Access Record Gateway for Network Security Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security applications in corporate networks face challenges in accurately tracking and managing user access records, particularly in terms of time information, which is crucial for detecting and responding to security breaches and unauthorized access.

Innovation Solution

A system and method involving an access record gateway and datastore that acquire, record, and update user access information, including time information, to create and manage access records, which can be queried by security applications for breach detection and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security applications monitor and detect security breaches in real-time, then network security detection capability is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an access record gateway as an intermediary component between the access server and security applications. This gateway collects, normalizes, and stores access records in a standardized format, allowing security applications to query historical access information without directly interfacing with the access server. This mediation reduces system complexity by centralizing data collection and providing a uniform interface for security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system pre-collects and stores access records including user identification, access time, and access status information in an access record datastore before security incidents occur. When security breaches are detected, security applications can immediately query pre-existing access records to identify affected users and devices, eliminating the need for real-time data collection during incident response and reducing overall system complexity.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If access record gateway stores detailed user access information including time data, then breach investigation accuracy is improved, but data storage requirements and query complexity increase

Engineering Contradiction:
Improvebreach investigation accuracyVSAvoiddata storage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The access record gateway segments access information into structured records with specific fields including user identification, access time, and access status. Each access record is divided into discrete components that can be independently stored and queried. This segmentation allows the system to store only essential information needed for breach investigation rather than raw unstructured data, optimizing storage efficiency while maintaining investigation accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms raw access data into standardized parameters with specific formats and structures. Access time is recorded as structured temporal data, user identification is normalized to consistent formats, and access status is coded with standardized values. This parameterization enables efficient storage and indexing, reducing data storage requirements while improving query accuracy for breach investigations.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If security applications query access records with multiple parameters, then breach detection precision is improved, but query processing time and system load increase

Engineering Contradiction:
Improvebreach detection precisionVSAvoidquery processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The access record gateway pre-processes and indexes access records with all relevant parameters including user identification, access time, and access status before queries are executed. This preliminary indexing organizes data in a manner that enables rapid retrieval based on multiple parameters simultaneously. When security applications perform breach detection queries, the pre-indexed structure allows the system to quickly filter and retrieve relevant records without processing entire datasets, reducing query processing time while maintaining high detection precision.

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If access record gateway updates access records with activity information, then information accuracy is improved, but data processing overhead and update frequency requirements increase

Engineering Contradiction:
Improveinformation accuracyVSAvoiddata processing overhead
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The access record gateway implements a feedback mechanism where the access server notifies the gateway of access activity changes such as login, logout, and status changes. When the access server detects an access event, it sends a notification to the gateway, which then updates the corresponding access record with current information. This event-driven feedback approach ensures information accuracy by maintaining synchronized data without requiring continuous polling or frequent updates, thereby reducing data processing overhead and energy consumption compared to continuous synchronization methods.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7552126B2Access record gateway
Publication Date: 2009.06.23 A10 NETWORKS INC
  • US7552126B2 patent drawing
  • US7552126B2 patent drawing
  • US7552126B2 patent drawing

AI summary

Systems and methods of managing access records of user access to a secure data network include an access record gateway and an access record datastore; the access record gateway being in communication with an access server of the secure data network; and the access record datastore being in communication with the access record gateway. The access record gateway acquires user access information, such as time information; records the user access information in at least one access record; and stores the at least one access record in the access record datastore. The access record gateway also acquires user access activity information, such as user access termination information, and updates previously recorded user access information with the user access activity information. The at least one access record includes a plurality of sub-records, selected from a list including a user information sub-record, a network information sub-record, and a time information sub-record. The system may include a security application in communication with the access record gateway to query for an access record satisfying the security query parameter(s).