Autonomous Data Source Protection via Virtual Avatar Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex multi-component computing environments, protecting data sources often requires active involvement from central security administrators to monitor and report on activities, which can be inefficient and inconvenient for data owners.

Innovation Solution

A 'virtual' or surrogate entity, referred to as an avatar, is created with non-human user identifiers to autonomously monitor and protect data sources by recording accesses, searching for unauthorized copies, auditing for threats, and responding to actionable events, allowing data owners to define actions in an action matrix for reporting and access inhibition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central security administrator actively monitors and reports on data source activities, then security monitoring and reporting capabilities are improved, but administrative burden and operational complexity increase

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security monitoring by enabling data source owners to autonomously protect their own data sources through avatar entities. The system allows owners to define their own security policies, monitor access activities, and receive reports without requiring active involvement from central security administrators. This transfers the security monitoring function from centralized administration to decentralized self-service, reducing administrative burden while maintaining security capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the centralized security monitoring function into individual avatar entities associated with specific data sources. Each avatar independently monitors its assigned data source, allowing security monitoring to be divided into multiple autonomous units. This segmentation eliminates the need for a single centralized monitoring system and reduces the complexity burden on central administrators.

Inventive Principle:
Principle #1Segmentation

2Reliability

If centralized security administration is used to protect data sources, then security policy enforcement is improved, but response time and autonomy for data owners deteriorate

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by allowing data source owners to pre-define security policies, access rules, and response actions through avatar configurations before security events occur. The action matrix is established in advance, specifying what actions to take for various security events. When security events occur, the pre-configured policies are automatically enforced without requiring real-time administrator intervention, thus maintaining policy enforcement reliability while improving response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables data source owners to autonomously enforce security policies through their avatar entities, which automatically monitor and respond to security events based on pre-configured rules. This self-service approach eliminates the delay associated with centralized administrator response while maintaining consistent policy enforcement through automated decision-making.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual monitoring and reporting by security administrators is implemented, then security oversight is improved, but productivity and efficiency deteriorate

Engineering Contradiction:
Improvesecurity oversightVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical system of manual monitoring and reporting by security administrators with an automated computational system. Avatar entities automatically monitor data source access, detect security events, and generate reports without human intervention. This substitution of manual mechanical processes with automated computational processes maintains comprehensive security oversight while dramatically improving operational efficiency and productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables automated self-service security oversight where avatar entities independently perform monitoring, event detection, and report generation functions. This eliminates the need for security administrators to manually monitor and report on each data source, maintaining thorough security oversight while freeing up administrative resources and improving overall system productivity.

Inventive Principle:
Principle #25Self-service

4Reliability

If comprehensive access monitoring is implemented to detect security threats, then security detection capability is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by having each avatar entity focus its monitoring capabilities on its specific assigned data source rather than requiring a centralized system to monitor all data sources uniformly. Each avatar develops specialized monitoring knowledge and policies tailored to its local data source characteristics. This localized approach maintains comprehensive threat detection capability while reducing overall system complexity by distributing monitoring functions across multiple specialized units rather than one complex centralized system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10229280B2System and method to protect a resource using an active avatar
Publication Date: 2019.03.12 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10229280B2 patent drawing
  • US10229280B2 patent drawing
  • US10229280B2 patent drawing

AI summary

A data source owner in a computing system protects that source via a “virtual” or surrogate entity or “avatar.” The entity is an object whose presence in the system is human-like, and it is given the specific task of protecting the data source for the owner. The avatar is associated with (or defined by) a non-human userid that has the same accesses and privileges of all (or defined) users, user groups and other resources that have access to the data source to be protected. During an initial setup, one or more actions to be performed by the non-human userid upon an occurrence of an actionable event with respect to the data source are specified, and a “baseline” associated with the data source is determined. Following setup, a monitor process is executed under the non-human userid, and this process records one or more accesses to the data source. Periodically, or upon a given occurrence, the monitor process spawns one or more ancillary processes to determine whether an actionable event has been triggered. If the avatar's monitoring efforts indicate an actionable event (such as an access violation), an action as defined in an action matrix is taken. The action typically includes reporting to the data source owner and, optionally, a security administrator, and restricting access to the data source.