Cloud Security Risk Scoring Using Multi-Attribute Empirical Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud-based security systems rely on transaction counts to identify high-risk users, which may not accurately reflect the actual security risk, as users or groups with lower negative event counts can pose greater risks.
Innovation Solution
Implementing a method that maintains logs of transactions, obtains attributes, performs empirical scoring to normalize and rank risky entities, and updates policies and monitoring to focus on the highest risk entities, using primary and secondary attributes, and applying modifiable weightings to security policy violations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional transaction-based counting is used to identify high-risk users, then the system can quickly identify users with high negative event counts, but the accuracy of security risk determination deteriorates because users with lower counts may actually pose greater risk
Solution Approach 1:
The patent transforms the single-parameter transaction count metric into a multi-parameter empirical scoring system that evaluates multiple attributes including but not limited to transaction count, user behavior patterns, device characteristics, and threat category severity. This parameter transformation enables more accurate security risk determination by considering diverse factors beyond simple transaction volume.
Solution Approach 2:
The patent adds dimensional depth to risk assessment by introducing hierarchical scoring levels (primary attributes, secondary attributes, tertiary attributes) and temporal dimensions (rolling time windows, trend analysis). This multi-dimensional approach allows the system to evaluate users from multiple perspectives simultaneously, improving measurement precision without excessive complexity through structured organization.
2Reliability
If the system focuses monitoring on users with highest transaction counts, then resource allocation is simplified, but the effectiveness of security protection deteriorates as truly high-risk users with lower transaction counts are missed
Solution Approach 1:
The patent replaces manual security analysis and simple threshold-based monitoring with an automated empirical scoring system that continuously evaluates users against normalized criteria. This substitution maintains ease of operation through automation while significantly improving reliability by systematically identifying high-risk users based on comprehensive attribute analysis rather than simple transaction counting.
Solution Approach 2:
The patent implements feedback mechanisms where the empirical scoring system continuously monitors user behavior, updates risk scores based on new transactions and attribute changes, and dynamically adjusts monitoring priorities. This feedback loop ensures the system adapts to emerging threats and maintains high protection effectiveness while operating automatically without manual intervention.
3Measurement precision
If empirical scoring with multiple attributes and normalizations is implemented, then accurate risk ranking is achieved, but the computational complexity and data processing requirements increase
Solution Approach 1:
The patent segments the empirical scoring process into distinct hierarchical levels (primary attributes, secondary attributes, tertiary attributes) and processes them in organized stages. This segmentation allows computational resources to be efficiently allocated to different scoring components, maintaining high measurement precision while managing computational complexity through structured, modular processing.
Solution Approach 2:
The patent implements selective attribute evaluation where the system processes only the most relevant attributes for each user context rather than uniformly analyzing all possible attributes for every user. This partial action approach reduces computational resource consumption while maintaining accurate risk scoring by focusing processing power on the most discriminative attributes for each specific assessment.
Data Source
AI summary
Systems and method are implemented by one or more servers associated with a cloud-based security system, for determining security risks of entities including users or groups of users associated with the cloud-based security system and optimizing remediation based thereon. The method includes maintaining logs of transactions through the cloud-based security system; obtaining a plurality of attributes from the transactions while excluding impossible comparison items from the transactions; performing empirical scoring on normalizing the plurality of attributes for ranking risky entities; identifying the risky entities based on one of the empirical scoring and analytics; and updating policies and/or monitoring in the cloud-based system based on the identifying. The cloud-based security system is multi-tenant system supporting a plurality of users, companies, and/or enterprises and the empirical scoring provides a deterministic comparison between the plurality of users, companies, and/or enterprises in the multi-tenant system.


