Adaptive Security Actions for Network Risk Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Secure Access Service Edge (SASE) services rely on manually generated rules for mitigating security risks, which can be tedious, inaccurate, and lead to high false alarm rates, causing unnecessary inconvenience to users.
Innovation Solution
The method involves defining event costs and action costs, creating prediction models for each user to predict security events and their severity, and generating an action list to block permissions based on these predictions and costs, allowing for adaptive and optimized action decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manually generated rules are used to block permissions based on risk scores, then security risk mitigation is achieved, but false alarm rate increases and user convenience deteriorates
Solution Approach 1:
The patent changes the parameter basis for decision-making from static manually-generated rules to dynamic multi-factor parameters including event costs, action costs, and predictive risk scores. This allows the system to adjust blocking decisions based on weighted combinations of multiple parameters rather than single threshold rules, reducing false alarms while maintaining security.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously learns from blocked and unblocked events, adjusting prediction models and cost parameters accordingly. This feedback loop enables the system to refine its decision-making over time, reducing false alarms while improving security detection accuracy.
2Reliability
If manually generated rules are used to block permissions, then security risk mitigation is achieved, but system complexity and maintenance burden increase
Solution Approach 1:
The patent enables the system to automatically generate and update its own security policies through machine learning prediction models that continuously analyze event data and adjust blocking decisions. This self-service capability eliminates the need for manual rule creation and maintenance, reducing system complexity while maintaining effective security mitigation.
Solution Approach 2:
The patent replaces the mechanical manual rule-generation process with automated machine learning systems that predict security risks and generate blocking decisions algorithmically. This substitution transforms the complex manual process of creating and maintaining security rules into an automated computational process.
3Reliability
If aggressive blocking actions are taken based on risk thresholds, then security protection is improved, but user convenience and productivity deteriorate
Solution Approach 1:
The patent applies different blocking actions to different users and permissions based on local characteristics such as user role, permission importance, and predicted event severity. Instead of uniform aggressive blocking, the system tailors actions to specific contexts, maintaining security protection while preserving user convenience for low-risk scenarios.
Solution Approach 2:
The patent implements partial blocking actions where only specific permissions are blocked rather than complete user blocking. The system applies the minimum necessary blocking action to mitigate detected risks while allowing other permissions to remain functional, thus maintaining productivity while providing security protection.
Data Source
AI summary
System and method for taking actions to mitigate security risks in a computer network are disclosed. The costs of security events and taking actions to block permissions granted to users are defined. For each of the users, prediction models are created, one for each of the security events. Using prediction models of a selected user, predictions on whether the security events will occur and/or predictions of severity if the security events actually occur are generated. For the selected user, an action list that indicates whether or not to take actions to block particular permissions granted to the selected user is generated based at least on the predictions, costs of the events, and costs of the permissions.


