Composite User Risk Scoring via Role and Event Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures struggle to accurately and dynamically assess the risk posed by users within an enterprise environment, as they often rely on static role-based assessments and fail to consider the persistence of historical behavior in risk scoring.
Innovation Solution
The proposed solution involves assigning composite risk scores to users based on a combination of role-based and event-based risk scores. These scores take into account a user's role within the organization, their specific actions, and their historical behavior, with a focus on degrading the impact of older risk events over time to provide a more accurate current risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If static role-based risk assessment is used, then the security assessment is simple and fast, but it fails to capture dynamic user behavior and historical risk patterns
Solution Approach 1:
The risk scoring system is segmented into multiple independent components: role-based risk scores, event-based risk scores, and historical behavior scores. Each component calculates a specific aspect of user risk independently, then these scores are aggregated to form a comprehensive composite risk score. This segmentation allows the system to capture diverse risk dimensions without requiring a single complex assessment model.
Solution Approach 2:
The system transitions from static role-based assessment to dynamic risk scoring by continuously updating event-based scores as new security events occur. The event-based risk score changes in real-time based on user actions, and the composite risk score dynamically adjusts by combining current event scores with historical patterns. This dynamic approach enables the system to adapt to changing user behavior while maintaining computational efficiency.
2Measurement precision
If historical behavior is fully considered in risk scoring, then persistent risk patterns are captured, but recent risky actions may be overshadowed by older events
Solution Approach 1:
The system implements periodic decay of historical risk scores, where the influence of past events gradually diminishes over time. Event-based risk scores are updated continuously as new events occur, and historical scores are systematically reduced through a decay mechanism. This periodic updating ensures that recent risky actions have greater impact on the current composite risk score while still maintaining awareness of persistent risk patterns from history.
3Measurement precision
If comprehensive user data is collected for risk assessment, then a holistic understanding of user behavior is achieved, but data processing overhead increases
Solution Approach 1:
The risk scoring system operates autonomously by automatically collecting user data from multiple sources, calculating role-based and event-based scores, and generating composite risk scores without requiring manual security analyst intervention. The system self-updates as new events occur, continuously refining user risk profiles through automated data processing. This self-service approach maintains comprehensive data collection while reducing the manual processing overhead that would otherwise hinder security analysis productivity.
Data Source
AI summary
Disclosed are techniques for monitoring internal security vulnerabilities in an enterprise based on determining composite risk scores for enterprise users. A method can include receiving information about an enterprise user, such as their role, identifying risks associated with the role, determining, based on the risks, a role-based risk score for the user, receiving, event alerts from a network security detection system, each event alert having been generated by the network security detection system identifying network activity on the enterprise's network that satisfies one or more security event rules indicative of a potential network security issue, determining that one or more of the event alerts are associated with the user in the enterprise to generate user-event pairings, determining, based on the user-event pairings, an event-based risk score for the user, and generating a composite risk score for the user based on aggregating the role-based risk score and the event-based risk score.


