×

Applying security policy based on behaviorally-derived user risk profiles

  • US 8,776,168 B1
  • Filed: 10/29/2009
  • Issued: 07/08/2014
  • Est. Priority Date: 10/29/2009
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method of establishing a security policy for a user based on risk information for that user, the method comprising:

  • receiving information about user behaviors for the user across a plurality of clients with which the user interacts;

    receiving one or more user attributes identified for the user;

    generating a user risk profile for the user based on the received information about the user behaviors and the received user attributes;

    assigning the user a user risk score based on an evaluation of the user risk profile for the user;

    identifying a plurality of user groups to which the user belongs based on the user attributes;

    assigning the user a group risk score for each of the identified user groups to which the user belongs, each group risk score calculated based on the risk scores of the users in the user group, and each group risk score indicating a likelihood of engaging in risky behaviors by the users of the user group;

    calculating a combined user risk score for the user based on the user risk score and at least one of the group risk scores; and

    automatically establishing a security policy requiring a plurality of remediative actions for the user based on the combined user risk score.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×