Distribution-Based Aggregate Score for Security Risk Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for aggregating user access event scores, such as those from the RSA SecurId Access identity assurance system, lack effectiveness in combining individual risk scores into a comprehensive aggregate score that accurately reflects the expected distribution of these scores, leading to inadequate security policy configuration and risk visibility.
Innovation Solution
A method that calculates an aggregate score by partitioning the range of possible values into non-overlapping buckets, assigning expected percentile distributions and weights to each bucket, and computing the score based on deviations from an expected distribution, such as a Bell Curve, allowing for dynamic computation and visualization across different vectors of an organization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional aggregation methods (e.g., simple averaging) are used to combine individual risk scores, then the aggregation process is simple and fast, but the aggregate score fails to accurately reflect the distribution of risk scores and provides inadequate security visibility
Solution Approach 1:
The patent segments the range of individual risk scores into multiple non-overlapping buckets, each representing a specific score range. This segmentation allows the system to analyze the distribution of scores across different ranges rather than treating all scores uniformly, thereby improving the accuracy of the aggregate score in reflecting the underlying risk distribution while maintaining a manageable level of complexity through structured binning.
Solution Approach 2:
The patent transforms the aggregation approach by changing the parameter from simple arithmetic averaging to a distribution-based calculation that considers the expected percentile distribution across score buckets. This parameter change enables the aggregate score to accurately reflect whether the distribution of individual scores matches expected patterns, significantly improving measurement precision without requiring overly complex computational mechanisms.
2Reliability
If distribution-based aggregation with multiple buckets and weights is implemented, then the aggregate score accurately reflects risk distribution, but the computation and configuration become more complex
Solution Approach 1:
The patent divides the continuous range of risk scores into discrete non-overlapping buckets, each with assigned weights and expected percentile distributions. This segmentation approach enhances reliability by enabling the system to detect distributional anomalies and provide more nuanced security assessments, while the structured bucket framework keeps the overall system complexity manageable through organized data handling.
Solution Approach 2:
The patent incorporates feedback mechanisms by comparing the observed distribution of individual scores against expected percentile distributions for each bucket. This feedback loop allows the system to dynamically assess whether the aggregate risk score aligns with expected patterns, improving reliability through continuous validation while using the feedback to simplify decision-making around security policy adjustments.
3Loss of information
If individual risk scores are aggregated without considering their distribution, then the aggregation process is straightforward, but security administrators lack visibility into risk patterns and cannot effectively configure security policies
Solution Approach 1:
The patent segments individual risk scores into distributional categories (buckets) that preserve information about score patterns and relationships. This segmentation prevents loss of information by maintaining visibility into how scores are distributed across different ranges, enabling security administrators to identify patterns and configure policies based on distributional characteristics rather than aggregated averages alone.
Solution Approach 2:
The patent adds a distributional dimension to the aggregation process by analyzing scores across multiple buckets with different expected percentile distributions. This dimensional expansion transforms the aggregation from a single-value calculation to a multi-dimensional analysis that preserves rich information about risk patterns, significantly reducing information loss while keeping the methodology accessible through structured bucket-based analysis.
Data Source
AI summary
Techniques are provided for distribution-based aggregation of scores across multiple events. One method comprises obtaining a plurality of individual scores associated with a plurality of events; obtaining an expected distribution for the plurality of individual scores; and generating an aggregate score for the plurality of individual scores based on a deviation of the plurality of individual scores from the obtained expected distribution for the plurality of individual scores. The aggregate score, for example, reflects how closely the individual scores follow the expected distribution. The aggregate score comprises, for example, an aggregate risk score that: (i) is compared across different vectors of an organization; (ii) is used to create a security policy and/or modify a security policy; and/or (iii) triggers an alert based on one or more predefined threshold criteria. The multiple aggregate risk scores can be visualized in one or more geographic regions and/or sub-networks of an organization.


