Dynamic employee security risk scoring

US10282702B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10282702-B2
Application numberUS-65164510-A
CountryUS
Kind codeB2
Filing dateJan 4, 2010
Priority dateJan 4, 2010
Publication dateMay 7, 2019
Grant dateMay 7, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments of the invention relate to systems, methods, and computer program products that provide for an employee security risk score. The security risk score is presented as an extensible composite vector that supports an arbitrary number of risk categories. The risk categories can be aggregated at any level in the business hierarchy or according to any employee parameter. The simplistic, highly normalized approach to employee security risk scoring reduces redundancies and dependencies and provides for real-time updates, As such, the employee security risk scoring system provides for easily identifiable recognition of employees who pose security threats and for a means to track and monitor security risks posed by the employee based on their security risk score.

First claim

Opening claim text (preview).

The invention claimed is: 1. An apparatus for quantifying employee security risk, the apparatus comprising: a computing platform including at least one processor and a memory; an employee security risk scoring module that is stored in the memory, executable by the processor, configured to: receive a plurality of security risk facts, each fact associated with one of a plurality of employees, wherein one or more of the security risk facts are received within real-time of an event associated with a security risk fact, consolidate the plurality of security risk facts to (1) determine one of a plurality of security risk categories to assign to each of the security risk facts, and (2) determine security risk facts that are redundant and remove the redundant risk facts from further employee risk score processing, wherein the security risk categories include (1) access to non-public information, (2) volume of non-public information consumed within a predetermined time period, (3) ability to export data, (4) behaviors associated with a security risk and (5) volume of hardware accessed within a predetermined time period, and transform the plurality of security risk facts to a standard format prior to the employees security risk score processing; an employee security risk scoring logic configured to determine an employee security risk score for each of the employees that meet a predetermined employee parameter, based on the plurality of security risk facts, wherein the employee security risk scoring logic further comprises: a security risk category scoring routine configured to determine, for each of the employees that meet the employee parameter, an employee-specific security risk category score for each of the plurality of security risk categories, a security risk category average routine configured to determine a security risk category average for each of the plurality of security risk categories and for the employees that meet the predetermined employee parameter, a security risk category standard deviation routine configured to determine a security risk category standard deviation for each of the plurality of security risk categories and for the employees that meet by a predetermined employee parameter, a sigma scoring routine configured to determine a sigma score, which is specific to the employee parameter, for each of the security risk categories, wherein the sigma score is determined by subtracting the security risk category average from the security risk category score to result in a remainder and dividing the remainder by the security risk category standard deviation, and an employee risk scoring routine configured to determine, for each of the employees that meet the employee parameter, the employee security risk score by aggregating all positive-valued sigma scores for each of the security risk categories; a graphical user interface module configured to dynamically display, via a network connection, employee security risk scores for each of the employees, to thereby providing tracking a security risk of employees in terms of their respective security risk scores for the predetermined employee parameter; a security risk reporting application configured to automatically generate a dynamic employee security risk report indicating employees that are determined to pose security risks based on their scores exceeding a predetermined threshold; and a reporting application configured to initiate communication of the report to a remote electronic device. 2. The apparatus of claim 1 , wherein the employee security category routine is further configured to aggregate the security risk facts associated with a security risk category to determine the security risk category score. 3. The apparatus of claim 1 , wherein the employee security risk scoring module further comprises a security risk fact weighting mechanism configured to apply a predetermined weighting factor to one or more of the security risk facts based on security risk significance prior to determining the security risk category score. 4. The apparatus of claim 1 , wherein the employee risk scoring logic is further configured to apply a predetermined weighting factor to each of the positive-valued parameter-specific sigma scores, wherein the predetermined weighting factor is based on the significance of the security risk category associated with the sigma score in determining the employee risk score. 5. The apparatus of claim 1 , wherein the plurality of risk categories include (6) high-risk user indicators. 6. The apparatus of claim 1 , wherein the employee security risk scoring module is further configured to provide for dynamic user-addition or user-subtraction to the plurality of security risk categories without requiring change to the employee security risk scoring logic. 7. The apparatus of claim 1 , wherein the predetermined employee parameter is further defined as a level within an employer hierarchy. 8. The apparatus of claim 7 , wherein the predetermined employee parameter is further defined as one of job title or business unit.

Assignees

Inventors

Classifications

  • Personal security, identity or safety · CPC title

  • G06Q10/10Primary

    Office automation; Time management · CPC title

  • Human resources · CPC title

  • Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10282702B2 cover?
Embodiments of the invention relate to systems, methods, and computer program products that provide for an employee security risk score. The security risk score is presented as an extensible composite vector that supports an arbitrary number of risk categories. The risk categories can be aggregated at any level in the business hierarchy or according to any employee parameter. The simplistic, hi…
Who is the assignee on this patent?
Paltenghe Cris T, Baikalov Igor, Kirby Craig, and 3 more
What technology area does this patent fall under?
Primary CPC classification G06Q10/10. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 07 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).