Transaction Security Risk Aggregation via Weighted Matrix
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security risk tracking methods provide an incomplete and dated view of security risks, focusing on individual employee compliance without considering the organizational perspective, threat likelihood, or business-level context, and do not evaluate transaction-based security risks effectively.
Innovation Solution
A computerized method and system for transaction-based security risk aggregation and analysis that combines security risk data elements into a weighted risk matrix, generating a risk score based on business-level context and execution priority to determine whether to allow transaction execution, using a server computing device to receive and process security risk data from various sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If security risk tracking is based on individual employee compliance with risk policies, then ease of operation is improved, but measurement precision and completeness of security risk view deteriorate
Solution Approach 1:
The patent merges multiple security risk data elements from diverse sources (device security posture, user behavior, transaction characteristics, business context) into a unified risk score. This consolidation transforms fragmented compliance data into a comprehensive risk assessment that captures both individual and organizational security health, resolving the contradiction between ease of operation and measurement precision.
Solution Approach 2:
The risk scoring system serves multiple functions simultaneously: it assesses individual employee compliance, evaluates device security posture, analyzes transaction risk, and provides organizational security health metrics. This multi-functionality allows the system to maintain operational simplicity while delivering comprehensive security measurements across multiple dimensions.
2Device complexity
If security risks are evaluated without organizational perspective, then device complexity is reduced, but loss of information about overall security health increases
Solution Approach 1:
The patent adds an organizational dimension to security risk evaluation by aggregating individual risk scores into departmental and enterprise-level security health metrics. This dimensional expansion enables the system to provide both detailed individual assessments and holistic organizational views without significantly increasing computational complexity, as the aggregation follows standardized algorithms.
3Measurement precision
If transaction security risk does not consider business-level context, then measurement precision is improved, but loss of information about execution priority increases
Solution Approach 1:
The patent applies local quality by customizing risk assessment parameters based on specific transaction characteristics and business context. Different transaction types (e.g., financial transfers, data access, system configuration) receive tailored risk evaluations that consider their specific business implications, execution priority, and potential impact. This localized approach enhances both measurement precision and information completeness simultaneously.
Data Source
AI summary
Methods and apparatuses, including computer program products, are described for transaction-based security risk aggregation and analysis. A server computing device receives security risk data elements from a plurality of data sources. The security risk data elements correspond to a transaction submitted by a remote computing device to the server computing device for execution. The server computing device aggregates the security risk data elements into a weighted risk matrix and generates a risk score for the submitted transaction based upon the weighted risk matrix. The server computing device determines a business-level context and an execution priority of the submitted transaction, the business-level context and the execution priority based upon the security risk data elements. The server computing device adjusts the risk score for the submitted transaction based upon the business-level context and the execution priority and determines whether to allow execution of the transaction based upon the adjusted risk score.


