Adaptive Security Quota System for Anomalous Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security and data loss prevention policies often inconvenience users and burden administrators, leading to lax settings and increased risks of unauthorized data access, as users and administrators circumvent these policies to maintain productivity and reduce administrative burdens.

Innovation Solution

Implementing a system that manages access by using a quota of allowed anomalous actions, where attempted actions are evaluated for anomaly and security actions are taken if the count exceeds the quota, allowing for adaptive security without rigid manual settings and configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security policies with access group restrictions and firewalls are implemented, then data protection is improved, but user convenience deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on user behavior patterns. The system learns normal user behaviors and dynamically creates security rules without manual configuration, allowing security to adapt to changing conditions while maintaining user convenience. This resolves the contradiction by making security flexible rather than rigid.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically analyzing user behavior patterns and generating security policies without requiring administrator intervention. The machine learning model continuously monitors and adapts security rules based on observed behaviors, eliminating the need for manual policy creation and adjustment while maintaining strong security.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional security policies with strict firewall rules are implemented, then data protection is improved, but administrative burden increases

Engineering Contradiction:
Improvedata protectionVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically monitors user behaviors, identifies patterns, and generates security policies without administrator intervention. The machine learning model continuously adapts security rules based on observed behaviors, eliminating the need for manual policy creation, modification, and maintenance while maintaining strong security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes security parameters dynamically based on learned behavior patterns. Instead of static firewall rules, the system adjusts security thresholds, access permissions, and monitoring levels automatically based on real-time behavioral analysis, reducing administrative complexity while maintaining protection.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional security policies are implemented, then data protection is improved, but user productivity deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security system dynamically adapts to user workflows by learning normal behaviors and adjusting security interventions accordingly. The system allows high-productivity normal operations to proceed smoothly while automatically detecting and blocking anomalous activities, thus protecting data without hindering user productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements continuous feedback loops where user actions are monitored, analyzed, and used to refine security policies in real-time. This feedback mechanism ensures that security measures evolve with actual usage patterns, maintaining protection while minimizing disruptions to productive work flows.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9754109B1Systems and methods for managing access
Publication Date: 2017.09.05 GEN DIGITAL INC
  • US9754109B1 patent drawing
  • US9754109B1 patent drawing
  • US9754109B1 patent drawing

AI summary

A computer-implemented method for managing access may include (1) identifying an attempt to perform, within a computing environment, an action that involves a specific entity, (2) determining that the attempted action is anomalous for the specific entity, (3) identifying a quota of allowed anomalous actions for the specific entity, (4) determining that the attempted action causes a count of anomalous actions to exceed the quota of allowed anomalous actions, and (5) performing a security action based on the determination that the attempted action causes the count of anomalous actions to exceed the quota of allowed anomalous actions. Various other methods, systems, and computer-readable media are also disclosed.