Community-Based Data Security Learning Component

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Database security analyzers within individual enterprises have limited capabilities due to their isolation, which restricts their ability to learn and detect security incidents effectively, as they only analyze local data access patterns, thereby reducing overall data security.

Innovation Solution

Implementing a community-based data security system that leverages information from multiple database security analyzers across enterprises to enhance learning and security incident detection capabilities, using a community-based data security learning component that generates security parameters and learning hints based on shared data access information and metadata.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If database security analyzers operate in isolation within individual enterprises, then device complexity and operational independence are maintained, but security incident detection capability and learning effectiveness are limited

Engineering Contradiction:
Improvesecurity incident detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple isolated database security analyzers into a unified community-based system where analyzers from different enterprises share data access information and security knowledge. This combining approach enables enhanced detection capability by aggregating security insights across enterprises while maintaining the functional independence of individual analyzers through standardized communication protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a community-based data security learning component as an intermediary that facilitates information exchange between database security analyzers of different enterprises. This intermediary manages the sharing of data access information and security parameters, enabling improved detection capability without requiring direct integration between all analyzers, thus controlling system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If database security analyzers analyze only local data access patterns, then operational simplicity and data privacy are maintained, but learning effectiveness and detection accuracy are reduced

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation sharing limitation
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the information sharing process into controlled components where database security analyzers share only anonymized data access patterns and security parameters with the community learning component, which then provides aggregated insights back to individual analyzers. This segmentation enables improved detection accuracy through broader data analysis while maintaining data privacy and controlling information loss.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a feedback mechanism where the community-based learning component receives data access information from multiple analyzers, processes it to identify security patterns, and returns refined security parameters and detection insights to the individual analyzers. This feedback loop enhances detection accuracy by incorporating collective learning while preserving the independence of local analysis operations.

Inventive Principle:
Principle #23Feedback

3Reliability

If database security analyzers operate independently without knowledge sharing, then data privacy and operational independence are preserved, but overall data security and collective learning are compromised

Engineering Contradiction:
Improveoverall data securityVSAvoidlearning capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal community-based learning component that serves multiple functions: collecting data access information from various enterprises, analyzing security patterns across the community, generating unified security parameters, and distributing these parameters back to individual analyzers. This multi-functionality enhances overall data security through collective intelligence while maintaining the adaptability of individual analyzers to their specific enterprise environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11328076B2Community-based data security
Publication Date: 2022.05.10 IMPERVA INC
  • US11328076B2 patent drawing
  • US11328076B2 patent drawing
  • US11328076B2 patent drawing

AI summary

A method by one or more electronic devices implementing a system for providing community-based data security, where the system is communicatively coupled to a plurality of database security analyzers, where each of the plurality of database security analyzers is configured to analyze data accesses to one or more databases associated with that database security analyzer. The method includes obtaining, for each of the plurality of database security analyzers, learning metadata generated by that database security analyzer, generating security parameters based on the learning metadata generated by the plurality of database security analyzers, and providing the security parameters to one or more of the plurality of database security analyzers to cause the one or more of the plurality of database security analyzers to apply the security parameters when analyzing data accesses to detect security incidents.