Network Security Rating System for Proactive Risk Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems for enterprise computer networks primarily focus on incident response rather than prevention, failing to adequately address security risks posed by varying user behaviors and skills, which can lead to information leakage or system breakdowns, especially in large networks.
Innovation Solution
A system that collects user data to calculate security ratings based on personal and professional information, risk factors, and communication patterns, adjusting security settings dynamically to reduce security risks across the network by deploying an administration server that monitors and configures user computers to prevent incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current security tools analyze past security incidents to configure users PCs according to security policies, then security configuration can be automated, but security incidents cannot be prevented as they occur
Solution Approach 1:
The system performs preliminary actions by collecting user profile information, calculating risk factors, and determining security ratings before security incidents occur. This proactive approach allows the system to configure security settings in advance based on predicted risk levels, preventing incidents rather than responding to them after they happen.
Solution Approach 2:
The system implements continuous feedback by monitoring user behavior, recalculating risk factors and security ratings in real-time, and dynamically adjusting security configurations. This closed-loop feedback mechanism enables the system to adapt to changing user behaviors and prevent security incidents as they develop.
2Device complexity
If uniform security policies are applied to all users in the network, then security management is simplified, but individual user risk factors and behaviors are not adequately addressed
Solution Approach 1:
The system applies local quality by tailoring security configurations to individual users based on their specific risk factors, professional roles, and behavioral patterns. Each user receives customized security settings appropriate to their risk profile rather than uniform policies, with the administration server automatically managing this differentiation without requiring complex manual configuration.
Solution Approach 2:
The system changes parameters by dynamically adjusting security ratings and configurations based on varying user attributes such as professional role, department, user behavior patterns, and communication activities. These parameter changes enable differentiated security management that adapts to individual user characteristics while maintaining automated administration.
3Measurement precision
If security ratings are adjusted based on user communication patterns and peer ratings, then security risk assessment becomes more accurate, but the system complexity increases
Solution Approach 1:
The system uses feedback from user communication patterns and peer security ratings to continuously refine security risk assessments. By monitoring interactions and incorporating ratings from users with whom a given user communicates, the system achieves more accurate risk measurement through social and behavioral feedback loops.
Solution Approach 2:
The system implements self-service by automatically collecting communication data, calculating peer ratings, and adjusting security configurations without requiring manual intervention. The administration server autonomously processes user interactions and determines appropriate security settings based on observed patterns and peer assessments.
Data Source
AI summary
Disclosed are systems, methods and computer program products for reducing security risk in a computer network. The system includes an administration server that collects system usage, user profile and security incidents information from a plurality of computers in the network. The server determines values of one or more risk factors for each computer using the collected information. The server then calculates security rating of each computer user as a function of the risk factors and adjusts the calculated security rating of a given computer user based on the security ratings of other computer users with whom the given computer users communicates. The server then selects, based on the adjusted security rating, security settings for the computer of the given user in order to reduce user's security risk to the computer network and applies the selected security settings to the computer of the given user.


