Security Event Bucketing for User Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Determining the susceptibility of devices to phishing attacks in isolation is difficult, making it challenging to accurately assess and target mitigation efforts.

Innovation Solution

Implementing systems and methods for generating risk scores by categorizing events into buckets and aggregator buckets, assigning weights, and computing risk scores over time, which allows for automated and targeted phishing simulations to identify vulnerable devices and users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If simulated phishing attacks are performed on individual devices in isolation, then device susceptibility can be tested, but accurate assessment of overall organizational risk and identification of high-risk users becomes difficult

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments security events into categorized buckets (e.g., phishing events, malware events, data access events) with assigned risk weights. This segmentation transforms complex organizational security data into structured, analyzable units that can be processed systematically to generate individual user risk scores, thereby improving measurement precision without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk scoring system that aggregates individual event bucket scores into comprehensive user risk profiles. This intermediary layer translates discrete phishing test results and security events into standardized risk scores, enabling accurate comparative assessment across users while maintaining manageable system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring of all devices is performed, then complete security coverage is achieved, but computing resources are wasted on low-risk devices

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputing resource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by tailoring monitoring intensity to individual user risk profiles. High-risk users receive intensified monitoring and simulated phishing campaigns, while low-risk users receive reduced monitoring. This differential approach maintains comprehensive security coverage reliability while minimizing computing resource waste on already-secure devices.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial monitoring action by focusing computational resources on users who exceed risk thresholds rather than uniformly monitoring all devices. This partial action approach achieves adequate security coverage by concentrating efforts where risk is highest, thereby reducing overall computing resource consumption while maintaining effective security posture.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If risk scores are computed for all users, then complete risk profile is obtained, but processing time and computational load increase

Engineering Contradiction:
Improverisk information completenessVSAvoidcomputation time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-categorizing security events into weighted buckets and establishing risk score thresholds before actual risk assessment. This preliminary structuring of data and criteria enables rapid computation of user risk scores when needed, as the heavy lifting of event classification and weight assignment has already been completed, thereby reducing real-time computational load while maintaining information completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250291930A1Systems and method for generating risk scores
Publication Date: 2025.09.18 KNOWBE4 INC
  • US20250291930A1 patent drawing
  • US20250291930A1 patent drawing
  • US20250291930A1 patent drawing

AI summary

Systems and methods are described for generating a risk score of a user based at least on groups of events related to security. In an example, a method is described that includes receiving data associated with a plurality of events, identifying a plurality of buckets, assigning each event to a bucket based at least on a type associated with the event, and computing a risk score for a user based at least on a function of the weight assigned to each bucket and a quantity of events in each bucket. In some examples, systems and methods also include providing a graphical user interface to display the risk score.