Risk Score Aggregation via Weighted Normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for aggregating individual risk scores across entity populations in organizations are limited, as they fail to account for population size and entity type differences, leading to ineffective comparisons and loss of important risk information, particularly when dealing with varying population sizes and compositions.

Innovation Solution

A system that generates category and population risk scores by weighting, combining, and normalizing individual risk scores using root mean square or non-linear functions, allowing for dynamic and arbitrary groupings of entities, enabling sensitive detection of high-risk entities and trends across different entity types and populations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If summation or averaging methods are used to aggregate individual risk scores, then aggregate risk scores can be calculated, but the results cannot be effectively compared across populations of different sizes and important risk information is lost

Engineering Contradiction:
Improverisk score aggregation capabilityVSAvoidrisk score comparability and information retention
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent transforms the aggregation approach by changing the mathematical parameters from simple summation or averaging to a weighted aggregation model that incorporates population size normalization and high-risk entity weighting. This allows aggregate scores to be comparable across different population sizes while preserving information about high-risk entities through the weighting mechanism that prevents them from being 'averaged out'.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies asymmetry by treating high-risk entities differently from low-risk entities in the aggregation process. Instead of symmetric treatment where all entities contribute equally to the average, the system applies asymmetric weighting that gives disproportionate importance to high-risk entities, ensuring their risk signals are not lost in the aggregation.

Inventive Principle:
Principle #4Asymmetry

2Ease of operation

If fixed population groupings based on organizational structure are used, then risk scores can be aggregated by department or location, but the ability to dynamically create arbitrary groupings and compare trends is limited

Engineering Contradiction:
Improverisk score aggregation by organizationVSAvoiddynamic grouping capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by allowing population definitions to change over time and across different analyses. Instead of fixed organizational groupings, the system enables dynamic creation of arbitrary populations based on various criteria (entity types, time periods, risk categories), allowing users to adapt groupings to different analytical needs and compare trends across flexible population definitions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies universality by creating a unified aggregation framework that can handle multiple types of groupings simultaneously. The same risk score aggregation mechanism works for traditional organizational structures (departments, locations) as well as arbitrary dynamic groupings (entity types, time-based populations, custom criteria), making the system versatile across different analysis scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If simple averaging methods are used to normalize risk scores across populations, then aggregate scores become comparable, but high-risk entities are averaged out and important information is lost

Engineering Contradiction:
Improverisk score normalizationVSAvoidhigh-risk entity information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent changes the aggregation parameter from equal-weighted averaging to a differentiated weighting scheme. The model incorporates population size normalization to enable comparability while simultaneously applying weights that amplify the contribution of high-risk entities. This dual-parameter approach preserves both normalization benefits and high-risk entity visibility.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent converts the potential harm of high-risk entities being 'lost' in large populations into a benefit by implementing a weighting mechanism that specifically identifies and amplifies high-risk signals. The aggregation process transforms what would be noise in a simple average into actionable risk information through strategic weighting of individual entity scores.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10887335B2Aggregation of risk scores across ad-hoc entity populations
Publication Date: 2021.01.05 INTERSET SOFTWARE
  • US10887335B2 patent drawing
  • US10887335B2 patent drawing
  • US10887335B2 patent drawing

AI summary

The systems and methods described herein, given a population of entities each with associated information technology (IT) security risk scores, computes an aggregate risk score which quantifies the overall risk of the population. The method works for any arbitrary population of any size, and of any combination of different entity types and results in normalized risk scores for the arbitrary population (i.e. in the [0,1] range, regardless of population size or makeup). Since the risk scores are normalized, it affords comparison across different arbitrary entity populations having different combinations of entity types (e.g. users, servers, and printers). The aggregation technique allows for sensitivity to small numbers of high risk entities, which is a highly desirable characteristic for risk-based applications, and allows for sensitivity to different entity types or other relevant factors such as higher risk users, different threat types.