Predictive Risk Score Generation for Enterprise User Compromise

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems face challenges in effectively monitoring and mitigating user risk in enterprise systems, particularly as the number of users and assets grows, as they often focus on detecting malicious activity rather than predicting compromise and assessing its impact.

Innovation Solution

Implementing a predictive inference method that monitors user behavior, generates risk scores, and automates remedial actions to modify asset configurations proactively, thereby reducing the risk of user compromise before it occurs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring is used to detect malicious activity, then security threats can be identified after they occur, but the system cannot proactively predict or prevent compromise before it happens

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidresponse time to compromise
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by monitoring user behavior and generating risk scores before compromise occurs. It proactively identifies users who may be compromised based on behavioral patterns and predicts potential impact, allowing security teams to take preventive measures before actual compromise happens, rather than waiting for traditional detection methods to identify malicious activity after the fact.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If comprehensive user monitoring is implemented across all users and assets, then risk visibility is improved, but system complexity and resource requirements increase significantly

Engineering Contradiction:
Improverisk visibilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system applies local quality by focusing monitoring and risk assessment resources on specific users and assets that exhibit higher risk characteristics. Instead of uniformly monitoring all users and assets with equal intensity, it dynamically adjusts monitoring depth and resource allocation based on individual risk scores and predicted impact, concentrating security resources where they are most needed while reducing overhead for lower-risk entities.

Inventive Principle:
Principle #3Local quality

3Productivity

If reactive security measures are taken after compromise detection, then security incidents can be responded to, but the damage has already occurred and resources are wasted

Engineering Contradiction:
Improvesecurity resource efficiencyVSAvoidimpact of compromise
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements preliminary anti-action by taking security measures before compromise occurs. It generates risk scores based on monitored user behavior and predicted impact, then proactively applies remedial actions such as isolating users, resetting credentials, or alerting security teams before actual compromise happens. This prevents the harmful effects of compromise rather than responding to them after damage has occurred, improving both security outcomes and resource efficiency.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11487873B2Risk score generation utilizing monitored behavior and predicted impact of compromise
Publication Date: 2022.11.01 EMC IP HLDG CO LLC
  • US11487873B2 patent drawing
  • US11487873B2 patent drawing
  • US11487873B2 patent drawing

AI summary

A method includes monitoring user behavior in an enterprise system, identifying a given user of the enterprise system associated with a given portion of the monitored user behavior, determining a predicted impact of compromise of the given user on the enterprise system, generating a risk score for the given user based on the predicted impact of compromise and the given portion of the monitored user behavior, and identifying one or more remedial actions to reduce the risk score for the given user. The method also includes implementing, prior to detecting compromise of the given user, at least one of the remedial actions to modify a configuration of at least one asset in the enterprise system, the at least one asset comprising at least one of a physical computing resource and a virtual computing resource in the enterprise system.