User Behavior Scoring in Online Security Event Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise networks face cyber threats due to varying user behaviors and lack of adherence to security policies, leading to potential data breaches and malware infections, as users engage in risky online activities and ignore security protocols.
Innovation Solution
A system that collects and analyzes user behavior data from endpoints, applies machine learning to assess risk, and implements responsive actions based on predefined security policies, including training, warnings, and access controls to mitigate risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If users are given access to the enterprise network and public networks, then productivity and business operations are enabled, but security risks increase due to cyber-attacks entering through user connections
Solution Approach 1:
The patent introduces an intermediary security management system that sits between users and the enterprise network resources. This system includes security agents on user devices, a security information and event management (SIEM) platform, and policy enforcement mechanisms that mediate all network access requests, allowing productive operations while filtering and controlling security risks through layered security policies and real-time monitoring
Solution Approach 2:
The patent segments the enterprise network access control into multiple independent components: user identity management, device compliance checking, network resource authorization, and real-time threat detection. Each segment operates independently but coordinates through the central security management platform, allowing granular control over different aspects of network access to maintain productivity while addressing specific security concerns
2Reliability
If security monitoring and control measures are implemented, then security risks are reduced, but user convenience and system complexity increase
Solution Approach 1:
The patent implements self-service security mechanisms where the security management system automatically performs device compliance verification, policy enforcement, and threat response actions without requiring manual user intervention. The security agents on user devices automatically report status and receive enforcement decisions, while the central platform automatically adjusts access permissions based on real-time security assessments, reducing user burden while maintaining strong security controls
Solution Approach 2:
The patent dynamically changes security parameters such as access permissions, monitoring intensity, and policy strictness based on real-time user behavior analysis, device security posture, and threat levels. The system adjusts these parameters automatically without user awareness or action, maintaining ease of operation while adapting security measures to current risk conditions
3Measurement precision
If comprehensive user behavior analysis is performed, then security threats are identified more accurately, but data processing requirements and system complexity increase
Solution Approach 1:
The patent segments the complex data processing task into distributed components: security agents on user devices collect and pre-process local behavior data, regional servers aggregate data from multiple users, and the central SIEM platform performs comprehensive analysis. This segmentation allows accurate threat detection through distributed processing while reducing the complexity burden on any single system component
Solution Approach 2:
The patent creates a universal security management platform that handles multiple functions: user authentication, device compliance checking, network access control, threat detection, and incident response. By consolidating these functions into a single multi-functional system, the patent reduces overall system complexity compared to having separate specialized systems for each function, while maintaining high threat detection accuracy through integrated analysis
Data Source
AI summary
A method for providing an automated response to user behavior comprising: receiving, by a computer system, data of user actions taken on a computer of the user, the computer of the user in communication with the computer system; analyzing the received data against the knowledge level of the user as determined by the computer system, and/or, the user's responses to simulations generated by the computer system, to determine a score for the user; and, in response to the score, making a behavior recommendation for the user and/or making a decision to take an action associated with the computer of the user.


