Enterprise Data Access Anomaly Detection via Baseline Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in tracking and protecting proprietary and confidential data due to increased remote network access and the bring-your-own-device model, lacking visibility into data access and flow, especially on mobile devices, which makes it difficult to detect and prevent data leakage.

Innovation Solution

Implementing an enterprise data access management system that monitors and logs access to enterprise data on multiple client computers, performs statistical analysis to establish access baselines, detects anomalous access, and alerts administrators to prevent data leakage, while generating reports for data flow patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If organizations allow remote network access and bring-your-own-device model to increase productivity and convenience, then employee productivity and user convenience are improved, but data security and control over confidential information deteriorate

Engineering Contradiction:
Improveemployee productivityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system continuously monitors data access events and provides feedback by comparing actual access patterns against established baselines. When anomalies are detected (such as unexpected access locations, times, or frequencies), the system generates alerts to security administrators, enabling real-time response to potential security threats while maintaining normal productive operations

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary monitoring system that sits between users and enterprise data. This intermediary layer (comprising log collection agents, baseline generation modules, and anomaly detection components) transparently tracks data access without interfering with legitimate work activities, allowing productive remote access while maintaining security oversight

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If organizations implement comprehensive data access monitoring to detect and prevent data leakage, then data security is improved, but system complexity and implementation difficulty worsen

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically collecting access logs from multiple sources, generating baselines from historical data, detecting anomalies, and producing reports without requiring manual configuration or intervention. The baseline generation and anomaly detection occur automatically, reducing the operational burden on security teams

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges multiple monitoring functions into a unified system that collects logs from various data sources (file systems, applications, network traffic), consolidates them into centralized logs, and processes them through a single anomaly detection engine. This integration simplifies the overall system architecture compared to implementing separate monitoring solutions for each data access vector

Inventive Principle:
Principle #5Merging (Combining)

3Loss of information

If organizations track data access and flow across multiple devices to prevent leakage, then visibility into data access is improved, but difficulty in detecting and preventing leakage worsens due to lack of tools

Engineering Contradiction:
Improvevisibility into data accessVSAvoiddifficulty in detecting anomalous patterns
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The system replaces manual security monitoring and analysis with automated computational processes. Instead of security personnel manually reviewing access logs or using basic monitoring tools, the patent employs automated baseline generation algorithms and anomaly detection systems that continuously analyze access patterns, significantly improving the ability to detect subtle malicious activities across distributed devices

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent enhances detection capability by analyzing access patterns across multiple dimensions simultaneously - temporal (time-based patterns), spatial (location-based patterns), and behavioral (user action patterns). By establishing baselines that incorporate multiple dimensions of normal behavior, the system can detect anomalies that would be invisible when examining single-dimensional metrics alone

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9298914B1Enterprise data access anomaly detection and flow tracking
Publication Date: 2016.03.29 CA TECH INC
  • US9298914B1 patent drawing
  • US9298914B1 patent drawing
  • US9298914B1 patent drawing

AI summary

Anomalous access activity is detected and managed. Access of enterprise data on multiple client computers is monitored and logged. The resulting log information identifies accessed units of enterprise data and corresponding access context. Log information concerning access of specific units of data on multiple client computers is received over a period of time and amalgamated. Statistical analysis is performed on amalgamated log information, thereby determining access baselines for data over the time period. Received log information concerning access of a specific unit of data on a specific client computer is compared to corresponding access baseline(s). Responsive to the comparison indicating that the access deviates from a baseline in excess of a threshold, the access is classified as being anomalous. Alerts are automatically output in response to detecting anomalous data access. Reports documenting data access activity on multiple client computers over time are generated, based on amalgamated log information.