User Risk Scoring via Internal and External Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face significant challenges in managing organization-based security risks due to dispersed operations, critical assets that require protection, and sophisticated threats like advanced persistent threats and spear phishing, which traditional security measures struggle to effectively address.

Innovation Solution

A method and system that analyze organization-based information and publicly available data to derive a risk score for users, prioritizing monitoring and incident response efforts by identifying high-risk employees and determining the ease with which their access can be exploited by attackers, using a combination of internal and external data sources and networking principles to map potential attack paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (fixed codes, physical devices) are used to control access, then access security is maintained, but users can be compromised through phishing attacks where attackers obtain possession of fixed codes or devices

Engineering Contradiction:
Improveaccess securityVSAvoidphishing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical authentication systems (physical keys, fixed passwords, tokens) with a biometric-based authentication system using fingerprint recognition. This substitution eliminates the vulnerability to phishing attacks where attackers obtain possession of fixed codes or devices, as biometric data cannot be stolen or transferred through social engineering. The system verifies user identity by comparing fingerprint patterns directly, making authentication immune to credential theft.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive security monitoring is implemented across all users, then security coverage is improved, but system complexity and resource consumption increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements security measures selectively at critical access points rather than uniformly across all system interactions. Fingerprint authentication is deployed specifically at authentication gates where security is most needed, while other system operations maintain standard procedures. This localized approach provides comprehensive security coverage at critical points without the complexity and resource consumption of monitoring all user activities throughout the system.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If fixed authentication codes are used, then authentication simplicity is maintained, but security is compromised as users must be trained to recognize phishing attempts

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces text-based authentication (passwords, codes) with biometric authentication using fingerprint recognition. This maintains ease of operation as users simply place their finger on a sensor rather than manually entering codes, while simultaneously improving security by eliminating the need for users to recognize or respond to phishing attempts. The biometric verification occurs automatically at the authentication gate, making the system both simpler and more secure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9239908B1Managing organization based security risks
Publication Date: 2016.01.19 EMC IP HLDG CO LLC
  • US9239908B1 patent drawing
  • US9239908B1 patent drawing
  • US9239908B1 patent drawing

AI summary

A method and system is used in managing organization based security risks. Organization based information is analyzed for information that is suitable for use in attacking a user in the organization. The organization based information comprises user access information. Publicly available information is analyzed for information that is suitable for use in identifying the user within the organization. Based on the analyzes, there is derived a risk score for the user.