Aggregated Application Access Risk Scoring via Layered Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security frameworks struggle to accurately assess access risk for applications by not considering the configuration of the computing environment and other access risk mitigation features, leading to unnecessary resource utilization and misidentification of actual access risks.
Innovation Solution
A system that generates aggregated application access risk scores by identifying multiple security layers associated with an application, determining layer access risk scores, calculating residual access risk scores based on mitigation information, and assigning risk contribution weights to produce a comprehensive access risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing security frameworks assess access risk without considering computing environment configuration and mitigation features, then the assessment process is simple, but the accuracy of risk assessment deteriorates and unnecessary resource utilization increases
Solution Approach 1:
The patent segments the security framework into multiple distinct layers (network layer, host layer, application layer, data layer), each assessed independently for access risk. This segmentation allows comprehensive evaluation of each layer's specific risks and mitigation features while maintaining organized complexity, resolving the contradiction between thorough assessment and framework simplicity.
Solution Approach 2:
The patent introduces a multi-dimensional assessment approach by evaluating access risk across four distinct security layers rather than using a single holistic assessment. This dimensional expansion enables more precise measurement of risk accuracy while structuring the complexity in an organized, manageable framework that doesn't overwhelm the assessment process.
2Measurement precision
If existing security frameworks do not calculate residual access risk scores based on mitigation information, then the calculation process is faster, but the identification of actual access risks becomes inaccurate
Solution Approach 1:
The patent performs preliminary identification and evaluation of access risk mitigation features at each security layer before calculating the final residual access risk score. By预先 identifying mitigation measures (such as security controls, configurations, and protective mechanisms) and their effectiveness, the framework prepares the necessary information in advance, enabling accurate risk identification without excessive calculation time during the actual assessment.
3Measurement precision
If existing security frameworks assign equal weight to all security layers, then the assessment process is simpler, but the aggregated risk score fails to reflect the true relative importance of different layers
Solution Approach 1:
The patent applies local quality by assigning different risk contribution weights to different security layers based on their specific characteristics, importance, and vulnerability profiles. Each layer (network, host, application, data) receives a weight reflecting its local quality and relative importance to overall application security, enabling the aggregated risk score to accurately reflect the true security posture without requiring complex manual configuration.
Data Source
AI summary
A system determines, based on a request to assess access risk associated with an application, a plurality of layer access risk scores that are associated with the application. The system determines, based on access risk mitigation information and the plurality of layer access risk scores, a plurality of layer residual access risk scores. The system determines respective risk contribution weights associated with the plurality of layer residual access risk scores. The system determines, based on the respective risk contribution weights and on the plurality of layer residual access risk scores, an aggregated application access risk score associated with the application. The system causes, based on the aggregated application access risk score, one or more actions to be performed. For example, the system may initiate an access risk analysis process for the application and/or may generate an access control policy associated with the application.


