Employee Security Risk Scoring via Composite Vector

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a comprehensive method to assess and manage internal security risks posed by employees within businesses, as existing pre-hiring assessments are intrusive, time-consuming, and costly, and do not effectively track or identify security threats from employees once they are hired.

Innovation Solution

A system for quantifying employee security risk using a dynamic scoring method that aggregates security risk facts into an extensible composite vector, allowing for real-time updates and flexible risk categorization across various business hierarchies, enabling identification and tracking of employees who pose security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-hiring security assessments (background checks, credit checks) are conducted, then security risk identification is improved, but time consumption and cost increase significantly

Engineering Contradiction:
Improvesecurity risk identificationVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security risk assessments by continuously collecting and analyzing employee behavior data, device usage patterns, and access logs during normal operations. This preliminary monitoring enables early identification of security risks without requiring time-consuming formal assessments, thus resolving the contradiction between reliable risk identification and time consumption

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables employees to self-report security incidents and anomalies through automated monitoring tools that track their own behavior patterns. This self-service approach reduces the need for external security assessments while maintaining continuous risk identification, thereby reducing time loss while preserving security reliability

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive employee security monitoring is implemented, then security risk detection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity risk detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into modular components: data collection modules that gather specific types of employee behavior data, analysis modules that process different data types independently, and scoring modules that evaluate specific risk dimensions. This segmentation improves detection reliability through comprehensive monitoring while managing system complexity through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs universal data collection mechanisms that gather multiple types of security-relevant information (access patterns, device usage, communication behavior) through a single integrated platform. This multi-functionality approach improves comprehensive risk detection while reducing overall system complexity by consolidating multiple monitoring functions into one system

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If dynamic real-time security risk scoring is implemented, then risk tracking capability is improved, but computational resources increase

Engineering Contradiction:
Improverisk tracking capabilityVSAvoidcomputational resources
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic security risk scoring at strategically determined intervals based on employee role, access level, and observed behavior patterns. Rather than continuous real-time scoring, the system updates risk scores periodically when significant behavior changes occur or at scheduled intervals, thereby improving risk tracking capability while reducing unnecessary computational resource consumption

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system dynamically adjusts scoring parameters and thresholds based on organizational context, employee position, and emerging threat patterns. By changing parameters adaptively rather than performing full computational recalculations, the system improves risk tracking accuracy while minimizing computational resource usage through parameter optimization rather than brute-force computation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10282702B2Dynamic employee security risk scoring
Publication Date: 2019.05.07 BANK OF AMERICA CORP
  • US10282702B2 patent drawing
  • US10282702B2 patent drawing
  • US10282702B2 patent drawing

AI summary

Embodiments of the invention relate to systems, methods, and computer program products that provide for an employee security risk score. The security risk score is presented as an extensible composite vector that supports an arbitrary number of risk categories. The risk categories can be aggregated at any level in the business hierarchy or according to any employee parameter. The simplistic, highly normalized approach to employee security risk scoring reduces redundancies and dependencies and provides for real-time updates, As such, the employee security risk scoring system provides for easily identifiable recognition of employees who pose security threats and for a means to track and monitor security risks posed by the employee based on their security risk score.