Web User Risk Assessment via Behavioral Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current internet security measures, including firewalls and browsing restrictions, fail to effectively monitor and mitigate risks posed by employee web behavior, leaving organizations vulnerable to threats despite the need for proactive risk assessment and management.

Innovation Solution

A system and method for calculating a user's risk score based on web actions, using a traffic-capturing module, classification module, computing agent, analyzing module, and reporting agent to assign risk scores and values, allowing for the determination of a total risk score and reporting of user risk indices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If basic security measures (firewalls, gateway security agents, intrusion detection systems) are implemented, then network security protection is improved, but these measures require regular updating and cannot protect from all possible threats

Engineering Contradiction:
Improvenetwork security protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism by continuously monitoring user web behavior, calculating risk scores based on observed actions, and dynamically updating security policies. The system captures web actions, computes risk scores using predefined criteria and weighting factors, and adjusts security measures based on the calculated risk levels, creating a closed-loop security system that adapts to emerging threats without requiring manual intervention for every update

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by pre-defining multiple risk criteria and weighting factors before deployment. The system establishes a framework with predetermined risk categories (such as browsing categories, download behaviors, email activities) and their associated weighting factors, allowing it to immediately assess and respond to user actions without requiring real-time analysis rule creation

Inventive Principle:
Principle #10Preliminary action

2Reliability

If applications that block or restrict access to certain websites are installed, then security policy enforcement is improved, but employees can still access websites that might have a detrimental effect on the organization

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoiddetrimental web access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter of security enforcement from binary block/allow decisions to a continuous risk score spectrum. Instead of simply blocking websites based on predefined categories, the system calculates risk scores based on multiple criteria including browsing categories, download behaviors, email activities, and application usage, with each criterion having adjustable weighting factors. This allows nuanced security decisions that adapt to individual user risk profiles

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If applications that record and report user generated web activity are used, then web behavior monitoring is improved, but administrators must perform the tedious task of examining stacks of reports to detect vulnerabilities

Engineering Contradiction:
Improveweb behavior monitoringVSAvoidadministrator review time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the system to automatically analyze recorded web activity, calculate risk scores, and generate actionable security recommendations without administrator intervention. The system autonomously processes captured web actions, applies risk criteria and weighting factors, determines overall risk levels, and presents synthesized findings, eliminating the need for administrators to manually examine extensive reports

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of manual report examination with an automated computational system. Instead of administrators physically reviewing stacks of reports, the system uses computing agents to automatically process web action data, calculate risk scores using predefined algorithms, and generate security assessments, substituting human analytical effort with automated computational analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If multiple security systems are deployed at the network edge, then security coverage is improved, but these systems cannot protect organizations from all possible threats including internal risks

Engineering Contradiction:
Improvesecurity coverageVSAvoidinternal threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent adds another dimension to security by moving from network-edge security to user-behavior-based security. Instead of solely relying on perimeter defenses, the system introduces a new dimension of monitoring that tracks individual user web activities, calculates risk scores based on behavioral patterns, and identifies internal threats through anomaly detection in user actions across multiple dimensions including browsing, downloading, emailing, and application usage

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8478708B1System and method for determining risk posed by a web user
Publication Date: 2013.07.02 ZSCALER INC
  • US8478708B1 patent drawing
  • US8478708B1 patent drawing
  • US8478708B1 patent drawing

AI summary

A system and method for determining the risk posed by a web user. The web user can be an individual, a department, a location, or an organization. The method includes the steps of capturing user generated web actions, and classifying the web actions under zero or more risk criteria. The risk criteria include one or more risk calculating and weighting factors. The method further includes the steps of calculating risk scores for the classified risk criteria, combining the calculated risk scores to obtain a total risk score, assigning a qualitative value to the total risk score, and reporting the total risk score. The reported total risk score can be used to enforce security policies based on the value of the risk scores.