Human Risk Visibility Platform for Insider Threat Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security measures for computers and networking systems focus on technological objects, leaving them vulnerable to human-related risks such as insider threats, identity theft, and ransomware due to a lack of visibility and context for human actions and behaviors.
Innovation Solution
Implementing a system that integrates existing security tools and data sources to generate a human risk score based on individual actions, access, attack frequency, and security controls, allowing for targeted security measures and adaptive policy orchestration to mitigate insider threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security products focus on technological objects such as antivirus software, then virus scanning and quarantine capabilities are improved, but visibility into human risk and insider threats remains insufficient
Solution Approach 1:
The patent combines multiple security data sources including endpoint detection data, network security data, cloud security data, and human behavior data into a unified security visibility platform. This integration allows the system to maintain traditional technological security protections while simultaneously gaining comprehensive visibility into human risk factors by merging previously siloed data sources.
Solution Approach 2:
The patent introduces a security visibility platform as an intermediary layer that sits between traditional security tools and security analysts. This platform aggregates, normalizes, and contextualizes data from multiple security sources, providing enhanced visibility into human risk without replacing existing security products. The intermediary platform translates raw security data into actionable human risk insights.
2Reliability
If security measures are implemented without human risk context, then technological security controls are strengthened, but friction and user experience deteriorate
Solution Approach 1:
The patent applies different security control levels to different users based on their individual human risk scores. Instead of uniform security measures, the system dynamically adjusts security controls locally for each user - implementing stricter controls for high-risk users and more permissive controls for low-risk users. This localized approach maintains security effectiveness while reducing friction for trustworthy users.
Solution Approach 2:
The patent implements dynamic security controls that automatically adjust based on real-time human risk assessment. Security measures are not static but dynamically adapt to each user's behavior patterns, risk score, and contextual factors. This dynamic approach allows security controls to strengthen when needed while easing restrictions when users demonstrate trustworthy behavior, thereby improving user experience without compromising security.
3Loss of information
If comprehensive security monitoring is implemented, then visibility into security events is improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent creates a universal security visibility platform that can ingest and process multiple types of security data from diverse sources including endpoints, networks, cloud environments, and human behavior tracking. This multi-functional platform consolidates what would otherwise require multiple separate tools, reducing overall system complexity while maintaining comprehensive security event visibility across the entire infrastructure.
Solution Approach 2:
The patent extracts and isolates the security visibility and analytics function into a separate platform, removing the complexity of data aggregation and analysis from individual security tools. By extracting the complex data processing tasks into a dedicated security visibility platform, existing security tools can remain simpler while the centralized platform handles the complexity of comprehensive monitoring and analysis.
Data Source
AI summary
Security event data from each of a plurality of security data sources is received, each unit of the security event data being associated with a security event involving one or more human users included in a monitored set of human users. The security event data is used to generate for each of at least a subset of the monitored set of human users a user-specific security risk score that is determined based at least in part on: a level of access to protected resources that a user has; an attack type that has been attempted with respect to the user; and an action taken by the user, as reflected in the security event data associated with the user from two or more of said security data sources.


