Cloud User Reputation Analysis for Data Exposure Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, businesses face challenges in ensuring that employee access settings for data objects do not inadvertently expose sensitive information to unauthorized users, as existing systems lack practical means to enforce desired privacy levels.

Innovation Solution

A reputation analysis system that collects and analyzes user behavior data from cloud computing environments to determine exposure characteristics, applying rules to assess user reputation and generate notifications for remedial actions to mitigate excessive data object exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employees are allowed to independently modify access settings for data objects, then ease of operation is improved, but data security deteriorates due to potential excessive exposure

Engineering Contradiction:
Improveemployee ability to modify access settingsVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors user behavior and automatically adjusts access settings based on reputation scores. When a user exhibits risky behavior patterns, the system provides feedback by restricting their ability to modify settings or by automatically tightening access controls, thus preventing data exposure while maintaining operational ease for trustworthy users

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically changes access control parameters based on user reputation metrics. Users with high reputation scores retain full ability to modify settings, while users with low scores have their modification capabilities restricted or require additional approval, effectively adapting security parameters to individual user risk profiles

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If access settings are restricted to prevent data exposure, then data security is improved, but ease of operation deteriorates as employees cannot independently manage their data

Engineering Contradiction:
Improvedata exposure preventionVSAvoidemployee autonomy in managing data
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of user behavior patterns and establishes reputation scores before security restrictions are applied. By proactively identifying at-risk users through behavioral analysis, the system can prevent data exposure issues before they occur, rather than imposing blanket restrictions on all users

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Security restrictions are applied locally to individual users based on their specific reputation scores and behavior patterns, rather than uniformly across all employees. This allows the system to maintain data security for at-risk users while preserving full operational autonomy for trustworthy users

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If the system monitors and analyzes user behavior to determine reputation, then data security is improved through better control, but device complexity increases

Engineering Contradiction:
Improvedata exposure controlVSAvoidreputation analysis system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The reputation analysis system automatically collects behavior data, analyzes patterns, calculates reputation scores, and adjusts access settings without requiring manual intervention from security administrators. The system serves itself by continuously monitoring and adapting, reducing operational complexity despite the sophisticated analysis performed

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The reputation analysis system serves multiple functions: it monitors user behavior, analyzes security risks, calculates reputation scores, communicates with users, and automatically adjusts access controls. By consolidating these diverse functions into a single integrated system, the patent reduces overall device complexity compared to having separate systems for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Object-affected harmful factors

If the system generates notifications and enforces remedial actions, then data security is improved through compliance enforcement, but ease of operation deteriorates due to additional constraints on users

Engineering Contradiction:
Improveprivacy policy complianceVSAvoiduser workflow continuity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies remedial actions selectively based on the severity and frequency of policy violations. For minor or first-time violations, the system may issue warnings or notifications without imposing immediate restrictions. For repeated or severe violations, progressively stronger remedial actions are applied, balancing compliance enforcement with minimal disruption to legitimate user workflows

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11962660B2Determination of user reputation regarding data object exposure in cloud computing environments
Publication Date: 2024.04.16 PALO ALTO NETWORKS INC
  • US11962660B2 patent drawing
  • US11962660B2 patent drawing
  • US11962660B2 patent drawing

AI summary

User reputation regarding exposure of data objects in a cloud computing environment is determined. Behavioral information, which indicates behavior of a user for a cloud computing environment corresponding to one or more data objects in the cloud computing environment that are associated with the user, is analyzed. Based on analyzing the behavior information, a plurality of characteristics for the user that indicate exposure of the data object(s) associated with the user is determined. Each of the plurality of characteristics reflects the behavior of the user pertaining to the one or more data objects. Based on compliance of the plurality of characteristics with corresponding ones of a plurality of rules, a reputation of the user for exposing data objects in the cloud computing environment is determined. The reputation of the user is indicated to an entity with which the user is associated.