Co-located Assessment Agents for Communication Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing risks associated with electronic communications, particularly when using external communication systems, as they struggle to enforce security standards due to the involvement of external service providers, making it difficult to identify and mitigate risky resources within communication systems that are often inaccessible for security management.

Innovation Solution

Implementing a system with co-located assessment agents that monitor communication traffic, determine assets and interactions, assign risk scores, and modify assets based on these scores to display risk information to users, while also providing just-in-time training to enhance user awareness and security practices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations block access to external communication services completely, then security risk is reduced, but communication functionality and productivity are lost

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidcommunication functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary assessment system that sits between the organization and external communication services. This system includes components that intercept, assess, and mediate communications without blocking access entirely. The intermediary provides real-time risk assessment of external communications while allowing legitimate business communications to proceed, thus resolving the contradiction between security and productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where communication risk is continuously assessed and information is fed back to users and security systems. This includes real-time risk scoring of communications, user notifications about risky messages, and dynamic adjustment of security policies based on assessed threats. The feedback loop enables security protection without complete blocking, maintaining productivity while mitigating risks.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If organizations use external communication services, then communication effectiveness improves, but security control and monitoring become difficult

Engineering Contradiction:
Improvecommunication effectivenessVSAvoidsecurity management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent enables self-service capabilities where the communication system itself performs security assessments. The assessment system automatically evaluates communications, identifies risks, and applies appropriate security measures without requiring manual intervention. This includes automated risk scoring, dynamic policy application, and self-monitoring of communication patterns, reducing security management complexity while maintaining effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal assessment framework that handles multiple types of communications (email, chat, collaboration tools) through a single integrated system. This multi-functional approach consolidates security management across diverse communication platforms, simplifying what would otherwise be complex multi-system management while maintaining comprehensive security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If organizations implement training programs, then user security awareness improves, but continuous monitoring of actual user behavior remains difficult

Engineering Contradiction:
Improveuser security awarenessVSAvoiduser behavior monitoring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements continuous feedback loops that monitor actual user communication behavior and compare it against security best practices. The system provides real-time feedback to users about risky behaviors, tracks compliance with security policies, and adjusts training requirements based on observed behavior patterns. This continuous monitoring and feedback mechanism bridges the gap between training programs and actual user behavior, making security awareness measurable and actionable.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10536475B1Threat assessment based on coordinated monitoring of local communication clients
Publication Date: 2020.01.14 PHISHCLOUD INC
  • US10536475B1 patent drawing
  • US10536475B1 patent drawing
  • US10536475B1 patent drawing

AI summary

Embodiments are directed to managing communication over a network. A co-located assessment agent may monitor communication traffic and determine assets and interactions with communication clients associated with one or more remote services. Asset groups associated with the assets may be determined based on characteristics of the assets. Representative assets from each asset group may be determined. Risk scores associated with each asset in a same asset group as the representative assets may be determined based on the remote services associated with the representative assets and the interactions with the communication clients such that a first risk score is initially generated based on a catalog local to a communication client and a succeeding risk score may be generated remotely based on an assessment model. The assets may be modified based on the first risk score or the succeeding risk score and provided to communication clients for display to a user.