Employee Reconnaissance Risk Score Calculation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in identifying which employees are most vulnerable to Advanced Persistent Threat (APT) attacks, as attackers use reconnaissance to gather information from public sources, leading to increased phishing and targeted malicious email attempts against employees with exposed names and roles online.
Innovation Solution
A method implemented by dedicated software that assigns a reconnaissance risk score to employees by simulating an attacker's search on the internet, using a contextual lexicon to determine the effort required to link an employee's role with their real identity, based on search engine results and reverse-indexing URLs containing relevant terms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If employees' names and roles are exposed in public web sources, then employees can participate in professional networks and conferences, but employees become more vulnerable to phishing and targeted malicious email attacks
Solution Approach 1:
The system performs preliminary reconnaissance risk assessment by searching public web sources for employee information before attacks occur. It proactively identifies employees with exposed names and roles in professional networks, conferences, and social media, calculating risk scores in advance to enable preemptive security measures.
Solution Approach 2:
The system introduces an intermediary security assessment layer between employee public exposure and attack vulnerability. By using search engines and web crawlers as intermediaries to collect and analyze public information, the system mediates the relationship between employee visibility and security risk, providing an indication score that bridges exposure level and attack probability.
2Reliability
If organizations monitor all employees for security risks, then security coverage is comprehensive, but resource consumption and system complexity increase
Solution Approach 1:
The system applies local quality by differentiating security monitoring intensity based on individual employee risk profiles. Instead of uniform monitoring, it calculates specific reconnaissance risk scores for each employee based on their public exposure level, concentrating monitoring resources on high-risk employees while reducing overhead for low-risk employees.
Solution Approach 2:
The system changes the parameter of security monitoring from binary (monitored/not monitored) to continuous (risk indication score from 0-100). By transforming the monitoring approach into a graded risk assessment system, it enables proportional resource allocation and simplifies system architecture compared to comprehensive uniform monitoring.
3Measurement precision
If the system searches extensively in public sources to accurately identify vulnerable employees, then detection precision improves, but time and computational resources increase
Solution Approach 1:
The system applies partial action by performing targeted searches in the most relevant public sources (professional networks, conference sites, social media) rather than exhaustively scanning all web content. It focuses computational effort on high-probability exposure sources, achieving sufficient detection precision without the time cost of complete web-wide searching.
Solution Approach 2:
The system performs preliminary indexing and caching of public source data, preparing search databases in advance. By pre-collecting and organizing information from professional networks and public sources, it reduces real-time search time while maintaining detection accuracy, as the heavy lifting of data collection occurs before risk assessment is needed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention is a method that is implemented by dedicated software that provides a computer system with instructions for carrying out a series of steps that assign a reconnaissance risk score for each employee in an organization. The risk score assigned by the computer system indicates the level of exposure of an employee on the Web; or in other words, the effort that an attacker will have to invest, when searching the Web, in order to link a role/function in an organization with a real employee. Using the method of the invention, the security officer of the organization can warn highly exposed employees and direct monitoring efforts on these employees.