Anonymization Dictionary for Cyber Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for tracking activity on computing devices fail to effectively anonymize records to protect resource identities while maintaining the ability to detect cyber-threats, leading to potential unauthorized access and data breaches.
Innovation Solution
A method and system for processing activity records by generating an anonymization dictionary that assigns anonymized identities to target entities, creating an equivalence map, and processing records to produce anonymized activity records, which can be stored and used for threat analysis without revealing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If activity records are anonymized to protect resource identities, then security and privacy are improved, but the ability to detect cyber-threats deteriorates
Solution Approach 1:
The patent introduces anonymization dictionaries and equivalence maps as intermediary structures that enable threat detection on anonymized data. These intermediaries translate between anonymized identifiers and original entities, allowing security analysis to proceed without exposing sensitive identity information, thus resolving the contradiction between privacy protection and threat detection capability
Solution Approach 2:
The patent segments the anonymization process into multiple components: detecting target entities, generating anonymization dictionaries, creating equivalence maps, and processing activity records. This segmentation allows different parts of the system to handle different aspects of the contradiction - the anonymization dictionary protects identities while the equivalence map preserves threat detection capability
2Object-generated harmful factors
If detailed activity records are maintained for threat detection, then threat detection capability is improved, but resource identity exposure and privacy risks worsen
Solution Approach 1:
The patent applies preliminary anonymization to activity records before they are stored or analyzed for threat detection. By pre-processing the data to replace identifiable entities with anonymized identifiers, the system eliminates identity exposure risks before threat analysis begins, while still maintaining the structural information needed for effective threat detection
Solution Approach 2:
The patent creates anonymized copies of activity records that preserve the operational characteristics needed for threat detection while removing sensitive identity information. These copies can be freely analyzed for threats without risking exposure of original identity data, effectively decoupling threat detection capability from identity exposure risk
Data Source
AI summary
A method for processing activity records. The method includes obtaining an activity record, and generating an anonymization dictionary. Generating the anonymization dictionary includes detecting, in the activity record, a set of target entities to be anonymized, making a determination that a resource is associated with a subset of the target entities of the set of target entities, and after making the determination, assigning an anonymized identity to the subset of target entities, and generating an anonymization identifier for each target entity in the subset of target entities to obtain a set of anonymization identifiers, each including the anonymized identity. The method further includes processing the activity record using the anonymization dictionary to obtain an anonymized activity record and storing the anonymized activity record.


