Social Risk Management System for Proactive Cyber Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cybersecurity measures are reactive and inadequate in addressing modern cyber threats that exploit social media and social networks, failing to predict and prevent attacks before they occur.

Innovation Solution

A predictive and active social risk management system that uses a scoring algorithm to analyze social entities' characteristics and communications, generating risk scores and recommending security actions based on these analyses to proactively protect users from potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional reactive security measures (anti-virus, firewalls) are used to secure endpoints and networks, then local system-level attacks can be detected and perimeter security can be established, but modern social media-based cyber threats cannot be predicted or prevented before they occur

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidcapability to address modern social media threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by continuously monitoring social network accounts of organization members and calculating risk scores before attacks occur. It identifies dormant malicious entities and potential threats in advance, enabling proactive security measures rather than reactive responses after breaches happen.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the monitoring approach by individually assessing each social network account's risk level through separate risk score calculations. Each user's social media presence is evaluated independently, allowing targeted security interventions for high-risk accounts while maintaining overall organizational security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If social network accounts of organization members are monitored to identify security risks, then dormant malicious entities can be detected before attacks, but user privacy and anonymity concerns arise

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiduser anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system extracts only the necessary risk assessment information from social network monitoring while leaving user identities protected. Risk scores and threat indicators are calculated and reported without exposing personal user data, separating the security intelligence from identifying information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The risk scoring system acts as an intermediary layer between social network monitoring and organizational security decisions. It translates raw social media data into anonymized risk scores that indicate threat levels without revealing user identities, enabling security actions while preserving privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If individual user social network accounts are monitored and risks are reported with user names, then specific security threats can be identified, but organizational-wide security patterns and aggregated risk assessment are compromised

Engineering Contradiction:
Improveindividual threat identification accuracyVSAvoidorganizational security management efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system merges individual risk assessments into aggregated organizational risk reports that show patterns across multiple users. By combining data from multiple social network accounts, it identifies organization-wide security trends and common threat vectors, enabling efficient resource allocation and targeted security campaigns.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system applies partial action by providing different levels of detail to different stakeholders. Individual users receive specific risk information relevant to their accounts, while organizational leaders receive aggregated reports showing overall security posture and trends, optimizing information delivery for each audience.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10868824B2Organizational social threat reporting
Publication Date: 2020.12.15 ZEROFOX INC
  • US10868824B2 patent drawing
  • US10868824B2 patent drawing
  • US10868824B2 patent drawing

AI summary

A computer-implemented method includes identifying, by one or more processors, a first user associated with an organization, identifying one or more social network accounts associated with the first user, identifying a second user associated with the organization, identifying one or more social network accounts associated with the second user, generating a protection portal for the organization, providing a link to the protection portal for the organization to a third user, and providing one or more alerts to the third user associated with the organization, wherein the one or more alerts identify security risks associated with one or more of the first or second user's social network accounts.