Adaptive Data Inspection System for Dynamic Cybersecurity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security tools are insufficient and limited in their capabilities and effectiveness, struggling to adapt to the increasing frequency and sophistication of cyber-attacks, and lack integration, leading to complex and costly management of data protection across modern computing networks.
Innovation Solution
A data inspection system and method that employs an Adaptive Data Protection (ADP) analytics engine and accelerator server computing devices for dynamic, policy-based management, continuously monitoring and adapting security measures through an inspection work queue, inspection class policies, and machine learning training data to apply appropriate cyber-security technologies and operations across the data lifecycle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing data security tools are used, then data protection is provided, but the tools are insufficient and limited in capabilities and effectiveness against sophisticated cyber-attacks
Solution Approach 1:
The patent implements dynamic security inspection by continuously monitoring data objects throughout their lifecycle and adapting inspection policies based on changing conditions. The system transitions from static security tools to dynamic inspection that adjusts its behavior based on real-time threat detection, data sensitivity changes, and lifecycle stage variations.
Solution Approach 2:
The system changes security inspection parameters dynamically based on data object properties, threat levels, and lifecycle stages. Different inspection policies are applied to different data objects based on their sensitivity, type, and current state, allowing the system to adapt its protective measures without a one-size-fits-all approach.
2Reliability
If comprehensive data protection is implemented, then security coverage is improved, but operational complexity and costs increase
Solution Approach 1:
The patent segments data protection into discrete inspection operations that can be independently managed and executed. Each data object can have its own inspection policy, and the system divides comprehensive security into manageable inspection tasks that are processed through a work queue system, reducing operational complexity while maintaining coverage.
Solution Approach 2:
The inspection system serves multiple functions through a unified platform: it monitors data objects, executes inspection policies, manages work queues, and adapts to changing conditions. This multi-functional approach consolidates what would otherwise require multiple separate security tools and processes, reducing operational complexity while maintaining comprehensive coverage.
3Difficulty of detecting and measuring
If continuous monitoring of data objects is performed, then security detection capability is improved, but system resource consumption increases
Solution Approach 1:
The system implements periodic inspection of data objects rather than continuous monitoring, scheduling inspections based on data lifecycle events and threat levels. The inspection work queue system processes monitoring tasks in periodic batches, allowing the system to maintain detection capability while conserving resources by not continuously analyzing all data objects at maximum intensity.
Data Source
AI summary
A system continuously stores, as machine learning data, metadata results associated with a previous cyber-attack, a previous inspection class policy definition at a time of the previous cyber-attack, and a result of a previous data protection operation taken upon indication of the previous cyber-attack; continuously monitors for a new security condition or event; detects the new security condition or event; determines an appropriate inspection class policy from a plurality of inspection class policies based on the new security condition or event; based on the determined inspection class policy and the machine learning training data, determines a specific class of inspection tool from a plurality of classes of inspection tools or a specific level of inspection from a plurality of different levels of inspection for the new security condition or event; and executes the specific class of inspection tool or the specific level of inspection using the specific class of inspection tool on a particular data object to be inspected.


