Data Object Protection Module for Breach Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional file access control systems fail to effectively prevent large-scale data breaches, particularly due to insider threats, as they become cumbersome to manage with growing user and data volumes, and often disrupt collaboration within organizations.
Innovation Solution
A Data Object Protection Module (DPM) is implemented to differentiate protection layers and utilize user-specific data object access budgets, allowing unobtrusive protection by classifying data objects as active or inactive, applying permissive or heightened protection mechanisms, and charging access costs against user budgets to detect and prevent illegitimate access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional file access control systems are implemented, then data breach prevention is attempted, but the systems become cumbersome to manage with growing user and data volumes
Solution Approach 1:
The patent extracts the access control function from complex file-level permission matrices and consolidates it into a simplified budget-based system. Instead of managing individual file permissions for each user, the system uses user-specific budgets that aggregate access rights, making management scalable and less cumbersome as data volumes grow.
Solution Approach 2:
The access control system is designed to serve multiple functions simultaneously: it provides data breach prevention, manages user access rights, and scales with organizational growth. The budget-based approach universally applies to different data types and user roles, eliminating the need for separate access control mechanisms for each scenario.
2Reliability
If conventional file access control systems are implemented, then data breach prevention is attempted, but they disrupt collaboration within organizations
Solution Approach 1:
The system changes the parameter of access control from rigid file-level permissions to flexible budget-based quotas. This allows users to access data based on their allocated budgets rather than being blocked by restrictive permission matrices, thereby maintaining collaboration while providing breach prevention through budget enforcement.
3Ease of operation
If permissive access protection is applied to active data objects, then legitimate user access is maintained, but detection of compromised insiders is reduced
Solution Approach 1:
The system continuously monitors data object access patterns and compares them against user budgets and baseline behavior. When access patterns deviate from expected norms (such as accessing inactive objects or exceeding budget allocations), the system generates feedback signals that trigger alerts, enabling detection of compromised insiders while maintaining permissive access for legitimate users.
4Reliability
If heightened protection is applied to inactive data objects, then data breach prevention is improved, but legitimate access to rarely accessed data is blocked
Solution Approach 1:
The protection level is made dynamic rather than static. The system automatically adjusts protection intensity based on data object characteristics (active vs. inactive status) and user context. Active objects receive permissive protection to maintain collaboration, while inactive objects receive heightened protection against breaches, with the ability to transition between states based on access patterns and user needs.
Data Source
AI summary
Techniques for unobtrusively protecting against large-scale data breaches over time are described. A security gateway coupled between clients and servers receives data object (DO) access requests from the clients on behalf of users of an enterprise. Each of the users is allocated a budget for each of one or more time periods. The security gateway determines an access cost for each DO access request based on characteristics of the DO request, where lower access costs are indicative expected DO access consumption for users of the enterprise, and charges the determined access cost against the budget for that user corresponding to the time period when the DO access request was received. Alert messages are transmitted based on different ones of the users exceeding their budget(s), and the transmission of the DO access requests to the data object servers is not prevented.


