Access Record Gateway for Network Security Breach Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security applications in corporate networks face challenges in accurately tracking and managing user access records, particularly in terms of time information, which is crucial for detecting and responding to security breaches and unauthorized access.
Innovation Solution
A system and method involving an access record gateway and datastore that acquire, record, and update user access information, including time information, to create and manage access records, which can be queried by security applications for breach detection and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security applications monitor and detect security breaches in real-time, then network security detection capability is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent introduces an access record gateway as an intermediary component between the access server and security applications. This gateway collects, normalizes, and stores access records in a standardized format, allowing security applications to query historical access information without directly interfacing with the access server. This mediation reduces system complexity by centralizing data collection and providing a uniform interface for security monitoring.
Solution Approach 2:
The system pre-collects and stores access records including user identification, access time, and access status information in an access record datastore before security incidents occur. When security breaches are detected, security applications can immediately query pre-existing access records to identify affected users and devices, eliminating the need for real-time data collection during incident response and reducing overall system complexity.
2Measurement precision
If access record gateway stores detailed user access information including time data, then breach investigation accuracy is improved, but data storage requirements and query complexity increase
Solution Approach 1:
The access record gateway segments access information into structured records with specific fields including user identification, access time, and access status. Each access record is divided into discrete components that can be independently stored and queried. This segmentation allows the system to store only essential information needed for breach investigation rather than raw unstructured data, optimizing storage efficiency while maintaining investigation accuracy.
Solution Approach 2:
The system transforms raw access data into standardized parameters with specific formats and structures. Access time is recorded as structured temporal data, user identification is normalized to consistent formats, and access status is coded with standardized values. This parameterization enables efficient storage and indexing, reducing data storage requirements while improving query accuracy for breach investigations.
3Measurement precision
If security applications query access records with multiple parameters, then breach detection precision is improved, but query processing time and system load increase
Solution Approach 1:
The access record gateway pre-processes and indexes access records with all relevant parameters including user identification, access time, and access status before queries are executed. This preliminary indexing organizes data in a manner that enables rapid retrieval based on multiple parameters simultaneously. When security applications perform breach detection queries, the pre-indexed structure allows the system to quickly filter and retrieve relevant records without processing entire datasets, reducing query processing time while maintaining high detection precision.
4Loss of information
If access record gateway updates access records with activity information, then information accuracy is improved, but data processing overhead and update frequency requirements increase
Solution Approach 1:
The access record gateway implements a feedback mechanism where the access server notifies the gateway of access activity changes such as login, logout, and status changes. When the access server detects an access event, it sends a notification to the gateway, which then updates the corresponding access record with current information. This event-driven feedback approach ensures information accuracy by maintaining synchronized data without requiring continuous polling or frequent updates, thereby reducing data processing overhead and energy consumption compared to continuous synchronization methods.
Data Source
AI summary
Systems and methods of managing access records of user access to a secure data network include an access record gateway and an access record datastore; the access record gateway being in communication with an access server of the secure data network; and the access record datastore being in communication with the access record gateway. The access record gateway acquires user access information, such as time information; records the user access information in at least one access record; and stores the at least one access record in the access record datastore. The access record gateway also acquires user access activity information, such as user access termination information, and updates previously recorded user access information with the user access activity information. The at least one access record includes a plurality of sub-records, selected from a list including a user information sub-record, a network information sub-record, and a time information sub-record. The system may include a security application in communication with the access record gateway to query for an access record satisfying the security query parameter(s).


