Adaptive Data Asset Discovery via Real-Time Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security approaches are inadequate in adapting to varying user behaviors and data asset values, leading to sub-optimal security responses, as they often apply the same policies uniformly without considering the specific risks associated with different user interactions and data access operations.

Innovation Solution

A method and system that capture data streams from user interactions, identify data asset discovery operations, generate data asset indices, and determine applicable security policies in real-time to assess and manage risks dynamically, using endpoint agents and security analytics systems to provide adaptive security oversight.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional uniform security policies are applied to all user behaviors, then security administration is simplified, but security effectiveness deteriorates due to inability to adapt to varying risks

Engineering Contradiction:
Improvesecurity policy management complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on real-time risk assessment. The system continuously monitors user behavior, data asset sensitivity, and contextual factors to dynamically modify security controls, transitioning from static uniform policies to adaptive risk-based policies that optimize both security effectiveness and operational efficiency

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security policy parameters based on risk assessment results. By evaluating multiple parameters including user role, data sensitivity classification, and behavior patterns, the system adjusts security policy parameters such as access restrictions, monitoring intensity, and approval requirements to match the actual risk level of each operation

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive data asset discovery operations are performed, then security coverage is improved, but system resource consumption and processing time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial scanning by focusing security discovery operations only on data assets and user behaviors that meet specific risk criteria. Instead of scanning all data assets uniformly, the system selectively applies discovery operations to high-risk targets identified through preliminary risk assessment, reducing resource consumption while maintaining effective security coverage

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system segments data assets into different sensitivity categories and applies differentiated discovery operations to each segment. By classifying data assets into sensitivity levels and tailoring discovery operations to each category, the system optimizes resource allocation and avoids unnecessary processing of low-risk assets

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If real-time risk assessment is implemented for data asset discovery operations, then security response adaptability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity response adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary risk assessment by pre-classifying data assets into sensitivity categories and pre-defining risk evaluation rules. This preliminary preparation enables real-time risk assessment to proceed efficiently by leveraging pre-computed classifications and predefined criteria, reducing the complexity of real-time decision-making while maintaining high adaptability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary risk assessment layer between data asset discovery operations and security policy enforcement. This intermediary layer evaluates risk based on multiple factors and translates complex risk analysis into simplified policy decisions, reducing system complexity while improving adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10628591B2Method for fast and efficient discovery of data assets
Publication Date: 2020.04.21 FORCEPOINT LLC
  • US10628591B2 patent drawing
  • US10628591B2 patent drawing
  • US10628591B2 patent drawing

AI summary

A method, system and computer-usable medium for performing a data asset discovery security operation, comprising: capturing a stream of data resulting from interactions between a user and a device; identifying an occurrence of a data asset discovery operation in the stream of data; generating a data asset index corresponding to a data asset associated with the occurrence of the data asset discovery operation; and, determining whether a data asset security policy is applicable to the data asset associated with the occurrence of the data asset discovery operation.