Data Breach Simulation Using Exposure Matrix Compression

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective tools for security analysts to accurately simulate and model the impact of data breaches in distributed databases, making it difficult to identify vulnerabilities and determine optimal protection schemes that minimize the impact of a breach while maximizing enterprise security at minimal costs.

Innovation Solution

A method and apparatus for data breach simulation and analysis that generates an exposure matrix to assess the impact of regulations on data stores, iteratively applies data compression algorithms to generate approximation matrices, and simulates data breach and mitigation scenarios to determine the overall impact and optimal protection strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual what-if scenarios are applied to enterprise data for data protection assessment, then data protection scenarios can be identified, but the process is time and labor-intensive and does not guarantee optimal results

Engineering Contradiction:
Improvedata protection scenario identification accuracyVSAvoidscenario analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates virtual copies of the enterprise data environment through data models that replicate the structure, relationships, and characteristics of actual data stores. These models serve as testbeds for simulating data breaches and evaluating protection scenarios without manipulating real data, thereby achieving accurate assessment results while significantly reducing time and resource requirements compared to manual analysis.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary data modeling and vulnerability assessment before actual data breaches occur. By pre-establishing data models, identifying potential attack vectors, and evaluating protection scenarios in advance, the system enables organizations to understand their risk profile and implement appropriate security measures before real threats materialize, rather than reacting after incidents occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive data protection is implemented across all data stores, then enterprise security is maximized, but costs increase significantly

Engineering Contradiction:
Improveenterprise security levelVSAvoiddata protection costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies different protection measures to different data stores based on their specific characteristics, sensitivity, and risk profiles. Rather than implementing uniform protection across all data, the system identifies high-value or high-risk data stores that require enhanced security and applies targeted protection strategies to those specific locations, while using lighter measures for lower-risk data, thereby optimizing the balance between security and cost.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system evaluates multiple protection scenarios with varying parameters such as encryption levels, access control strictness, and monitoring intensity. By changing these protection parameters across different data stores based on their risk profiles, the organization can achieve adequate security coverage while avoiding the excessive costs of maximum protection applied uniformly everywhere.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If data compression algorithms are applied to exposure matrices, then computational efficiency improves, but approximation accuracy may be reduced

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidimpact assessment accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies data compression to exposure matrices by retaining only the most significant components or features that contribute to impact assessment. Rather than compressing away all detailed information, the system keeps the critical data elements necessary for accurate risk evaluation while removing redundant or less important information, achieving a balance between computational efficiency and assessment accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10771347B2Method, apparatus, and computer-readable medium for data breach simulation and impact analysis in a computer network
Publication Date: 2020.09.08 INFORMATICA CORP
  • US10771347B2 patent drawing
  • US10771347B2 patent drawing
  • US10771347B2 patent drawing

AI summary

A system, method and computer-readable medium for data breach simulation and impact analysis in a computer network, including generating an exposure matrix corresponding to data stores connected to the computer network, the exposure matrix storing a correspondence between regulations and an exposure of each data store the regulations, generating approximation matrices from the exposure matrix by iteratively applying a data compression algorithm to the exposure matrix, each successive iteration of the data compression algorithm being configured to more closely approximate the exposure matrix than a previous iteration of the data compression algorithm, simulating a plurality of data breach and mitigation scenarios on the plurality of data stores based at least in part on the plurality of approximation matrices to determine an overall impact of each data breach and mitigation scenario, determining an optimal data breach and mitigation scenario in the plurality of data breach and mitigation scenarios.