Rolling Risk Score Detection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems struggle to efficiently detect sudden increases in user risk in real-time, making it difficult to initiate appropriate security measures promptly and prevent potential security breaches from escalating.

Innovation Solution

The implementation of a system that uses a rolling time window to determine risk scores for multiple users, generating a rolling set of risk scores. Anomalous detection is performed on the time series of relative risk scores, allowing for the automatic initiation of pre-configured security measures when an anomalous increase in risk is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional risk scoring methods are used to monitor user risk, then security analysts can review risk scores to identify risk trends, but sudden increases in risk cannot be detected quickly enough to take immediate security measures

Engineering Contradiction:
ImproveSpeed of risk increase detectionVSAvoidTime delay in initiating security measures
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent implements dynamic risk score comparison by continuously calculating current risk scores and comparing them against historical risk scores within a rolling time window. This dynamic approach allows the system to adapt to changing risk conditions in real-time, enabling rapid detection of sudden risk increases and immediate initiation of security measures without fixed time delays

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where risk scores are continuously monitored, compared against thresholds and historical data, and used to automatically trigger security measures. This closed-loop feedback mechanism enables the system to respond automatically to risk changes, eliminating manual review delays and ensuring rapid response to security threats

Inventive Principle:
Principle #23Feedback

2Productivity

If security measures are automatically initiated based on risk scores, then response time is reduced, but false positives may cause unnecessary security actions

Engineering Contradiction:
ImproveSpeed of security measure initiationVSAvoidAccuracy of risk assessment
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary actions by pre-configuring security measures that are automatically triggered when risk scores exceed predetermined thresholds. These pre-configured responses are prepared in advance, allowing immediate execution when conditions are met, thereby reducing response time while maintaining reliability through careful threshold calibration and pre-validation of security measures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts risk assessment parameters by comparing current risk scores against historical scores within rolling time windows and evaluating multiple risk factors. This multi-parameter approach with adjustable thresholds and time windows allows the system to differentiate between normal fluctuations and genuine security threats, reducing false positives while maintaining rapid response capability

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4348464B1Conditional security measures using rolling set of risk scores
Publication Date: 2025.04.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4348464B1 patent drawingFigure 1
  • EP4348464B1 patent drawingFigure 2
  • EP4348464B1 patent drawingFigure 3

AI summary

Conditionally initiating a security measure in response to an estimated increase in risk imposed related to a particular user of a computing network. The risk is determined using a rolling time window. Accordingly, sudden increases in risk are quickly detected, allowing security measures to be taken quickly within that computing network. Thus, improper infiltration into a computing network is less likely to escalate or move laterally to other users or resources within the computing network. Furthermore, the security measure may be automatically initiated using settings pre-configured by the entity. Thus, the security measures go no further than what the entity instructed, thereby minimizing risk of overreaching with the security measure.