can be applied during the learning phase of risk engines and beyond.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If generic policies are used in risk detection systems, then implementation is simple and immediate, but false positives increase and detection accuracy deteriorates
Solution Approach 1:
The system performs preliminary actions by automatically extracting features and generating policies before the risk engine's learning period begins. This allows tailored policies to be ready in advance, eliminating the need to wait for the risk engine to learn from data while avoiding generic policy limitations.
Solution Approach 2:
The system enables self-service by automatically extracting relevant features from organizational data and generating tailored policies without requiring manual intervention. The process autonomously identifies patterns, calculates probabilities, and creates intervention strategies, freeing customers from manual policy creation efforts.
2Adaptability or versatility
If manual policy creation is performed by customers, then policies can be highly tailored to unique environments, but significant customer effort and time are required
Solution Approach 1:
The system performs self-service by automatically extracting features, calculating probabilities, and generating tailored policies without requiring manual customer input. This maintains high adaptability to unique organizational environments while eliminating the time and effort customers would otherwise need to invest in policy creation.
Solution Approach 2:
The system replaces the mechanical process of manual policy creation with an automated machine learning-based approach. Instead of customers manually crafting policies, the system uses algorithms to automatically generate tailored policies from organizational data, maintaining customization while eliminating manual labor.
3Reliability
If risk engines undergo learning period to adapt to unique data and attack types, then detection accuracy improves, but potential losses occur during the learning period
Solution Approach 1:
The system performs preliminary policy generation before the risk engine's learning period begins. By extracting features and creating tailored policies in advance, the system provides immediate protective action during the learning period, preventing losses that would otherwise occur while the risk engine adapts to unique data and attack types.
Solution Approach 2:
The system introduces an intermediary layer of automatically generated policies that bridge the gap between generic policies and fully adapted risk engine performance. These intermediary policies provide tailored protection during the learning period, mediating between the need for immediate protection and the risk engine's ongoing adaptation process.
4Productivity
If proprietary rules are created to address specific organizational needs, then detection performance optimizes, but device complexity and implementation difficulty increase
Solution Approach 1:
The system maintains high detection performance through self-service automation. By automatically extracting features, calculating probabilities, and generating tailored policies, the system achieves proprietary rule effectiveness without requiring manual creation. This eliminates the complexity associated with manual policy development while maintaining optimized detection performance.
Solution Approach 2:
The system changes the parameters of policy generation from manual specification to automated calculation. Instead of customers manually defining complex rules, the system automatically determines policy parameters based on extracted features and calculated probabilities, achieving optimized performance while reducing implementation complexity.
Data Source
AI summary
Techniques are provided for generating adaptive policies from organization data for detection of risk-related events. One method comprises obtaining features identified in organization data of an organization for a risk analysis, wherein a given feature comprises a plurality of data values, wherein each data value for the given feature comprises a discrete value of the given feature or a range of values for the given feature; obtaining a probability of occurrence associated with each data value based on the organization data; identifying a plurality of candidate anomalous data values based on the probabilities of occurrence; determining an intervention rate for a plurality of combinations of the candidate anomalous data values; and generating policies for the organization using the combinations of candidate anomalous data values based on a corresponding intervention rate. The generated policies are used to detect one or more risk-related events.


