Risk-Based Computer System Scanning for Confidential Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in monitoring and identifying computer systems that pose a higher risk of compromising confidential information due to the sheer volume of data and numerous ways information can be disseminated across various devices within their networks.
Innovation Solution
A system and method for compiling a list of user computer systems at risk, determining their availability for scanning, and scanning them to identify potential or actual threats, while rating their risk levels and remediating incidents through a coordinated effort involving remediation and escalation teams.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive scanning of all computer systems is performed, then security monitoring coverage is improved, but system resources and time consumption increase significantly
Solution Approach 1:
The patent applies local quality by differentiating scanning intensity and frequency based on risk ratings. High-risk systems receive more frequent and thorough scanning, while low-risk systems receive less intensive monitoring. This resolves the contradiction by concentrating security resources where they are most needed rather than applying uniform scanning across all systems.
Solution Approach 2:
The patent changes the parameter of scanning frequency and depth based on dynamically calculated risk ratings. Systems are re-rated periodically, and scanning parameters are adjusted accordingly. This allows the organization to maintain high security coverage for critical systems while reducing scanning overhead for lower-risk systems, thereby managing time consumption effectively.
2Measurement precision
If frequent scanning of computer systems is performed, then threat detection capability is improved, but system performance and user productivity deteriorate
Solution Approach 1:
The patent implements local quality by applying different scanning frequencies to different systems based on their risk profiles. High-risk systems are scanned more frequently to maintain high threat detection capability, while low-risk systems are scanned less frequently to minimize impact on user productivity. This differentiated approach resolves the contradiction between detection precision and productivity.
3Productivity
If risk-based prioritization of scanning is implemented, then scanning efficiency is improved, but complexity of system management increases
Solution Approach 1:
The patent applies segmentation by dividing the computer system population into risk-based groups (high, medium, low risk). Each group receives appropriate scanning frequency and intensity. This segmentation improves scanning efficiency by focusing resources on high-risk systems while simplifying management through clear categorization and automated risk-based routing.
Data Source
AI summary
Embodiments of the present invention provide apparatuses and methods for identifying computer systems that pose a threat for potential dissemination of confidential information, and thereafter, scanning the computer systems for unauthorized activity related to potential dissemination of confidential information. Embodiments of the invention comprise compiling a list of user computer systems that are at risk of accessing, using, or disseminating confidential information; determining whether the computer systems on the list are available for scanning; and scanning the computer systems on the list to identify an incident related to potential or actual threats or breaches of confidential information.


