Big Data Security Gap Analysis System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for Big Data environments are limited to point security measures, failing to provide comprehensive security coverage and are often complex to implement, with overlapping functionalities that make it difficult to select an optimum set of solutions for comprehensive security.

Innovation Solution

A system and method for implementing and managing information security in Big Data environments that involves obtaining user inputs related to the environment and business requirements, converting them into security requirements, selecting and implementing security controls based on a security reference architecture, and comparing existing controls to identify and implement missing security measures, thereby enhancing existing security mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple point security solutions are implemented to address specific security needs, then security coverage is improved, but device complexity and overlapping functionalities increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomplexity of security solutions
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security architecture into distinct layers (infrastructure layer, data layer, application layer) and functional components (security agents, management server, policy engine). This segmentation allows each component to have a specific, non-overlapping responsibility, thereby improving security coverage while managing complexity through structured organization rather than through multiple overlapping point solutions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security management server implements a universal platform that handles multiple security functions including policy generation, compliance monitoring, vulnerability assessment, and incident response across all layers of the Big Data environment. This multi-functional approach replaces multiple specialized point solutions with a single comprehensive system that provides end-to-end security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security controls are implemented across all layers, then security coverage is improved, but implementation time and cost increase

Engineering Contradiction:
Improvecomprehensive security coverageVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically discovering the Big Data environment architecture, identifying security requirements, and pre-generating compliance policies before actual security implementation. The security agents are deployed in advance to collect baseline information, enabling the management server to pre-compute security policies and reduce on-site implementation time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security management system implements self-service capabilities through automated environment discovery, policy generation, and compliance monitoring. The security agents autonomously collect data from Hadoop, MapReduce, and other Big Data components, and the management server automatically generates and updates security policies without requiring manual configuration, thereby significantly reducing implementation and maintenance time.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If existing security controls are compared with required controls, then security gaps are identified, but the process becomes complex due to overlapping functionalities

Engineering Contradiction:
Improvegap identification accuracyVSAvoidcomplexity of comparison process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by performing gap analysis at each specific layer (infrastructure, data, application) and for each specific security control category rather than attempting a monolithic comparison. The system evaluates security controls locally at each component level (HDFS, MapReduce, YARN) and aggregates results, which simplifies the comparison process while maintaining high precision in identifying gaps.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security management server acts as an intermediary that standardizes the comparison process between existing security controls and required controls. It receives security state information from agents, compares it against compliance policies, and generates gap analysis reports. This intermediary layer abstracts the complexity of the comparison process and provides a unified interface for gap identification across all security layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If point security solutions are used for specific security needs, then specific security requirements are met, but overall security integration and management become difficult

Engineering Contradiction:
Improveability to address specific security needsVSAvoidease of security management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges multiple point security solutions into a unified security management platform that covers infrastructure, data, and application layers. The security agents on each component merge local security information into a centralized view managed by the security management server, which coordinates policy enforcement across all components. This merging maintains the ability to address specific security needs at each layer while providing centralized management that simplifies overall security operations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3065077B1Gap analysis of security requirements against deployed security capabilities
Publication Date: 2020.04.08 TATA CONSULTANCY SERVICES LTD
  • EP3065077B1 patent drawingFigure 1
  • EP3065077B1 patent drawingFigure 2A
  • EP3065077B1 patent drawingFigure 2B

AI summary

Embodiments for providing security to Big Data of an organization are described. In one example, security related inputs are received from a user and are converted into security requirement. Thereafter, a security policy template is identified from plurality of pre-defined security policy templates based on security reference architecture and the security requirement. The security policy template represents a plurality of security controls. Thereafter, one or more security controls are selected from the security controls based on the security requirement. Further, one or more existing security controls implemented in Big Data environment are identified. Thereafter, the selected security controls are compared with the existing security controls for determining a security control that is not implemented in the Big Data environment. Subsequently, the security control is implemented in the Big Data environment to provide security to the Big Data of the organization.