Dynamic User Grouping for Enterprise Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems struggle to accurately identify users who pose heightened security risks within enterprise groups, as traditional methods compare risk scores across all users rather than within dynamic groupings based on role and network activity.

Innovation Solution

The system dynamically groups users based on factors like role, network behavior, and risk scores, allowing for the generation of normalized risk scores within each group. Users with significantly higher risk scores are identified and added to a watch list for closer monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional risk score comparison methods are used across all users, then the security assessment covers the entire user base, but the accuracy of identifying heightened security risks deteriorates due to lack of contextual normalization

Engineering Contradiction:
Improveaccuracy of security risk identificationVSAvoidcomplexity of risk assessment system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the user base into distinct groups based on roles, departments, and network behavior patterns. By dividing users into contextual groups rather than assessing all users uniformly, the system achieves more accurate risk identification within each segment while maintaining manageable complexity through automated grouping algorithms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing context-specific risk thresholds and normalization factors for different user groups. Each group receives tailored risk assessment criteria appropriate to their role and behavior patterns, improving measurement precision without requiring complete system redesign.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If dynamic grouping of users is implemented based on role and network activity, then the accuracy of risk score comparison improves within groups, but the complexity of the system increases due to multiple grouping dimensions

Engineering Contradiction:
Improveaccuracy of risk score comparisonVSAvoidcomplexity of grouping mechanism
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments users into multiple overlapping groups based on different dimensions (role, department, behavior). This segmentation enables precise contextual comparison while the modular group structure keeps complexity manageable through systematic organization of grouping criteria.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The grouping mechanism serves multiple functions simultaneously: it segments users for accurate comparison, normalizes risk scores across different contexts, and identifies outliers efficiently. This multi-functionality reduces the need for separate systems for each purpose.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 3:

The system dynamically adjusts grouping parameters and risk thresholds based on user attributes and behavior patterns. By changing parameters adaptively rather than using fixed criteria, the system achieves high precision while managing complexity through automated parameter adjustment.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If all users are monitored uniformly for security risks, then comprehensive security coverage is achieved, but the efficiency of identifying actual threats deteriorates due to noise from benign activities

Engineering Contradiction:
Improveefficiency of threat identificationVSAvoidcomprehensive security coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments monitoring efforts by creating user groups with similar risk profiles and behaviors. This allows security resources to be focused on high-risk groups while maintaining coverage of all users, improving efficiency without sacrificing comprehensive security monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial monitoring intensity to different user groups based on their risk profiles. High-risk groups receive intensified monitoring while low-risk groups receive standard monitoring, optimizing resource allocation while maintaining adequate coverage across all users.

Inventive Principle:
Principle #16Partial or excessive action

4Measurement precision

If risk scores are normalized within dynamic groups, then the detection of outliers and heightened risks improves, but the time required for continuous assessment increases

Engineering Contradiction:
Improvedetection accuracy of heightened risksVSAvoidtime for continuous risk assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing user groups and baseline risk profiles before actual threat detection is needed. This preliminary organization enables faster real-time assessment by comparing user behavior against pre-computed group norms rather than building groups from scratch during assessment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where risk assessments update group profiles dynamically. This continuous feedback loop refines normalization baselines over time, improving detection accuracy while reducing the computational burden of reassessment by leveraging learned patterns from previous assessments.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12273350B2Dynamic grouping of users in an enterprise and watch list generation based on user risk scoring
Publication Date: 2025.04.08 TARGET BRANDS INC
  • US12273350B2 patent drawing
  • US12273350B2 patent drawing
  • US12273350B2 patent drawing

AI summary

Disclosed are techniques for identifying users within an enterprise who pose heightened security risks to the enterprise. A method can include receiving, by a computing system, information about users in the enterprise, grouping the users into groups based on at least one grouping feature and the user information, the at least one grouping feature including, for each of the users, behavior, activity, role, department, region, role-based risk score, event-based risk score, and/or composite risk score, identifying, for each group, normalized behavior of users in the group, generating, for each user in each group, a composite risk score based on deviation of the user's activity from the normalized behavior of the group, identifying, for each group, a subset of users in the group to be added to a watch list, and adding the subset of users to the watch list.