Cloud Database Query Anomaly Detection and Role Suggestion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-platform security, it is challenging for security teams to provision the right roles and permissions within a role, especially as data is consolidated and shared across multiple internal and external teams, leading to increased internal and external threats and financial liabilities from data breaches.

Innovation Solution

A computerized system comprising an atypical query engine and a role suggestion engine that analyzes and processes data access within a cloud-based database, generates user behavior fingerprints, identifies outliers, and suggests new roles within an enterprise to manage anomalous query activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is consolidated and shared across multiple teams in a single SaaS database, then data accessibility and collaboration are improved, but security risks and difficulty in provisioning appropriate roles increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidrole provisioning complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automatically analyzes query patterns and generates role recommendations without requiring manual security team intervention. The automated role provisioning system monitors data access patterns, identifies appropriate role assignments, and suggests roles to users, enabling self-service security management that scales with data consolidation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors query patterns and provides feedback through automated role recommendations. By analyzing access patterns and comparing them against security policies, the system generates feedback loops that automatically suggest role adjustments, enabling dynamic adaptation to changing data sharing requirements while maintaining security

Inventive Principle:
Principle #23Feedback

2Productivity

If automated role provisioning is implemented to manage data access, then security management efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated role provisioning system performs multiple functions within a single integrated platform: monitoring query patterns, analyzing access behaviors, generating role recommendations, and managing role assignments. This multi-functional approach consolidates what would otherwise require separate security tools and processes, improving efficiency without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically performs security management tasks including pattern analysis, role recommendation generation, and provisioning execution without requiring extensive manual configuration or intervention. This self-service capability reduces the operational burden on security teams while managing complex automated processes in the background

Inventive Principle:
Principle #25Self-service

3Measurement precision

If traditional security monitoring is used to detect anomalous query activity, then detection capability is maintained, but ability to identify and respond to threats is insufficient

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidthreat response capability
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system implements continuous feedback loops where query patterns are monitored, anomalies are detected, and automated responses are triggered. The feedback mechanism not only detects precision anomalies but also automatically responds by suggesting role adjustments or blocking suspicious access patterns, thereby improving both detection precision and response capability simultaneously

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis of query patterns to establish baseline behavior before threats occur. By pre-configuring anomaly detection thresholds and automated response protocols based on historical patterns, the system is prepared to quickly identify and respond to threats without requiring complex manual analysis when incidents occur

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12289331B2Methods and systems for locating anomalous query activity on data stores
Publication Date: 2025.04.29 THEOM INC
  • US12289331B2 patent drawing
  • US12289331B2 patent drawing
  • US12289331B2 patent drawing

AI summary

In one aspect, a computerized system for locating anomalous query activity with a cloud-based database, comprising: with an atypical query engine: analyzing and understanding data within a cloud-based database, processing all accesses to the data within cloud-based database and SAAS environment, generating a list of user that accesses a table from a location in the cloud-based database using, and capture a set of specified key statistics about the cloud-based database query; and role suggestion engine: generating a user behavior fingerprint comprising a history of the user's behavior within the cloud-based database, identifying that a user is an outlier with respect to behavior with respect to the set of specified key statistics, and suggesting a new role within an enterprise managing the cloud-based database for the user, wherein the fingerprint of the outlier user is used to generate the suggestion for the new role.