User Behavioral Risk Assessment via Segmented Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems inadequately address the risk posed by human behavior in computing environments, as they primarily focus on device vulnerabilities without considering user activities, which can lead to security weaknesses and threats.

Innovation Solution

A system that includes a user behavioral risk analysis tool, which detects specific activities performed by users, determines if they violate predefined rules, and calculates a behavioral risk score, triggering countermeasures based on thresholds such as time, repetition, or severity, using a combination of local and remote data from security tools to assess and mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security systems focus only on device vulnerabilities, then device security is improved, but user behavior risks are not addressed

Engineering Contradiction:
Improvedevice securityVSAvoiduser behavior risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security assessment is segmented into two independent components: device vulnerability assessment and user behavior risk assessment. The system separately evaluates device security status and user activity patterns, then combines them to form a comprehensive risk profile. This allows each component to be optimized independently while addressing both device security and user behavior risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges device vulnerability data with user behavior analysis data to create a unified risk assessment model. By combining these previously separate assessment dimensions, the system achieves comprehensive security evaluation that addresses both device security and user behavior risks simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

2Object-affected harmful factors

If comprehensive user behavior monitoring is implemented, then user activity risks are detected, but system complexity increases

Engineering Contradiction:
Improveuser activity risksVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system extracts and isolates specific user behavior indicators that are most relevant to security risks, rather than monitoring all user activities comprehensively. By selecting only the critical behavior metrics needed for risk assessment, the system reduces monitoring complexity while still effectively detecting user activity risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the assessment parameters from comprehensive behavioral monitoring to focused risk indicator monitoring. By defining specific behavioral thresholds and risk criteria, the system simplifies the monitoring process while maintaining effective detection of problematic user activities.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If behavioral risk scores are calculated and enforced, then security enforcement is improved, but user convenience decreases

Engineering Contradiction:
Improvesecurity enforcementVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements dynamic security enforcement where countermeasures are adjusted based on real-time behavioral risk scores. Rather than applying fixed restrictive policies to all users, the system dynamically adapts security measures to individual user risk levels, maintaining strong security enforcement for high-risk behaviors while preserving user convenience for low-risk activities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security enforcement parameters based on calculated behavioral risk scores. By using risk score thresholds to determine when countermeasures should be applied, the system achieves effective security enforcement only when necessary, thereby maintaining user convenience for normal behaviors while preventing security violations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10505965B2User behavioral risk assessment
Publication Date: 2019.12.10 MAGENTA SECURITY HOLDINGS LLC
  • US10505965B2 patent drawing
  • US10505965B2 patent drawing
  • US10505965B2 patent drawing

AI summary

A particular activity performed by a particular user of a computing device is identified, for instance, by an agent installed on the computing device. It is determined that the particular activity qualifies as a particular use violation in a plurality of pre-defined use violations. A behavioral risk score for the particular score for the user is determined based at least in part on the determination that the particular activity of the particular user qualifies as a particular use violation. Determining that the particular activity qualifies as a particular use violation can include determining that the particular activity violates a particular rule or event trigger corresponding to a particular pre-defined use violation.