User Confidence Scoring for Security Policy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security technologies are inadequate in quantifying user riskiness and reducing false positives in detecting anomalous behavior, as they rely on comparing user behavior to peer groups, which is not granular enough to effectively identify potential security threats.

Innovation Solution

The system uses behavior analytics and machine learning to evaluate user compliance with security policies by grouping users based on app usage and location, calculating a user confidence score that reflects the severity and decay of alerts over time, and dynamically reassigning users to peer groups based on behavior patterns, thereby reducing false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If user behavior is compared to peer groups using traditional security technologies, then detection coverage is provided, but measurement precision of user riskiness deteriorates due to insufficient granularity

Engineering Contradiction:
Improveuser riskiness quantificationVSAvoidbehavior analytics system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments users into dynamic peer groups based on multiple dimensions including app usage patterns, location, device type, and security policy compliance history. This segmentation enables granular comparison at the group level while maintaining individual user risk assessment precision, resolving the contradiction between measurement precision and system complexity by creating manageable segments rather than comparing all users uniformly.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The peer groups are dynamically adjusted based on changing user behavior patterns rather than being static. The system continuously monitors user activities and reassigns users to different peer groups as their behavior evolves, which improves measurement precision by comparing users against relevant dynamic benchmarks while the automated dynamic adjustment manages system complexity through adaptive algorithms.

Inventive Principle:
Principle #15Dynamics

2Reliability

If traditional anomaly detection methods are used, then security threats can be identified, but false positives increase due to insufficient behavioral context

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system incorporates feedback loops where detection results, false positives, and security incidents are fed back into the behavior analytics engine. This feedback continuously refines the baseline behavior profiles and alert thresholds, improving reliability by learning from past performance while reducing false positives through iterative optimization of detection parameters based on actual outcomes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts detection parameters such as alert thresholds, confidence levels, and behavior window periods based on contextual factors including user role, department, time of day, and historical behavior patterns. This parameter adaptation improves reliability by tailoring detection sensitivity to specific contexts while reducing false positives through contextual awareness rather than rigid one-size-fits-all thresholds.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If static peer group assignments are used, then system complexity is reduced, but adaptability to changing user behavior patterns deteriorates

Engineering Contradiction:
Improvepeer group assignmentVSAvoiddynamic group management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service mechanisms where users automatically belong to appropriate peer groups based on their current behavior patterns without manual intervention. The automated assignment process monitors user activities and dynamically places users in the most relevant peer groups, improving adaptability to behavior changes while managing complexity through rule-based automatic classification rather than manual group management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-defining multiple potential peer group categories and criteria before users exhibit anomalous behavior. When behavior patterns change, the system can quickly reassign users to pre-established appropriate groups rather than creating new groups from scratch, improving adaptability while managing complexity through pre-prepared classification frameworks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20220377111A1Scoring confidence in user compliance with an organization's security policies
Publication Date: 2022.11.24 NETSKOPE INC
  • US20220377111A1 patent drawing
  • US20220377111A1 patent drawing
  • US20220377111A1 patent drawing

AI summary

The disclosed technology teaches a method for evaluating user compliance with an organization's security policies, formulating a user confidence or risk score, comprising scoring for each user a sum of alert weights, categorized by severity, and generated over time. Each contribution to an alert weight is generated due to an activity by the user that the organization's security policies treat as risky. Alert weights, over time, are subject to a decay factor that attenuates the alert weights as time passes. Also disclosed is reporting the user confidence score, comprising causing display of a time series of the user confidence or risk scores over a predetermined time and/or a current user confidence or risk score and/or at least some details of the activity by the user that contributed to the alert weights over time.