Predictive Threat Rating System for Insider Risk
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for monitoring and managing electronic confidential information within organizations are inadequate in providing a comprehensive threat rating, as they fail to consider individual user characteristics and activities, leading to inefficient resource utilization and delayed response to potential threats.
Innovation Solution
A method and system for calculating predictive threat ratings for individuals within an organization by monitoring and weighting various activities, such as internet access, blocked communications, and security application usage, to provide a nuanced threat assessment that accounts for user-specific job responsibilities and access levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current systems block certain activities to protect confidential information, then security protection is improved, but productivity and efficiency are reduced
Solution Approach 1:
The system applies different security policies and threat thresholds to different user accounts based on their job responsibilities and access levels. High-risk users receive more stringent monitoring and lower threat thresholds, while low-risk users experience fewer restrictions, thereby maintaining security where needed while preserving productivity for trusted users.
Solution Approach 2:
The system dynamically adjusts security measures and threat ratings based on real-time user behavior patterns and risk assessments. Rather than applying static blocking rules to all users, the system adapts security controls to individual risk profiles, allowing legitimate productivity while blocking only the specific high-risk activities identified for each user.
2Ease of manufacture
If a one size fits all security policy is applied to all users, then implementation simplicity is improved, but accuracy in identifying actual threats is reduced
Solution Approach 1:
The system implements user-specific threat ratings and security policies tailored to each user's job function, access level, and behavioral patterns. This allows the system to accurately identify actual threats for each user rather than applying uniform thresholds that either over-block low-risk users or under-block high-risk users.
Solution Approach 2:
The system pre-configures baseline security policies and threat thresholds for different user categories, simplifying initial implementation. These pre-established frameworks can be quickly deployed across the organization while still allowing for individualized adjustments based on specific user risk profiles and observed behaviors.
3Reliability
If multiple individual security measures are applied to each user, then comprehensive security coverage is improved, but complexity of the system increases
Solution Approach 1:
The system consolidates multiple individual security measures and monitoring mechanisms into a unified threat rating framework. By integrating various security controls, behavior analytics, and risk assessments into a single comprehensive threat rating system, the organization achieves broad security coverage while simplifying management and reducing operational complexity.
Solution Approach 2:
The threat rating system serves multiple security functions simultaneously - it monitors user behavior, assesses risk levels, determines appropriate security controls, and guides incident response actions. This multi-functional approach eliminates the need for separate systems for each security function, reducing overall system complexity while maintaining comprehensive coverage.
4Measurement precision
If data collection from multiple systems is performed continuously, then up-to-date threat indication is improved, but resource consumption increases
Solution Approach 1:
The system implements periodic sampling and event-driven data collection from multiple security systems rather than continuous monitoring. Threat ratings are updated at scheduled intervals or triggered by specific security events, providing timely threat indications while significantly reducing the computational resources required compared to continuous real-time analysis of all security data streams.
Data Source
AI summary
Systems and methods for calculating threat scores for individuals within an organization or domain are provided. Aspects of the invention relate to computer-implemented methods that form a predictive threat rating for user accounts. In one implementation, a first threat score representing a first time period may be calculated. The first threat score may be compared with aspects of the same user accounts for a second time period. Weighting schemes may be applied to certain activities, controls, and/or user accounts. Further aspects relate to apparatuses configured to execute methods for ranking individual user accounts. Certain embodiments may not block transmissions that violate predefine rules, however, indications of such improper transmission may be considered when constructing a threat rating. Blocked transmissions enforced upon a user account may also be received. Certain activity, such as accessing the internet, may be monitored for the presence of a security threat and/or an ethics threat.


