Co-located Assessment Agents for Communication Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in managing risks associated with electronic communications, particularly when using external communication systems, as they struggle to enforce security standards due to the involvement of external service providers, making it difficult to identify and mitigate risky resources within communication systems that are often inaccessible for security management.
Innovation Solution
Implementing a system with co-located assessment agents that monitor communication traffic, determine assets and interactions, assign risk scores, and modify assets based on these scores to display risk information to users, while also providing just-in-time training to enhance user awareness and security practices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations block access to external communication services completely, then security risk is reduced, but communication functionality and productivity are lost
Solution Approach 1:
The patent introduces an intermediary assessment system that sits between the organization and external communication services. This system includes components that intercept, assess, and mediate communications without blocking access entirely. The intermediary provides real-time risk assessment of external communications while allowing legitimate business communications to proceed, thus resolving the contradiction between security and productivity.
Solution Approach 2:
The patent implements feedback mechanisms where communication risk is continuously assessed and information is fed back to users and security systems. This includes real-time risk scoring of communications, user notifications about risky messages, and dynamic adjustment of security policies based on assessed threats. The feedback loop enables security protection without complete blocking, maintaining productivity while mitigating risks.
2Ease of operation
If organizations use external communication services, then communication effectiveness improves, but security control and monitoring become difficult
Solution Approach 1:
The patent enables self-service capabilities where the communication system itself performs security assessments. The assessment system automatically evaluates communications, identifies risks, and applies appropriate security measures without requiring manual intervention. This includes automated risk scoring, dynamic policy application, and self-monitoring of communication patterns, reducing security management complexity while maintaining effectiveness.
Solution Approach 2:
The patent creates a universal assessment framework that handles multiple types of communications (email, chat, collaboration tools) through a single integrated system. This multi-functional approach consolidates security management across diverse communication platforms, simplifying what would otherwise be complex multi-system management while maintaining comprehensive security control.
3Reliability
If organizations implement training programs, then user security awareness improves, but continuous monitoring of actual user behavior remains difficult
Solution Approach 1:
The patent implements continuous feedback loops that monitor actual user communication behavior and compare it against security best practices. The system provides real-time feedback to users about risky behaviors, tracks compliance with security policies, and adjusts training requirements based on observed behavior patterns. This continuous monitoring and feedback mechanism bridges the gap between training programs and actual user behavior, making security awareness measurable and actionable.
Data Source
AI summary
Embodiments are directed to managing communication over a network. A co-located assessment agent may monitor communication traffic and determine assets and interactions with communication clients associated with one or more remote services. Asset groups associated with the assets may be determined based on characteristics of the assets. Representative assets from each asset group may be determined. Risk scores associated with each asset in a same asset group as the representative assets may be determined based on the remote services associated with the representative assets and the interactions with the communication clients such that a first risk score is initially generated based on a catalog local to a communication client and a succeeding risk score may be generated remotely based on an assessment model. The assets may be modified based on the first risk score or the succeeding risk score and provided to communication clients for display to a user.


