Behavioral Security Policy for Dynamic Scan Sensitivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security agents face challenges in balancing malware detection sensitivity with false positives, as users with varying risk levels are often subjected to uniform security policies, leading to either excessive interruptions or missed threats, particularly in BYOD scenarios where personalized risk assessment is difficult to manage.
Innovation Solution
A security agent that monitors user behavior using machine learning and heuristic algorithms to assess risk levels based on browser history and settings, adjusting scan sensitivity accordingly to provide optimal protection with minimal disruption, allowing for per-user configuration of security settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If uniform security policies are applied to all users, then security coverage is simplified, but false positives increase and user experience deteriorates
Solution Approach 1:
The patent applies local quality by transitioning from uniform security policies to personalized security policies tailored to each user's risk profile. The system monitors user behavior, determines risk levels, and adjusts scan sensitivity accordingly, so that high-risk users experience more aggressive scanning while low-risk users experience minimal disruption. This resolves the contradiction by making security policy quality local to each user rather than uniform across all users.
2Reliability
If high scan sensitivity is applied to detect all malware, then threat detection improves, but false positives increase and user interruptions worsen
Solution Approach 1:
The patent applies parameter changes by dynamically adjusting the scan sensitivity parameter based on each user's risk profile. Instead of using a fixed high sensitivity setting for all users, the system modifies the sensitivity parameter according to individual behavior patterns and risk assessments. This allows the system to maintain high malware detection capability for high-risk users while reducing false positives for low-risk users, resolving the contradiction between detection reliability and false positive reduction.
3Measurement precision
If personalized risk assessment is implemented, then security accuracy improves, but system complexity increases
Solution Approach 1:
The patent applies self-service by enabling the security system to automatically monitor user behavior, determine risk profiles, and adjust security settings without requiring manual configuration or complex administrative intervention. The system serves itself by autonomously collecting data, analyzing patterns, and making policy adjustments, thereby achieving personalized risk assessment accuracy while minimizing the increase in system complexity through automation rather than manual processes.
Data Source
AI summary
There is disclosed in one example a computing apparatus, including: a hardware platform including at least a processor and a memory; and a security agent including instructions encoded in the memory to instruct the processor to: monitor a user's operation of the computing apparatus over time, including determining whether a selected behavior is a security risk; provide a risk analysis of the user's operation based at least in part on the monitoring; select a scan sensitivity based at least in part on the risk analysis; and scan, with the selected sensitivity, one or more objects on the computing apparatus to determine if the one or more objects are a threat.


