Data DNA Modeling for Abnormality Detection in Access Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently tracking and analyzing vast amounts of data access requests to detect abnormalities, as the sheer volume of data overwhelms existing tracking systems, making it difficult to identify potential security threats in a timely and effective manner.

Innovation Solution

The introduction of a data DNA model that creates event and asset DNA representations to track data access, allowing for the identification of deviations and quantification of risks associated with these deviations, enabling the system to respond appropriately to potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a system tracks and collects data from millions of data access requests, then the ability to detect abnormalities improves, but the system becomes overwhelmed by the volume of data

Engineering Contradiction:
Improveabnormality detection capabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex data access monitoring task into distinct components: creating DNA representations for assets and events, comparing current DNA against stored DNA, and evaluating deviations. This segmentation allows the system to process millions of requests by breaking down the analysis into manageable, standardized steps rather than attempting to analyze all raw data simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces DNA representations as an intermediary layer between raw data access requests and abnormality detection. Instead of directly analyzing millions of raw access requests, the system converts them into standardized DNA profiles (event DNA, asset DNA, relationship DNA), which serve as compressed, comparable representations that reduce processing complexity while preserving essential security-relevant information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system collects and analyzes all data access requests, then detection accuracy improves, but the time required for analysis increases

Engineering Contradiction:
Improveabnormality detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by creating and storing DNA representations of assets, events, and relationships before actual security incidents occur. This pre-characterization allows the system to quickly compare current access requests against established baselines, enabling rapid anomaly detection without requiring time-consuming analysis of all historical data for each new request.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the essential security-relevant features from millions of data access requests by converting them into condensed DNA representations. This extraction process identifies and isolates the critical attributes needed for anomaly detection while discarding redundant information, thereby maintaining detection accuracy while significantly reducing analysis time.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If the system creates detailed DNA representations for all assets and events, then the precision of deviation detection improves, but the computational resources required increase

Engineering Contradiction:
Improvedeviation detection precisionVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by creating detailed DNA representations only for specific assets and events that are relevant to security monitoring, rather than uniformly processing all data. The system focuses computational resources on generating comprehensive DNA profiles for critical assets while using lighter-weight representations for less critical elements, optimizing the balance between detection precision and resource consumption.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10614225B2System and method for tracing data access and detecting abnormality in the same
Publication Date: 2020.04.07 DATIPHY
  • US10614225B2 patent drawing
  • US10614225B2 patent drawing
  • US10614225B2 patent drawing

AI summary

Data DNA modeling is used to represent data and the relationship this data has with other data. When an information access request from a user is detected, an asset DNA associated with the user is retrieved and analyzed against the information access request. Using the asset DNA, it can be determined whether the information access request is a normal request or a suspicious request. If the user is unknown, a generic asset DNA can be created and populated with the data from the information access request. The system checks the newly created asset DNA against other similar asset DNA to determine whether there is any abnormality associated with this newly created asset DNA.