Enterprise Data Access Anomaly Detection via Baseline Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in tracking and protecting proprietary and confidential data due to increased remote network access and the bring-your-own-device model, lacking visibility into data access and flow, especially on mobile devices, which makes it difficult to detect and prevent data leakage.
Innovation Solution
Implementing an enterprise data access management system that monitors and logs access to enterprise data on multiple client computers, performs statistical analysis to establish access baselines, detects anomalous access, and alerts administrators to prevent data leakage, while generating reports for data flow patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If organizations allow remote network access and bring-your-own-device model to increase productivity and convenience, then employee productivity and user convenience are improved, but data security and control over confidential information deteriorate
Solution Approach 1:
The system continuously monitors data access events and provides feedback by comparing actual access patterns against established baselines. When anomalies are detected (such as unexpected access locations, times, or frequencies), the system generates alerts to security administrators, enabling real-time response to potential security threats while maintaining normal productive operations
Solution Approach 2:
The patent introduces an intermediary monitoring system that sits between users and enterprise data. This intermediary layer (comprising log collection agents, baseline generation modules, and anomaly detection components) transparently tracks data access without interfering with legitimate work activities, allowing productive remote access while maintaining security oversight
2Reliability
If organizations implement comprehensive data access monitoring to detect and prevent data leakage, then data security is improved, but system complexity and implementation difficulty worsen
Solution Approach 1:
The system performs self-service by automatically collecting access logs from multiple sources, generating baselines from historical data, detecting anomalies, and producing reports without requiring manual configuration or intervention. The baseline generation and anomaly detection occur automatically, reducing the operational burden on security teams
Solution Approach 2:
The patent merges multiple monitoring functions into a unified system that collects logs from various data sources (file systems, applications, network traffic), consolidates them into centralized logs, and processes them through a single anomaly detection engine. This integration simplifies the overall system architecture compared to implementing separate monitoring solutions for each data access vector
3Loss of information
If organizations track data access and flow across multiple devices to prevent leakage, then visibility into data access is improved, but difficulty in detecting and preventing leakage worsens due to lack of tools
Solution Approach 1:
The system replaces manual security monitoring and analysis with automated computational processes. Instead of security personnel manually reviewing access logs or using basic monitoring tools, the patent employs automated baseline generation algorithms and anomaly detection systems that continuously analyze access patterns, significantly improving the ability to detect subtle malicious activities across distributed devices
Solution Approach 2:
The patent enhances detection capability by analyzing access patterns across multiple dimensions simultaneously - temporal (time-based patterns), spatial (location-based patterns), and behavioral (user action patterns). By establishing baselines that incorporate multiple dimensions of normal behavior, the system can detect anomalies that would be invisible when examining single-dimensional metrics alone
Data Source
AI summary
Anomalous access activity is detected and managed. Access of enterprise data on multiple client computers is monitored and logged. The resulting log information identifies accessed units of enterprise data and corresponding access context. Log information concerning access of specific units of data on multiple client computers is received over a period of time and amalgamated. Statistical analysis is performed on amalgamated log information, thereby determining access baselines for data over the time period. Received log information concerning access of a specific unit of data on a specific client computer is compared to corresponding access baseline(s). Responsive to the comparison indicating that the access deviates from a baseline in excess of a threshold, the access is classified as being anomalous. Alerts are automatically output in response to detecting anomalous data access. Reports documenting data access activity on multiple client computers over time are generated, based on amalgamated log information.


