Data Flow Security Analysis via Sequence Deviation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security approaches fail to attribute data interactions to business processes and provide context on whether these interactions are permitted or sanctioned by the enterprise, making it difficult for data security management professionals to manage and prioritize data security risks effectively.

Innovation Solution

A system that determines and monitors data flow configurations across multiple processing nodes, identifying potential security issues by comparing expected and observed sequences, and provides actionable indicators of risk through data flow analysis and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If data flows are gathered and managed to understand risks, then data security assessment capability is improved, but resource intensity increases

Engineering Contradiction:
Improvedata security assessment capabilityVSAvoidresource intensity
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by establishing expected data flow configurations and sequences before monitoring actual data flows. This allows the system to proactively identify deviations and potential security issues without requiring intensive real-time analysis of all data flows, thereby improving assessment capability while managing resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates simplified representations or models of data flow configurations (expected sequences) that can be stored and compared against actual data flows. This copying approach enables efficient risk assessment by comparing actual flows against pre-defined models rather than analyzing every raw data interaction from scratch, reducing resource intensity while maintaining assessment precision.

Inventive Principle:
Principle #26Copying

2Measurement precision

If data interactions are monitored to detect behavioral anomalies, then detection capability is improved, but context about business processes is lost

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidbusiness process context
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system incorporates feedback by comparing actual data flow sequences against expected sequences and providing context about whether deviations represent genuine security risks or legitimate business process variations. This feedback mechanism preserves business process context while maintaining anomaly detection capability by explaining the significance of detected deviations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system introduces an intermediary layer that maps raw data interactions to business process contexts. This intermediary translates technical data flow events into business-relevant information, preserving context about sanctioned versus unsanctioned interactions while maintaining the ability to detect anomalies through sequence comparison.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If expected sequences of processing nodes are defined and monitored, then security issue identification is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity issue identificationVSAvoiddata flow configuration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex task of security monitoring into manageable components: defining expected sequences for specific data flows, monitoring actual sequences, and comparing them. This segmentation allows the system to focus on specific data flows and sequences rather than attempting to monitor all system activity simultaneously, improving security identification while managing complexity through modular configuration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10198582B2Method and apparatus for data security analysis of data flows
Publication Date: 2019.02.05 IOR ANALYTICS LLC
  • US10198582B2 patent drawing
  • US10198582B2 patent drawing
  • US10198582B2 patent drawing

AI summary

A method and apparatus useful for data risk monitoring and management includes configuration and analysis of data flows to identify and assess risk and compliance to various regulatory standards and business practices. The evaluation of monitored data flows are then further used to identify potential security risks based on deviation from expected flows or compliant handling methods.