Adaptive Risk Profile System for Help Desk Service Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Help desks face challenges in effectively managing risk profiles for service requests, particularly in preventing social engineering attacks and efficiently verifying user identities, as existing systems lack adaptive risk management and automated initial risk assessment capabilities.

Innovation Solution

A system that includes a filtering module for initial risk profile assessment, a ticketing module for storing risk profiles, and adaptive rules to modify risk levels based on user interactions, combined with automated call filtering and human operator input, allowing for efficient service provision by verifying user identities through various controls and override functionalities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual risk assessment is performed by help desk agents, then security verification can be conducted, but the workload on agents increases and processing time extends

Engineering Contradiction:
Improvesecurity verificationVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary risk assessment actions automatically before the help desk agent receives the service request. The filtering module evaluates risk factors and establishes an initial risk profile level automatically, so that when the agent receives the request, the preliminary security verification is already completed, reducing their workload and processing time while maintaining security reliability

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple controls are implemented for high-risk requests, then security verification improves, but the complexity of the verification process increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts the number and type of controls implemented based on the assessed risk profile level. For low-risk requests, fewer controls are applied; for high-risk requests, more controls are implemented. This dynamic adaptation allows the system to maintain high security verification reliability for critical requests while reducing verification process complexity for routine requests

Inventive Principle:
Principle #15Dynamics

3Productivity

If automated risk assessment is implemented, then processing efficiency improves, but the system complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsystem structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the risk assessment function into a separate filtering module that operates independently from the main service provision system. This modular segmentation allows automated risk assessment to be implemented as a distinct component, improving processing efficiency while containing system complexity within a well-defined module rather than throughout the entire system

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8326654B2Providing a service to a service requester
Publication Date: 2012.12.04 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8326654B2 patent drawing
  • US8326654B2 patent drawing
  • US8326654B2 patent drawing

AI summary

A data processing system for providing a service to a service requester is provided. The data processing system includes a filtering module to receive a request for a service from the service requester, and a ticket module to create a ticket. The ticket includes a risk profile level which is one of a predefined number of levels. The system further includes at least a first and second rule. The first rule specifies a control and the risk profile level response to a result obtained from the service requester. The second rule specifies a maximum acceptable risk profile level required to serve the service. An interface includes an output module to output the control to an agent and an input module to allow input of the service requester's response to the control. A modifier modifies the risk profile level according to the first rule and the service requester's response. The modifier compares the risk profile level with the maximum acceptable risk profile level. A service provision module allows the service to be performed if the risk profile level is less than or equal to the maximum acceptable risk profile level.