Crowdsourced Security System with Dynamic Risk Profile Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems that rely on user and sign-in risk profiles face challenges in timely updating and managing risk profiles, especially in distributed systems managing large volumes of user accounts, which can lead to delayed or ineffective tracking and correlation of bad user accounts, allowing potential security breaches.

Innovation Solution

The implementation of crowdsourced feedback loops and machine learning algorithms to dynamically validate and modify user and sign-in risk profiles through user interfaces, generating label data for refining risk assessments and enabling proactive remediation measures such as credential resets or demotion of access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If distributed systems manage high volumes of user accounts with traditional risk profile updating methods, then system coverage and user base expand, but the timeliness and effectiveness of risk profile updates deteriorate

Engineering Contradiction:
Improvenumber of user accountsVSAvoidtime delay in risk profile updates
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively identifying and flagging accounts that exhibit suspicious behavior patterns before they can execute malicious attacks. Risk profiles are updated in advance based on detected anomalies, enabling preventive security measures rather than reactive responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where security events, user behaviors, and threat intelligence are constantly monitored and fed back into the risk assessment engine. This real-time feedback mechanism enables dynamic updating of risk profiles across all user accounts, ensuring timely responses to emerging threats regardless of system size.

Inventive Principle:
Principle #23Feedback

2Reliability

If traditional security systems update risk profiles after detecting bad behavior, then security policies are enforced, but the ability to prevent first-time attacks by new bad actors deteriorates

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidresponse time before first attack
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security assessments and establishes baseline risk profiles for all users before they can execute malicious actions. By pre-configuring security policies and monitoring mechanisms, the system is prepared to immediately respond to and prevent first-time attacks from new bad actors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-actions by proactively blocking suspicious accounts and preventing potential attacks before they occur. Security controls are pre-positioned to counteract threatened actions, enabling the system to stop bad actors at the outset rather than responding after damage occurs.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If login credentials are used for user authentication, then access control is implemented, but vulnerability to credential spoofing and circumvention increases

Engineering Contradiction:
Improveuser authenticationVSAvoidcredential spoofing attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements multi-factor feedback verification that goes beyond simple credential checking. Additional verification signals such as device fingerprints, location data, behavior patterns, and biometric information provide layered feedback to confirm genuine user identity, making credential spoofing ineffective.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication system uses composite verification methods combining multiple independent factors (credentials, device information, behavioral biometrics, location data) rather than relying on a single authentication mechanism. This composite approach creates robust security that resists circumvention while maintaining ease of use for legitimate users.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS11017088B2Crowdsourced, self-learning security system through smart feedback loops
Publication Date: 2021.05.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11017088B2 patent drawing
  • US11017088B2 patent drawing
  • US11017088B2 patent drawing

AI summary

Systems are provided for utilizing crowdsourcing and machine learning to improve computer system security processes associated with user risk profiles and sign-in profiles. Risk profiles of known users and logged sign-ins are confirmed by user input as either safe or compromised. This input is used as crowdsourced feedback to generate label data for training/refining machine learning algorithms used to generate corresponding risky profile reports. The risky profile reports are used to provide updated assessments and initial assessments of known users and logged sign-ins, as well as newly discovered users and new sign-in attempts, respectively. These assessments are further confirmed or modified to further update the machine learning and risky profile reports.