Application Control Rules via User Competency Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing application control systems struggle to effectively generate rules for managing applications on computing devices, often blocking harmless software while failing to adequately protect against malicious programs, as they rely on whitelisting approaches that do not account for unknown or unclassified applications.
Innovation Solution
A method and system that classify applications into predetermined groups, determine a user's computer competency score, and categorize applications based on their functions, purpose, and criticality scores to define control rules, allowing for more nuanced access control and reducing the blocking of harmless software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a default denial approach with a whitelist of trusted applications is used, then protection against malicious software is improved, but harmless unknown applications are blocked
Solution Approach 1:
The system changes the parameter of application classification from binary (trusted/untrusted) to multi-dimensional by introducing competency scores for both users and applications. This allows dynamic adjustment of control rules based on calculated scores, enabling the system to adaptively allow or block applications based on their compatibility and trustworthiness rather than relying solely on predefined whitelists
Solution Approach 2:
The patent replaces the static mechanical whitelist approach with a dynamic scoring mechanism. Instead of manually maintaining lists of trusted applications, the system automatically calculates competency scores based on user profiles, application characteristics, and compatibility data, then uses these scores to dynamically generate control rules
2Adaptability or versatility
If application control rules are made more permissive to allow unknown applications, then adaptability is improved, but protection against malicious software deteriorates
Solution Approach 1:
The system implements feedback mechanisms where control rules are continuously adjusted based on competency score calculations. The system monitors application behavior, updates user and application competency scores, and dynamically modifies control rules accordingly, creating a closed-loop system that adapts to new applications while maintaining security
3Reliability
If control rules are customized for each user and application, then effectiveness of protection is improved, but system complexity increases
Solution Approach 1:
The system enables self-service by automatically generating control rules based on calculated competency scores without requiring manual administrator intervention for each application. The system autonomously evaluates user and application profiles, computes compatibility scores, and formulates appropriate control rules, reducing administrative burden while maintaining high effectiveness
Data Source
AI summary
Disclosed is a system and method for configuring control rules for applications executable on a computer. An example method includes classifying computer applications into one of a plurality of classification groups that include at least one predetermined classification group and an unknown classification group. The method further includes configuring control rules when the applications are classified in the unknown classification group that is done by determining, by the hardware processor, a computer competency score for a user of the computer; categorizing the applications into one or more predefined categories, and defining control rules for the application based on the determined computer competency score for the user and the one or more predefined categories of the at least one application.


