Multivariate Risk Scoring via Auto-Encoder Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current contextual access systems rely on univariate anomaly detection models, which fail to capture multivariate anomalies, overlook historical data correlations, and use subjective heuristics, leading to inaccurate risk assessments and potential security breaches or user experience deterioration.

Innovation Solution

Implementing a multivariate model-based scoring schema using under-complete auto-encoder networks (AEs) that form a hierarchical structure to analyze multiple input features across various time horizons, combining marginal risks into overall risk scores based on historical data without manual input, enabling more accurate and holistic risk evaluation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If univariate anomaly detection models are used in contextual access systems, then the system complexity is reduced and ease of operation is improved, but measurement precision of risk assessment deteriorates and false positives/negatives increase

Engineering Contradiction:
Improveease of operationVSAvoidmeasurement precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent transitions from univariate anomaly detection to multivariate anomaly detection by incorporating multiple features (user, device, network, location, time) simultaneously. This dimensional expansion allows the system to capture complex attack patterns that span multiple variables, thereby improving measurement precision of risk assessment while maintaining system operability through automated multivariate analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent combines multiple univariate risk scores into a composite multivariate risk score. By integrating assessments from different dimensions (user behavior, device characteristics, network conditions, location data, time patterns) into a unified risk evaluation, the system achieves higher measurement precision without proportionally increasing operational complexity.

Inventive Principle:
Principle #40Composite materials

2Ease of manufacture

If subjective heuristics are used for risk assessment, then device complexity is reduced and ease of manufacture is improved, but reliability of risk assessment deteriorates

Engineering Contradiction:
Improveease of manufactureVSAvoidreliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces subjective human heuristics with automated machine learning models and algorithms. The system uses computational methods to objectively analyze multivariate data and generate risk scores, eliminating the need for manual rule configuration and subjective judgment. This substitution improves reliability by providing consistent, data-driven assessments while keeping the system relatively simple to deploy through automated training and evaluation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If historical data correlations are overlooked, then loss of time in data processing is reduced and productivity is improved, but measurement precision of risk assessment deteriorates

Engineering Contradiction:
ImproveproductivityVSAvoidmeasurement precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions by pre-processing and storing historical data in structured formats suitable for multivariate analysis. The system prepares feature sets, establishes baseline behaviors, and pre-computes risk models in advance, enabling rapid real-time assessment without reprocessing raw historical data during actual access requests. This approach maintains high productivity while improving measurement precision through informed historical context.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If multivariate model-based scoring schema is implemented, then measurement precision of risk assessment is improved, but device complexity increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the multivariate risk assessment into distinct modular components: feature extraction modules for different data sources (user, device, network, location, time), individual risk score computation modules for each feature, and a composite scoring module that integrates them. This segmentation allows the complex multivariate model to be implemented as separate, manageable units that can be independently configured, trained, and maintained, thereby reducing the practical complexity burden despite the advanced measurement precision achieved.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11533330B2Determining risk metrics for access requests in network environments using multivariate modeling
Publication Date: 2022.12.20 CITRIX SYSTEMS INC
  • US11533330B2 patent drawing
  • US11533330B2 patent drawing
  • US11533330B2 patent drawing

AI summary

Described embodiments provide systems, methods, computer readable media for determining risk metrics. A device may provide a risk model for a network environment. The risk model may include an input level and an output level. The input level may process first datasets each corresponding to a feature and a time window. The first datasets may include factors on access requests. The output level may generate a first aggregate risk metric of a first access request according to the datasets processed by the input level. The device may identify a second dataset corresponding to a second access request over the features and time windows. The device may determine a second aggregate risk metric by applying the second dataset to the risk model. The device may generate a response to the second access request according to an access control policy and the second aggregate risk metric.