Effective Access Permission Monitoring for Offline File Forensics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing enterprise data face challenges in efficiently monitoring and detecting anomalies, such as ransomware attacks, due to the complexity of file systems and the lack of real-time permission updates, making it difficult to obtain accurate forensic information and manage access control.

Innovation Solution

A data analytics system that provides near-real-time analytics and alerts by centralizing data from distributed file servers, using metadata and event-based analytics to monitor access permissions and generate reports, even when file servers are offline, through a cloud-hosted service that integrates with virtualized file systems and virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If file servers are taken offline to limit damage during security incidents, then security risk is reduced, but ability to obtain forensic information is lost

Engineering Contradiction:
Improvesecurity riskVSAvoidforensic information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system pre-collects and stores permission information in a historical database before security incidents occur. This allows forensic analysis to continue even when file servers are taken offline, as the necessary permission data has already been captured and archived for later investigation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of permission information from the live file server and stores them in a separate historical database. This copying mechanism ensures that forensic information is preserved independently of the file server's operational state, allowing analysis to proceed when the original system is offline

Inventive Principle:
Principle #26Copying

2Measurement precision

If real-time permission monitoring is implemented across distributed file servers, then anomaly detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential permission information from complex file system operations and monitors these specific data points. By focusing on permission changes rather than all file operations, the system achieves effective anomaly detection while avoiding the complexity of monitoring every system event

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces a permission information database as an intermediary layer between the distributed file servers and the monitoring system. This mediator consolidates permission data from multiple sources into a unified structure, simplifying the monitoring architecture while maintaining comprehensive detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If permission information is updated continuously from distributed file servers, then data accuracy is improved, but data collection overhead increases

Engineering Contradiction:
Improvepermission information accuracyVSAvoiddata collection overhead
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system updates permission information at periodic intervals rather than continuously monitoring every change. This periodic collection approach maintains sufficient data accuracy for forensic analysis while significantly reducing the overhead of constant data synchronization across distributed servers

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system collects permission information at a frequency that exceeds the minimum needed for basic functionality but is less than continuous monitoring. This partial action approach ensures adequate data accuracy for security investigations while avoiding the excessive overhead of real-time continuous collection

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20260064865A1Data analytics systems with effective access permission monitoring
Publication Date: 2026.03.05 NUTANIX INC
  • US20260064865A1 patent drawing
  • US20260064865A1 patent drawing
  • US20260064865A1 patent drawing

AI summary

Data analytics methods are described herein which may provide permission management to one or more file servers in a virtualized file system. Example methods may include receiving, at an analytics system, an access control list of a storage item in a file server responsive to a change to data in the storage item, the access control list including access control entries; evaluating effective access of the access control list based on an active directory; detecting a change in either one or more permissions or one or more memberships of the storage item in the active directory; re-evaluating, at the analytics system, the effective permission of the access control list upon detecting the change; storing the effective permission in a data repository of the analytics system; and accessing the effective permission at the data repository during a time the file server is unavailable to the analytics system.