Remedial actions based on user risk assessments
First Claim
Patent Images
1. A method comprising:
- receiving, at a data processing apparatus and for each of a plurality of users within an organization;
(i) user activity data describing a plurality of actions taken by the user by use of a user device over a period of time and risks associated with the actions, and (ii) user responsibility data describing responsibilities of the user within the organization, wherein;
the user responsibility data comprises sensitivity assessment data characterizing a security risk associated with data to which the user has access; and
the plurality of users within the organization comprises users having access to data associated with different security risks;
processing, by the data processing apparatus and for each user;
(i) the user activity data describing the actions taken by the user by use of the user device over the period of time and the risks associated with the actions, and (ii) the user responsibility data describing the responsibilities of the user within the organization, using a risk model to generate a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device; and
determining, by the data processing apparatus, for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation, wherein the user-specific remedial action includes presenting a message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user.
3 Assignments
0 Petitions
Accused Products
Abstract
In some implementations, a method includes receiving, for each of multiple users, user activity data describing actions taken by the user by use of a user device over a period of time, determining, for each user and based on the actions taken by the user over the period of time and user responsibility data that describe responsibilities of the user, a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device, and determining, by the data processing apparatus, for each user and based on the risk assessment determined for the user, whether to implement a user-specific remedial action directed to risk mitigation.
-
Citations
19 Claims
-
1. A method comprising:
-
receiving, at a data processing apparatus and for each of a plurality of users within an organization;
(i) user activity data describing a plurality of actions taken by the user by use of a user device over a period of time and risks associated with the actions, and (ii) user responsibility data describing responsibilities of the user within the organization, wherein;the user responsibility data comprises sensitivity assessment data characterizing a security risk associated with data to which the user has access; and the plurality of users within the organization comprises users having access to data associated with different security risks; processing, by the data processing apparatus and for each user;
(i) the user activity data describing the actions taken by the user by use of the user device over the period of time and the risks associated with the actions, and (ii) the user responsibility data describing the responsibilities of the user within the organization, using a risk model to generate a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device; anddetermining, by the data processing apparatus, for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation, wherein the user-specific remedial action includes presenting a message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A system comprising:
-
one or more user devices; and a remote server, comprising one or more computing devices and connected to the one or more user devices over a network, that performs operations comprising; receiving, at the remote server and for each of a plurality of users within an organization from the one or more user devices;
(i) user activity data describing a plurality of actions taken by the user by use of a user device over a period of time and risks associated with the actions, and (ii) user responsibility data describing responsibilities of the user within the organization, wherein;the user responsibility data comprises sensitivity assessment data characterizing a security risk associated with data to which the user has access; and the user responsibility data describes different responsibilities for different users within the organization; processing, by the remote server and for each user;
(i) the user activity data describing the actions taken by the user by use of the user device over the period of time and the risks associated with the actions, and (ii) the user responsibility data describing the responsibilities of the user within the organization, using a risk model to generate a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device; anddetermining, by the remote server, for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation, wherein the user-specific remedial action includes presenting a message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user. - View Dependent Claims (17)
-
-
18. A non-transitory computer readable medium storing instructions that when executed by one or more computing devices, cause the one or more computing devices to perform operations comprising:
-
receiving, at the one or more computing devices and for each of a plurality of users within an organization;
(i) user activity data describing a plurality of actions taken by the user by use of a user device over a period of time and risks associated with the actions, and (ii) user responsibility data describing responsibilities of the user within the organization, wherein;the user responsibility data comprises sensitivity assessment data characterizing a security risk associated with data to which the user has access; and the user responsibility data describes different responsibilities for different users within the organization; processing, by the one or more computing devices and for each user;
(i) the user activity data describing the actions taken by the user by use of the user device over the period of time and the risks associated with the actions, and (ii) the user responsibility data describing the responsibilities of the user within the organization, using a risk model to generate a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device; anddetermining, by the one or more computing devices, for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation, wherein the user-specific remedial action includes presenting a message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user. - View Dependent Claims (19)
-
Specification