Anonymizing Access Data for Application Server Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Application servers are vulnerable to unauthorized access due to the constant evolution of tools and strategies used by perpetrators, making it challenging to predict, detect, and prevent such access effectively.
Innovation Solution
An anonymization method is implemented where access data is collected by application servers, anonymized, and stored in a remote computing environment's access data warehouse. Identifying keys are retained securely within the application environment, allowing organizations to reidentify their own data while maintaining security, enabling analysis to identify abnormal usage patterns and generate protective measures without compromising other organizations' data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access data is collected and analyzed to identify unauthorized access patterns, then the ability to detect and prevent security threats is improved, but the risk of compromising organizational data security and privacy increases
Solution Approach 1:
The patent introduces anonymization as an intermediary process between data collection and analysis. Access data is transformed into anonymized form that preserves behavioral patterns while removing direct identifiers. This intermediary layer enables security analysis of multi-organization data without exposing sensitive organizational information, thus improving detection capability while maintaining data security.
Solution Approach 2:
The patent creates anonymized copies of access data that retain the essential characteristics needed for pattern recognition and threat detection. These copies can be shared and analyzed across organizations without compromising the original sensitive data. The anonymized copies serve as substitutes that enable collective security improvement while preserving individual organizational privacy.
2Measurement precision
If anonymized access data from multiple organizations is aggregated and analyzed, then pattern recognition and trend identification improve, but the system complexity and data management overhead increase
Solution Approach 1:
The patent segments the data management process into distinct components: local anonymization at each organization, secure transmission of anonymized data, centralized aggregation in a data warehouse, and analysis. This segmentation allows each component to be optimized independently and reduces overall system complexity while enabling sophisticated multi-organization pattern analysis.
Solution Approach 2:
The patent performs anonymization as a preliminary action before data leaves individual organizations. By pre-anonymizing data at the source, the system eliminates the need for complex secure access controls and authentication mechanisms during data sharing and analysis phases, significantly reducing data management complexity while preserving analytical capabilities.
3Adaptability or versatility
If identifying keys are retained securely within the application environment, then data reidentification capability is maintained, but the security risk of key compromise increases
Solution Approach 1:
The patent extracts the identifying keys from the analysis environment and retains them only in secure locations within individual organization environments. The analysis system operates exclusively on anonymized data without access to keys. This extraction separates the sensitive key management function from the data analysis function, maintaining reidentification capability when needed while eliminating the risk of key compromise during analysis operations.
Data Source
AI summary
A method and platform for preventing unauthorized access to an application server comprises collecting access data associated with an organization, anonymizing the access data, creating identifying keys which allow the anonymized access data to be matched to its associated users, storing the identifying keys at a secure location associated with the organization, transferring the anonymized access data to an access data warehouse, and performing an analysis on the anonymized access data. The access data warehouse can be maintained in a cloud computing environment, and may aggregate anonymized access data from a plurality of organizations. An organization may detect abnormal usage patterns by analyzing its usage data and the anonymized usage data of further organizations, and may use the abnormal usage patterns to predict future events, for example intrusion attempts. An organization can automatically generate protective measures against potential threats associated with abnormal usage patterns.


