Collaboration System Risk Assessment via Shared Link Event Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing collaboration systems lack effective techniques for calculating and reporting risks associated with cross-enterprise document sharing, particularly when anonymous users are involved, leading to increased vulnerability and data loss risks.
Innovation Solution
The implementation of techniques that capture and analyze events on shared objects to distill sharing events into an interactive threat assessment tool, enabling administrators to monitor and report collaboration system risks effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cross-enterprise document sharing is enabled with anonymous users, then accessibility and collaboration versatility are improved, but security vulnerability and data loss risk increase
Solution Approach 1:
The system continuously monitors access events to shared documents and provides feedback to administrators through risk calculations and reports. This feedback mechanism enables real-time detection of suspicious activities and informed decision-making regarding document access permissions, thereby maintaining security while preserving collaboration versatility.
Solution Approach 2:
An intermediary risk assessment system is introduced between the document sharing mechanism and the security monitoring layer. This intermediary component analyzes access patterns, calculates risks, and provides recommendations, effectively mediating between the need for broad access and security requirements.
2Reliability
If comprehensive monitoring of anonymous user actions is implemented, then risk detection capability is improved, but system complexity and processing requirements increase
Solution Approach 1:
The system extracts and focuses monitoring on specific risk indicators rather than analyzing all document access events uniformly. By identifying and prioritizing critical risk factors (such as unusual access patterns, unauthorized modifications, or access from unknown locations), the system achieves effective risk detection without proportionally increasing overall system complexity.
Solution Approach 2:
The system dynamically adjusts monitoring parameters based on the document type, user profile, and access context. Rather than applying a fixed complex monitoring approach, the system adapts its analysis depth and parameters to the specific situation, reducing unnecessary processing complexity while maintaining high risk detection capability where needed.
3Measurement precision
If detailed analysis of sharing events is performed, then threat assessment accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The threat assessment process is segmented into multiple stages: initial risk filtering, detailed analysis of suspicious events, and final threat assessment. This segmentation allows the system to perform quick preliminary assessments on most events and reserve detailed analysis only for potentially threatening activities, thereby improving accuracy for critical cases without unnecessarily increasing overall processing time.
Solution Approach 2:
The system applies partial analysis to the majority of routine access events, performing only the necessary minimal checks. Detailed thorough analysis is applied selectively only to events that trigger risk thresholds or show anomalous patterns. This partial action approach maintains sufficient threat assessment accuracy for most scenarios while significantly reducing total computational resource consumption and processing time.
Data Source
AI summary
Methods, systems, and computer program products for a content management system. Embodiments operate within or in conjunction with such a content management system. The content management system stores content objects for access by various collaborators, including extra-system collaborators. A user of the content management system configures extra-enterprise shared link URLs that permit the extra-system collaborators to access shared content objects over an Internet connection. A shared link event graph data structure is formed based on access requests over the extra-enterprise shared link URLs. An interactive user interface module is generated by processing a shared link report query over the shared link event graph data structure to select a subject set of the extra-enterprise shared link URLs, and to generate a data set of the interactive user interface module based at least in part on results from the query. A user interacts with the interactive user interface module to generate insights.


