Insider Threat Scoring via HR Data Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internal users pose a significant threat to IT systems, causing a majority of data breaches and security attacks, often unintentionally or maliciously, due to complex security systems and delayed breach detection.

Innovation Solution

A threat scoring system that integrates multiple data sources, including human resources, directory services, asset management, endpoint security, and firewall systems, using machine learning to analyze user behavior and generate a comprehensive threat score, enabling proactive mitigation measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security measures (passwords, encryption, information containment) are implemented to protect IT systems, then security protection capability is improved, but system complexity increases and may overwhelm the organization

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (user behavior analytics, threat scoring, automated response) into a single integrated platform that consolidates data from HR systems, directory services, asset management, endpoint security, and firewall systems. This merging approach maintains comprehensive security protection while reducing operational complexity by providing a unified interface and centralized management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements automated threat response capabilities that can self-manage security incidents without human intervention. The automated response engine can automatically isolate compromised devices, block malicious traffic, and alert appropriate personnel, reducing the burden on organizational staff while maintaining robust security protection.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive security monitoring is implemented to detect breaches, then breach detection capability is improved, but detection time increases due to system complexity

Engineering Contradiction:
Improvebreach detection capabilityVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by continuously monitoring user behavior and establishing baseline patterns before breaches occur. By pre-calculating threat scores based on behavioral deviations and maintaining ready-to-execute response playbooks, the system can detect and respond to breaches immediately when they occur, rather than requiring time-consuming analysis after detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security monitoring and analysis with machine learning algorithms and automated analytics engines. These computational systems process security data in real-time, identifying breach patterns and anomalies much faster than human analysts could, thereby improving detection precision while reducing detection time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If detailed user behavior analytics are collected to assess insider threats, then threat assessment accuracy is improved, but data processing complexity and resource requirements increase

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments threat assessment into distinct components: behavioral baseline establishment, deviation detection, threat scoring, and response recommendation. Each component processes specific types of data independently, allowing the system to maintain high assessment accuracy while managing processing complexity through modular architecture and specialized analytics engines for different data types.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11411980B2Insider threat management
Publication Date: 2022.08.09 DEFENDEDGE AI CYBER TECH LLC
  • US11411980B2 patent drawing
  • US11411980B2 patent drawing
  • US11411980B2 patent drawing

AI summary

A method is provided. The method includes receiving information about user data and user behavior relating to a user, where the information is derived at least in part from a human resources database. The method includes applying analytics to the received information. The method includes, as a result of applying analytics to the received information, generating a threat score for the user.