Human-Centric Risk Modeling Framework for Insider Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current human-centric risk modeling frameworks, such as the Critical Pathway Model and Sociotechnical and Organizational Factors for Insider Threat, face limitations in accurately assessing security risks due to retrospective approaches, qualitative scoring, and inadequate addressing of various insider threats and workplace behaviors, leading to potential security vulnerabilities.

Innovation Solution

A human-centric, behavior-based security risk modeling framework that monitors electronically-observable data sources, derives observables, identifies security-related activities, analyzes them using a human-centric risk modeling framework, and performs security operations to mitigate risks, incorporating factors like motivation, stressors, and organizational dynamics to quantify behavioral risks more accurately.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If retrospective approaches and qualitative scoring are used in risk modeling, then implementation simplicity is maintained, but measurement precision and reliability of security risk assessment deteriorate

Engineering Contradiction:
Improvesecurity risk assessment accuracyVSAvoidrisk modeling framework complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces qualitative, manual risk assessment methods with quantitative, automated behavioral biometric analysis. The system substitutes human judgment and retrospective scoring with real-time computational analysis of user behavior patterns, replacing the 'mechanical' process of qualitative assessment with an automated digital system that measures and evaluates behavioral data objectively.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The framework transforms security risk assessment from static, retrospective qualitative scores to dynamic, real-time quantitative measurements. By changing the parameters from subjective categorical ratings to objective behavioral metrics (keystroke dynamics, mouse movements, navigation patterns), the system achieves higher measurement precision while maintaining implementability through automated data collection and analysis.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive behavioral monitoring is implemented, then measurement precision of security risks improves, but loss of time for data collection and processing increases

Engineering Contradiction:
Improvebehavioral risk detection accuracyVSAvoiddata collection and processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements continuous, passive collection of behavioral biometric data during normal user operations. Instead of discrete, time-consuming assessment events, the framework continuously monitors keystroke patterns, mouse movements, and navigation behaviors as users naturally interact with systems, eliminating interruptions and reducing the time loss associated with periodic manual assessments.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The framework performs preliminary establishment of baseline behavioral patterns during normal operations before security incidents occur. By pre-collecting and analyzing behavioral data to establish user-specific baselines, the system prepares risk assessment models in advance, so that when security evaluation is needed, the heavy computational lifting has already been done, reducing real-time processing time.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If traditional risk modeling frameworks are used, then ease of operation is maintained, but adaptability to various insider threats and workplace behaviors deteriorates

Engineering Contradiction:
Improvecoverage of insider threats and workplace behaviorsVSAvoidoperational simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal behavioral biometric framework that can assess multiple types of security risks through a single system. The same core technology evaluates insider threats, workplace behavior anomalies, credential misuse, and data exfiltration risks, replacing multiple specialized assessment tools with one multi-functional platform that adapts to different threat scenarios through configurable parameters rather than requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The risk modeling framework transitions from static, pre-defined risk categories to dynamic, behavior-driven assessment. The system continuously adapts to new threat patterns and workplace behaviors by learning from ongoing behavioral data, allowing it to respond to emerging insider threats and unusual workplace conduct without requiring manual reconfiguration or updates to the underlying model structure.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11570197B2Human-centric risk modeling framework
Publication Date: 2023.01.31 FORCEPOINT LLC
  • US11570197B2 patent drawing
  • US11570197B2 patent drawing
  • US11570197B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing a security risk modeling operation. The security risk modeling operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; deriving an observable based upon the monitoring of the electronically-observable data source; identifying a security related activity, the security related activity being based upon the observable from the electronic data source; analyzing the security related activity, the analyzing the security related activity using a human-centric risk modeling framework; and, performing a security operation in response to the analyzing the security related activity.