Aggregated Application Access Risk Scoring via Layered Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security frameworks struggle to accurately assess access risk for applications by not considering the configuration of the computing environment and other access risk mitigation features, leading to unnecessary resource utilization and misidentification of actual access risks.

Innovation Solution

A system that generates aggregated application access risk scores by identifying multiple security layers associated with an application, determining layer access risk scores, calculating residual access risk scores based on mitigation information, and assigning risk contribution weights to produce a comprehensive access risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing security frameworks assess access risk without considering computing environment configuration and mitigation features, then the assessment process is simple, but the accuracy of risk assessment deteriorates and unnecessary resource utilization increases

Engineering Contradiction:
Improveaccuracy of risk assessmentVSAvoidcomplexity of security framework
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security framework into multiple distinct layers (network layer, host layer, application layer, data layer), each assessed independently for access risk. This segmentation allows comprehensive evaluation of each layer's specific risks and mitigation features while maintaining organized complexity, resolving the contradiction between thorough assessment and framework simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a multi-dimensional assessment approach by evaluating access risk across four distinct security layers rather than using a single holistic assessment. This dimensional expansion enables more precise measurement of risk accuracy while structuring the complexity in an organized, manageable framework that doesn't overwhelm the assessment process.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If existing security frameworks do not calculate residual access risk scores based on mitigation information, then the calculation process is faster, but the identification of actual access risks becomes inaccurate

Engineering Contradiction:
Improveidentification accuracy of actual access risksVSAvoidtime for risk assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary identification and evaluation of access risk mitigation features at each security layer before calculating the final residual access risk score. By预先 identifying mitigation measures (such as security controls, configurations, and protective mechanisms) and their effectiveness, the framework prepares the necessary information in advance, enabling accurate risk identification without excessive calculation time during the actual assessment.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If existing security frameworks assign equal weight to all security layers, then the assessment process is simpler, but the aggregated risk score fails to reflect the true relative importance of different layers

Engineering Contradiction:
Improveaccuracy of aggregated risk scoreVSAvoidcomplexity of risk weighting
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different risk contribution weights to different security layers based on their specific characteristics, importance, and vulnerability profiles. Each layer (network, host, application, data) receives a weight reflecting its local quality and relative importance to overall application security, enabling the aggregated risk score to accurately reflect the true security posture without requiring complex manual configuration.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250156552A1Systems and methods for generating aggregated application access risk scores
Publication Date: 2025.05.15 CAPITAL ONE SERVICES LLC
  • US20250156552A1 patent drawing
  • US20250156552A1 patent drawing
  • US20250156552A1 patent drawing

AI summary

A system determines, based on a request to assess access risk associated with an application, a plurality of layer access risk scores that are associated with the application. The system determines, based on access risk mitigation information and the plurality of layer access risk scores, a plurality of layer residual access risk scores. The system determines respective risk contribution weights associated with the plurality of layer residual access risk scores. The system determines, based on the respective risk contribution weights and on the plurality of layer residual access risk scores, an aggregated application access risk score associated with the application. The system causes, based on the aggregated application access risk score, one or more actions to be performed. For example, the system may initiate an access risk analysis process for the application and/or may generate an access control policy associated with the application.