Behavioral Security Policy for Dynamic Scan Sensitivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security agents face challenges in balancing malware detection sensitivity with false positives, as users with varying risk levels are often subjected to uniform security policies, leading to either excessive interruptions or missed threats, particularly in BYOD scenarios where personalized risk assessment is difficult to manage.

Innovation Solution

A security agent that monitors user behavior using machine learning and heuristic algorithms to assess risk levels based on browser history and settings, adjusting scan sensitivity accordingly to provide optimal protection with minimal disruption, allowing for per-user configuration of security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If uniform security policies are applied to all users, then security coverage is simplified, but false positives increase and user experience deteriorates

Engineering Contradiction:
Improvesecurity policy managementVSAvoiduser experience
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent applies local quality by transitioning from uniform security policies to personalized security policies tailored to each user's risk profile. The system monitors user behavior, determines risk levels, and adjusts scan sensitivity accordingly, so that high-risk users experience more aggressive scanning while low-risk users experience minimal disruption. This resolves the contradiction by making security policy quality local to each user rather than uniform across all users.

Inventive Principle:
Principle #3Local quality

2Reliability

If high scan sensitivity is applied to detect all malware, then threat detection improves, but false positives increase and user interruptions worsen

Engineering Contradiction:
Improvemalware detectionVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies parameter changes by dynamically adjusting the scan sensitivity parameter based on each user's risk profile. Instead of using a fixed high sensitivity setting for all users, the system modifies the sensitivity parameter according to individual behavior patterns and risk assessments. This allows the system to maintain high malware detection capability for high-risk users while reducing false positives for low-risk users, resolving the contradiction between detection reliability and false positive reduction.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If personalized risk assessment is implemented, then security accuracy improves, but system complexity increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the security system to automatically monitor user behavior, determine risk profiles, and adjust security settings without requiring manual configuration or complex administrative intervention. The system serves itself by autonomously collecting data, analyzing patterns, and making policy adjustments, thereby achieving personalized risk assessment accuracy while minimizing the increase in system complexity through automation rather than manual processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11443035B2Behavioral user security policy
Publication Date: 2022.09.13 MCAFEE LLC
  • US11443035B2 patent drawing
  • US11443035B2 patent drawing
  • US11443035B2 patent drawing

AI summary

There is disclosed in one example a computing apparatus, including: a hardware platform including at least a processor and a memory; and a security agent including instructions encoded in the memory to instruct the processor to: monitor a user's operation of the computing apparatus over time, including determining whether a selected behavior is a security risk; provide a risk analysis of the user's operation based at least in part on the monitoring; select a scan sensitivity based at least in part on the risk analysis; and scan, with the selected sensitivity, one or more objects on the computing apparatus to determine if the one or more objects are a threat.