Web User Risk Assessment via Behavioral Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current internet security measures, including firewalls and browsing restrictions, fail to effectively monitor and mitigate risks posed by employee web behavior, leaving organizations vulnerable to threats despite the need for proactive risk assessment and management.
Innovation Solution
A system and method for calculating a user's risk score based on web actions, using a traffic-capturing module, classification module, computing agent, analyzing module, and reporting agent to assign risk scores and values, allowing for the determination of a total risk score and reporting of user risk indices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If basic security measures (firewalls, gateway security agents, intrusion detection systems) are implemented, then network security protection is improved, but these measures require regular updating and cannot protect from all possible threats
Solution Approach 1:
The patent implements a feedback mechanism by continuously monitoring user web behavior, calculating risk scores based on observed actions, and dynamically updating security policies. The system captures web actions, computes risk scores using predefined criteria and weighting factors, and adjusts security measures based on the calculated risk levels, creating a closed-loop security system that adapts to emerging threats without requiring manual intervention for every update
Solution Approach 2:
The patent applies preliminary action by pre-defining multiple risk criteria and weighting factors before deployment. The system establishes a framework with predetermined risk categories (such as browsing categories, download behaviors, email activities) and their associated weighting factors, allowing it to immediately assess and respond to user actions without requiring real-time analysis rule creation
2Reliability
If applications that block or restrict access to certain websites are installed, then security policy enforcement is improved, but employees can still access websites that might have a detrimental effect on the organization
Solution Approach 1:
The patent changes the parameter of security enforcement from binary block/allow decisions to a continuous risk score spectrum. Instead of simply blocking websites based on predefined categories, the system calculates risk scores based on multiple criteria including browsing categories, download behaviors, email activities, and application usage, with each criterion having adjustable weighting factors. This allows nuanced security decisions that adapt to individual user risk profiles
3Measurement precision
If applications that record and report user generated web activity are used, then web behavior monitoring is improved, but administrators must perform the tedious task of examining stacks of reports to detect vulnerabilities
Solution Approach 1:
The patent implements self-service by enabling the system to automatically analyze recorded web activity, calculate risk scores, and generate actionable security recommendations without administrator intervention. The system autonomously processes captured web actions, applies risk criteria and weighting factors, determines overall risk levels, and presents synthesized findings, eliminating the need for administrators to manually examine extensive reports
Solution Approach 2:
The patent replaces the mechanical process of manual report examination with an automated computational system. Instead of administrators physically reviewing stacks of reports, the system uses computing agents to automatically process web action data, calculate risk scores using predefined algorithms, and generate security assessments, substituting human analytical effort with automated computational analysis
4Reliability
If multiple security systems are deployed at the network edge, then security coverage is improved, but these systems cannot protect organizations from all possible threats including internal risks
Solution Approach 1:
The patent adds another dimension to security by moving from network-edge security to user-behavior-based security. Instead of solely relying on perimeter defenses, the system introduces a new dimension of monitoring that tracks individual user web activities, calculates risk scores based on behavioral patterns, and identifies internal threats through anomaly detection in user actions across multiple dimensions including browsing, downloading, emailing, and application usage
Data Source
AI summary
A system and method for determining the risk posed by a web user. The web user can be an individual, a department, a location, or an organization. The method includes the steps of capturing user generated web actions, and classifying the web actions under zero or more risk criteria. The risk criteria include one or more risk calculating and weighting factors. The method further includes the steps of calculating risk scores for the classified risk criteria, combining the calculated risk scores to obtain a total risk score, assigning a qualitative value to the total risk score, and reporting the total risk score. The reported total risk score can be used to enforce security policies based on the value of the risk scores.


