Cyber Security Image Detection for Unauthorized Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber-attacks involving unauthorized data access are complex and time-consuming to investigate, often requiring anonymization of accessed data, which is expensive and inefficient.

Innovation Solution

A system that detects suspicious operations by reviewing highlights, determines if a predefined cyber security image exists, generates a cyber security image based on sub-images, and stores it in a repository to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional investigation methods are used for unauthorized data access, then detailed analysis can be performed, but the process becomes time-consuming and expensive

Engineering Contradiction:
Improvedetection accuracyVSAvoidinvestigation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-generating cyber security images for various suspicious operations and storing them in a repository before actual security incidents occur. When a suspicious operation is detected, the system immediately compares it against the pre-existing images, eliminating the need for time-consuming real-time analysis and enabling instant identification of unauthorized access patterns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates simplified copies of security-relevant information in the form of cyber security images that capture essential characteristics of suspicious operations. These images serve as searchable representations that can be quickly compared against new operations, providing accurate detection without requiring detailed examination of the original complex data structures.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive security analysis is performed on all operations, then unauthorized access can be detected, but system performance deteriorates

Engineering Contradiction:
Improvesecurity detectionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts only the essential security-relevant features from operations and represents them as compact cyber security images. By taking out only the critical characteristics needed for security analysis rather than analyzing complete operation details, the system maintains high detection reliability while significantly reducing processing overhead and preserving system performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms complex operation data into simplified visual representations with changed parameters - converting detailed operational data into cyber security images that retain security-discriminative properties while reducing data complexity. This parameter transformation enables efficient comparison and detection without the computational burden of analyzing full operation sequences.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If manual anonymization of accessed data is performed, then investigation can proceed, but the process becomes expensive and inefficient

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing efficiency
Core Design Contradiction:
Loss of informationVSEase of manufacture

Solution Approach 1:

The system performs self-service by automatically generating cyber security images that inherently protect sensitive information while maintaining investigative value. The image generation process automatically anonymizes and abstracts accessed data without requiring manual intervention, eliminating the need for separate anonymization steps and reducing both cost and complexity of the investigation process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10708282B2Unauthorized data access detection based on cyber security images
Publication Date: 2020.07.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10708282B2 patent drawing
  • US10708282B2 patent drawing
  • US10708282B2 patent drawing

AI summary

In some examples, a system for detecting unauthorized data access can include a processor to detect a suspicious operation to be executed by the system and review a plurality of highlights corresponding to the suspicious operation. The processor can also determine that a predefined cyber security image corresponding to the highlights and the suspicious operation does not exist and generate the predefined cyber security image based on a plurality of sub-cyber security images. Furthermore, the processor can store the predefined cyber security image in a cyber security image repository and prevent the suspicious operation from being executed.