Privileged Remote Access Session Risk Scoring and Dynamic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods to protect shared Privileged Remote Access (PRA) sessions based on user risk, potentially introducing security risks to enterprise environments.

Innovation Solution

A system that receives invitations to join PRA sessions, determines the risk score of each user by referencing a user risk database, and either rejects or allows the invitations based on the risk score, while continuously monitoring and updating risk scores during the session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If shared PRA sessions are allowed to improve collaboration and productivity, then user access flexibility increases, but security risk increases

Engineering Contradiction:
Improveuser access flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary risk assessment by determining risk scores for users before allowing them to join PRA sessions. This proactive approach evaluates user risk profiles in advance, preventing high-risk users from accessing privileged resources while allowing legitimate users to collaborate effectively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The PRA system acts as an intermediary between users and privileged resources, implementing continuous risk monitoring and dynamic access control. This mediator evaluates user behavior in real-time and can revoke or restrict access when suspicious activity is detected, balancing collaboration needs with security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous risk monitoring is implemented to improve security, then detection capability increases, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PRA system integrates multiple functions into a unified platform: user authentication, risk score determination, continuous behavior monitoring, dynamic policy enforcement, and session management. This multi-functional approach achieves comprehensive security monitoring without requiring separate complex systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically determines risk scores and enforces access policies based on predefined criteria and continuous monitoring data. This self-service capability reduces the need for manual security management and complex human intervention, simplifying operations while maintaining high detection capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250078002A1Systems and methods to protect shared Privileged Remote Access (PRA) sessions based on user risk
Publication Date: 2025.03.06 ZSCALER INC
  • US20250078002A1 patent drawing
  • US20250078002A1 patent drawing
  • US20250078002A1 patent drawing

AI summary

Systems and methods to protect shared Privileged Remote Access (PRA) sessions based on user risk include receiving, at a Privileged Remote Access (PRA) system, one or more invitations from a host, the one or more invitations being for one or more users to join a PRA session; responsive to receiving the one or more invitations, determining a risk score of each of the one or more users associated with the one or more invitations; and rejecting or allowing each of the one or more invitations based on the risk score of each of the one or more users.