Confidence score - Idemeum Docs

Overview

When idemeum captures an application event (either execution event for allowlisting or elevation event for elevation control), it calculates a confidence score for that application.

Confidence score determines how confident we are that allowing execution or elevation of this app is safe in our environment. For each application we look at more than 20 signals, calculate the score as a weighted sum across independent signal groups, and then present the score as a recommendation zone.

We look at the following signal categories:

Category Definition
Identity trust Capturing signals that represent the metadata of the application, including signature, verified publisher, OS binary, etc.
Execution context risk Capturing signals related to how the application executes, from what path, under what context, what is the parent process chain and more.
Prevalence and history Capturing stats on how prevalent this application is across idemeum customers and how and when it was seen in your environment.
Malware verdict Capturing signals, reputation and metadata returned by Sophos reputation API
Policy trust What rules the application matching

At the end of the scoring computation we return the confidence zone for each application:

Here is the example of the confidence score calculation:

- Signed by Microsoft
- Standard User + running from Program Files
- Low Tenant Prevalence
- CLEAN Reputation
- Publisher allow rule

=  89.5

—>  High Confidence Allow

Where confidence score is shown

Confidence score is shown in all places where you are interacting with an application event:

Here is the example of the confidence score displayed in the admin portal Events view: