Behavioral risk scoring framework for performing security analytics
A system, method, and computer-readable medium are disclosed for performing behavioral risk analysis operation. The behavior risk analysis operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; observing a behavior of the entity based upon the monitoring; identifying a standardized risk factor associated with the entity; analyzing the behavior and the standardized risk factor associated with the entity; and, performing a security operation in response to the analyzing the behavior and the standardized risk factor.
1 . A computer-implementable method for performing behavioral risk analysis operation, comprising:
monitoring an entity, the monitoring observing an electronically-observable data source; observing a behavior of the entity based upon the monitoring;
identifying a security related activity associated with the entity based upon the behavior;
identifying a standardized risk factor associated with the entity, the standardized risk factor facilitating accurately portraying a risk associated with the behavior of the entity, the standardized risk factor being based upon a standardized risk model, the standardized risk model comprising a Sociotechnical and Organizational Factors for Insider Threat (SOFIT) model, the SOFIT model providing a machine computable automated risk factor;
creating an event model based upon a feature, the feature having an associated feature value;
generating a standardized risk score based upon the standardized risk factor and the event model;
analyzing the behavior, the security related activity, and the standardized risk factor associated with the entity and the standardized risk score, the analyzing identifying an insider threat associated with the security related activity based upon the standardized risk factor associated with the entity; and,
performing a security operation in response to the analyzing the behavior, the security related activity, the standardized risk factor and the standardized risk score, the security operation being performed by at least one of an endpoint device and a security analytics system.
2 . The method of claim 1 , further comprising:
generating a standardized risk score based upon the standardized risk factor; and,
using the standardized risk score when generating the risk score; and wherein, the security operation uses the standardized risk score when performing the security operation.
3 . The method of claim 2 , wherein:
the standardized risk score is based upon the standardized risk model.
4 . The method of claim 2 , further comprising:
generating a normalized risk score based upon the standardized risk factor, the normalized risk score being generated using a normalization operation, the normalization operation determining whether the behavior is normal or not normal based upon a group of user entities with similar characteristics enacting similar behaviors; and wherein,
the security operation uses the normalized risk score when performing the security operation.
5 . The method of claim 1 , wherein:
the security operation includes a continuous evaluation operation, the continuous evaluation operation providing ongoing assessment of a security risk of the entity.
6 . The method of claim 5 , wherein:
the continuous evaluation operation is performed on a recurring basis.
7 . A system comprising:
a processor;
a data bus coupled to the processor; and
a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:
monitoring an entity, the monitoring observing an electronically-observable data source;
observing a behavior of the entity based upon the monitoring;
identifying a security related activity associated with the entity based upon the behavior;
identifying a standardized risk factor associated with the entity, the standardized risk factor facilitating accurately portraying a risk associated with the behavior of the entity, the standardized risk factor being based upon a standardized risk model, the standardized risk model comprising a Sociotechnical and Organizational Factors for Insider Threat (SOFIT) model, the SOFIT model providing a machine computable automated risk factor;
creating an event model based upon a feature, the feature having an associated feature value;
generating a standardized risk score based upon the standardized risk factor and the event model;
analyzing the behavior, the security related activity, the standardized risk factor associated with the entity and the standardized risk score, the analyzing identifying an insider threat associated with the security related activity based upon the standardized risk factor associated with the entity; and,
performing a security operation in response to the analyzing the behavior, the security related activity, the standardized risk factor and the standardized risk score, the security operation being performed by at least one of an endpoint device and a security analytics system.
8 . The system of claim 7 , wherein the instructions executable by the processor are further configured for:
generating a standardized risk score based upon the standardized risk factor; and,
using the standardized risk score when generating the risk score; and wherein,
the security operation uses the standardized risk score when performing the security operation.
9 . The system of claim 8 , wherein:
the standardized risk score is based upon the standardized risk model.
10 . The system of claim 8 , wherein the instructions executable by the processor are further configured for:
generating a normalized risk score based upon the standardized risk factor, the normalized risk score being generated using a normalization operation, the normalization operation determining whether the behavior is normal or not normal based upon a group of user entities with similar characteristics enacting similar behaviors; and wherein,
the security operation uses the normalized risk score when performing the security operation.
11 . The system of claim 7 , wherein:
the security operation includes a continuous evaluation operation, the continuous evaluation operation providing ongoing assessment of a security risk of the entity.
12 . The system of claim 11 , wherein:
the continuous evaluation operation is performed on a recurring basis.
13 . A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:
monitoring an entity, the monitoring observing an electronically-observable data source; observing a behavior of the entity based upon the monitoring;
identifying a security related activity associated with the entity based upon the behavior;
identifying a standardized risk factor associated with the entity, the standardized risk factor facilitating accurately portraying a risk associated with the behavior of the entity, the standardized risk factor being based upon a standardized risk model, the standardized risk model comprising a Sociotechnical and Organizational Factors for Insider Threat (SOFIT) model, the SOFIT model providing a machine computable automated risk factor;
creating an event model based upon a feature, the feature having an associated feature value;
generating a standardized risk score based upon the standardized risk factor and the event model;
analyzing the behavior, the security related activity, the standardized risk factor associated with the entity and the standardized risk score, the analyzing identifying an insider threat associated with the security related activity based upon the standardized risk factor associated with the entity; and,
performing a security operation in response to the analyzing the behavior, the security related activity, the standardized risk factor and the standardized risk score, the security operation being performed by at least one of an endpoint device and a security analytics system.
14 . The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:
generating a standardized risk score based upon the standardized risk factor; and,
using the standardized risk score when generating the risk score; and wherein,
the security operation uses the standardized risk score when performing the security operation.
15 . The non-transitory, computer-readable storage medium of claim 14 , wherein:
the standardized risk score is based upon the standardized risk model.
16 . The non-transitory, computer-readable storage medium of claim 14 , wherein:
generating a normalized risk score based upon the standardized risk factor, the normalized risk score being generated using a normalization operation, the normalization operation determining whether the behavior is normal or not normal based upon a group of user entities with similar characteristics enacting similar behaviors; and wherein,
the security operation uses the normalized risk score when performing the security operation.
17 . The non-transitory, computer-readable storage medium of claim 13 , wherein:
the security operation includes a continuous evaluation operation, the continuous evaluation operation providing ongoing assessment of a security risk of the entity.
18 . The non-transitory, computer-readable storage medium of claim 17 , wherein:
the continuous evaluation operation is performed on a recurring basis.
19 . The non-transitory, computer-readable storage medium of claim 13 , wherein:
the computer executable instructions are deployable to a client system from a server system at a remote location.
20 . The non-transitory, computer-readable storage medium of claim 13 , wherein:
the computer executable instructions are provided by a service provider to a user on an on-demand basis.