Normalized Risk Score for Network Entity Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security management systems face challenges in accurately monitoring and managing access to network resources due to the heterogeneity of client devices and varying access patterns, leading to difficulties in detecting and quantifying risky behaviors within organizations.
Innovation Solution
The system generates a normalized risk score for network entities by combining risk values, amplification, and dampening factors, adjusting for frequency and timeline, and initiating actions based on pre-defined thresholds to protect the organization from potential risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security monitoring systems are used to track network entities, then basic security monitoring is achieved, but the systems cannot accurately detect and quantify risky behaviors due to heterogeneity of client devices and varying access patterns
Solution Approach 1:
The system transforms raw security events into normalized risk scores by applying parameter transformations. Each risk indicator is converted from its original scale to a standardized risk score through mathematical transformations, allowing accurate comparison and aggregation across different device types and access patterns while maintaining detection precision.
Solution Approach 2:
The patent introduces normalized risk scores as an intermediary metric between raw security events and security decisions. This intermediary transformation layer handles the heterogeneity of different client devices and access patterns by converting diverse security events into a common risk score scale, enabling accurate risk detection without being constrained by device or access pattern differences.
2Reliability
If risk scores are calculated without normalization to capture all risky activities, then comprehensive risk coverage is achieved, but the scores become arbitrary large values that are difficult to interpret and act upon
Solution Approach 1:
The system applies parameter transformation by normalizing aggregated risk scores into a standardized scale (e.g., 0-100 or 0-1 range). This transformation preserves the comprehensive risk coverage achieved through aggregation while converting arbitrary large values into interpretable scores that facilitate easy decision-making and threshold-based actions.
Solution Approach 2:
The patent transforms the risk score from a high-dimensional aggregated value (sum of multiple risk indicators) into a standardized one-dimensional score. This dimensional transformation maintains all the risk information while presenting it in an easily interpretable format that enables straightforward security operations and threshold comparisons.
3Speed
If frequent monitoring of network entities is implemented to detect risky activities quickly, then real-time security detection is achieved, but the computational resources and system complexity increase significantly
Solution Approach 1:
The system uses parameter transformation to convert complex multi-indicator risk assessments into simple normalized scores. This allows frequent monitoring at standardized intervals rather than continuous monitoring, as the normalized score calculation is computationally efficient compared to analyzing all raw security events in real-time, thus reducing system complexity while maintaining detection speed.
Data Source
AI summary
Embodiments described include a computing device for generating risk scores of network entities. The computing device can include one or more processors configured to detect a plurality of risk indicators. Each of the risk indicators identify one of a plurality of activities of a network entity of an organization. The network entity includes a device, an application or a user in the organization's network. The one or more processors can generate a risk score of the network entity, by combining a risk value, an amplification factor and a dampening factor of each of the plurality of risk indicators, and adding an adjustment value for the plurality of risk indicators. The one or more processors can determine, using the generated risk score, a normalized risk score of the network entity. The one or more processors can initiate an action according to the normalized risk score.


