Contagion Risk Detection via Dynamic User Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems face challenges in effectively identifying and controlling anomalous, abnormal, or malicious user behavior due to difficulties in assessing the risks associated with user interactions and their influences on others, leading to inefficient resource utilization and inadequate protection.

Innovation Solution

A method and system for automatically detecting and analyzing contagion-based risk events in real-time by processing electronic data and communications to identify contagion networks, assigning risk scores, and using auto-prevention and policy enforcement tools for dynamic data protection and access limitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If indiscriminate security policy is applied to all user behavior, then security coverage is improved, but resource utilization efficiency deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements risk-based security policies that are locally adapted to each user's specific risk profile, behavior patterns, and contextual factors. Instead of uniform security measures, the system dynamically adjusts security oversight and response levels for different users and situations, allocating resources proportionally to actual risk levels rather than applying blanket policies across all users.

Inventive Principle:
Principle #3Local quality

2Difficulty of detecting and measuring

If comprehensive monitoring of user behavior is implemented, then detection capability is improved, but system complexity deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent introduces intermediary components including behavior analytics engines, risk scoring systems, and contextual data processors that mediate between raw user behavior data and security decisions. These intermediaries aggregate, analyze, and transform complex behavioral data into actionable risk assessments, simplifying the overall system architecture while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time risk assessment is performed for all users, then security response effectiveness is improved, but processing time deteriorates

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary risk assessments by continuously analyzing user behavior patterns, establishing baseline profiles, and pre-computing risk scores during normal operations. When security events occur, the system leverages these pre-computed assessments to enable rapid response without requiring time-consuming real-time analysis from scratch, thus maintaining both effectiveness and efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11171980B2Contagion risk detection, analysis and protection
Publication Date: 2021.11.09 FORCEPOINT LLC
  • US11171980B2 patent drawing
  • US11171980B2 patent drawing
  • US11171980B2 patent drawing

AI summary

A method, system, and computer-usable medium for protecting against contagion-based risk events are disclosed for monitoring behavior of users to construct a contagion network relationship map of connection and influence relationships between different users and then analyzing a received stream of events from the users to identify a critical event performed by a first user having a first risk score so that one or more propagated risk scores can be generated from the first risk score for at least a first connected user based on connection and influence relationships between the first user and the first connected user that are extracted from the contagion network relationship so that an adaptive response may be automatically generated to protect and control against actions by at least the first connected user based on the one or more propagated risk scores.