Multivariate Risk Scoring via Auto-Encoder Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current contextual access systems rely on univariate anomaly detection models, which fail to capture multivariate anomalies, overlook historical data correlations, and use subjective heuristics, leading to inaccurate risk assessments and potential security breaches or user experience deterioration.
Innovation Solution
Implementing a multivariate model-based scoring schema using under-complete auto-encoder networks (AEs) that form a hierarchical structure to analyze multiple input features across various time horizons, combining marginal risks into overall risk scores based on historical data without manual input, enabling more accurate and holistic risk evaluation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If univariate anomaly detection models are used in contextual access systems, then the system complexity is reduced and ease of operation is improved, but measurement precision of risk assessment deteriorates and false positives/negatives increase
Solution Approach 1:
The patent transitions from univariate anomaly detection to multivariate anomaly detection by incorporating multiple features (user, device, network, location, time) simultaneously. This dimensional expansion allows the system to capture complex attack patterns that span multiple variables, thereby improving measurement precision of risk assessment while maintaining system operability through automated multivariate analysis.
Solution Approach 2:
The patent combines multiple univariate risk scores into a composite multivariate risk score. By integrating assessments from different dimensions (user behavior, device characteristics, network conditions, location data, time patterns) into a unified risk evaluation, the system achieves higher measurement precision without proportionally increasing operational complexity.
2Ease of manufacture
If subjective heuristics are used for risk assessment, then device complexity is reduced and ease of manufacture is improved, but reliability of risk assessment deteriorates
Solution Approach 1:
The patent replaces subjective human heuristics with automated machine learning models and algorithms. The system uses computational methods to objectively analyze multivariate data and generate risk scores, eliminating the need for manual rule configuration and subjective judgment. This substitution improves reliability by providing consistent, data-driven assessments while keeping the system relatively simple to deploy through automated training and evaluation.
3Productivity
If historical data correlations are overlooked, then loss of time in data processing is reduced and productivity is improved, but measurement precision of risk assessment deteriorates
Solution Approach 1:
The patent performs preliminary actions by pre-processing and storing historical data in structured formats suitable for multivariate analysis. The system prepares feature sets, establishes baseline behaviors, and pre-computes risk models in advance, enabling rapid real-time assessment without reprocessing raw historical data during actual access requests. This approach maintains high productivity while improving measurement precision through informed historical context.
4Measurement precision
If multivariate model-based scoring schema is implemented, then measurement precision of risk assessment is improved, but device complexity increases
Solution Approach 1:
The patent segments the multivariate risk assessment into distinct modular components: feature extraction modules for different data sources (user, device, network, location, time), individual risk score computation modules for each feature, and a composite scoring module that integrates them. This segmentation allows the complex multivariate model to be implemented as separate, manageable units that can be independently configured, trained, and maintained, thereby reducing the practical complexity burden despite the advanced measurement precision achieved.
Data Source
AI summary
Described embodiments provide systems, methods, computer readable media for determining risk metrics. A device may provide a risk model for a network environment. The risk model may include an input level and an output level. The input level may process first datasets each corresponding to a feature and a time window. The first datasets may include factors on access requests. The output level may generate a first aggregate risk metric of a first access request according to the datasets processed by the input level. The device may identify a second dataset corresponding to a second access request over the features and time windows. The device may determine a second aggregate risk metric by applying the second dataset to the risk model. The device may generate a response to the second access request according to an access control policy and the second aggregate risk metric.


