Security Event Bucketing for User Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Determining the susceptibility of devices to phishing attacks in isolation is difficult, making it challenging to accurately assess and target mitigation efforts.
Innovation Solution
Implementing systems and methods for generating risk scores by categorizing events into buckets and aggregator buckets, assigning weights, and computing risk scores over time, which allows for automated and targeted phishing simulations to identify vulnerable devices and users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If simulated phishing attacks are performed on individual devices in isolation, then device susceptibility can be tested, but accurate assessment of overall organizational risk and identification of high-risk users becomes difficult
Solution Approach 1:
The patent segments security events into categorized buckets (e.g., phishing events, malware events, data access events) with assigned risk weights. This segmentation transforms complex organizational security data into structured, analyzable units that can be processed systematically to generate individual user risk scores, thereby improving measurement precision without overwhelming system complexity.
Solution Approach 2:
The patent introduces an intermediary risk scoring system that aggregates individual event bucket scores into comprehensive user risk profiles. This intermediary layer translates discrete phishing test results and security events into standardized risk scores, enabling accurate comparative assessment across users while maintaining manageable system architecture.
2Reliability
If comprehensive monitoring of all devices is performed, then complete security coverage is achieved, but computing resources are wasted on low-risk devices
Solution Approach 1:
The patent applies local quality by tailoring monitoring intensity to individual user risk profiles. High-risk users receive intensified monitoring and simulated phishing campaigns, while low-risk users receive reduced monitoring. This differential approach maintains comprehensive security coverage reliability while minimizing computing resource waste on already-secure devices.
Solution Approach 2:
The patent implements partial monitoring action by focusing computational resources on users who exceed risk thresholds rather than uniformly monitoring all devices. This partial action approach achieves adequate security coverage by concentrating efforts where risk is highest, thereby reducing overall computing resource consumption while maintaining effective security posture.
3Loss of information
If risk scores are computed for all users, then complete risk profile is obtained, but processing time and computational load increase
Solution Approach 1:
The patent performs preliminary action by pre-categorizing security events into weighted buckets and establishing risk score thresholds before actual risk assessment. This preliminary structuring of data and criteria enables rapid computation of user risk scores when needed, as the heavy lifting of event classification and weight assignment has already been completed, thereby reducing real-time computational load while maintaining information completeness.
Data Source
AI summary
Systems and methods are described for generating a risk score of a user based at least on groups of events related to security. In an example, a method is described that includes receiving data associated with a plurality of events, identifying a plurality of buckets, assigning each event to a bucket based at least on a type associated with the event, and computing a risk score for a user based at least on a function of the weight assigned to each bucket and a quantity of events in each bucket. In some examples, systems and methods also include providing a graphical user interface to display the risk score.


