Anonymization Dictionary for Cyber Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for tracking activity on computing devices fail to effectively anonymize records to protect resource identities while maintaining the ability to detect cyber-threats, leading to potential unauthorized access and data breaches.

Innovation Solution

A method and system for processing activity records by generating an anonymization dictionary that assigns anonymized identities to target entities, creating an equivalence map, and processing records to produce anonymized activity records, which can be stored and used for threat analysis without revealing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If activity records are anonymized to protect resource identities, then security and privacy are improved, but the ability to detect cyber-threats deteriorates

Engineering Contradiction:
Improvesecurity and privacy protectionVSAvoidthreat detection capability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces anonymization dictionaries and equivalence maps as intermediary structures that enable threat detection on anonymized data. These intermediaries translate between anonymized identifiers and original entities, allowing security analysis to proceed without exposing sensitive identity information, thus resolving the contradiction between privacy protection and threat detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the anonymization process into multiple components: detecting target entities, generating anonymization dictionaries, creating equivalence maps, and processing activity records. This segmentation allows different parts of the system to handle different aspects of the contradiction - the anonymization dictionary protects identities while the equivalence map preserves threat detection capability

Inventive Principle:
Principle #1Segmentation

2Object-generated harmful factors

If detailed activity records are maintained for threat detection, then threat detection capability is improved, but resource identity exposure and privacy risks worsen

Engineering Contradiction:
Improvethreat detection capabilityVSAvoididentity exposure risk
Core Design Contradiction:
Object-generated harmful factorsVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anonymization to activity records before they are stored or analyzed for threat detection. By pre-processing the data to replace identifiable entities with anonymized identifiers, the system eliminates identity exposure risks before threat analysis begins, while still maintaining the structural information needed for effective threat detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates anonymized copies of activity records that preserve the operational characteristics needed for threat detection while removing sensitive identity information. These copies can be freely analyzed for threats without risking exposure of original identity data, effectively decoupling threat detection capability from identity exposure risk

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10387667B2Method and system for anonymizing activity records
Publication Date: 2019.08.20 DTEX SYSTEMS INC
  • US10387667B2 patent drawing
  • US10387667B2 patent drawing
  • US10387667B2 patent drawing

AI summary

A method for processing activity records. The method includes obtaining an activity record, and generating an anonymization dictionary. Generating the anonymization dictionary includes detecting, in the activity record, a set of target entities to be anonymized, making a determination that a resource is associated with a subset of the target entities of the set of target entities, and after making the determination, assigning an anonymized identity to the subset of target entities, and generating an anonymization identifier for each target entity in the subset of target entities to obtain a set of anonymization identifiers, each including the anonymized identity. The method further includes processing the activity record using the anonymization dictionary to obtain an anonymized activity record and storing the anonymized activity record.