Data Object Protection Module for Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional file access control systems fail to effectively prevent large-scale data breaches, particularly due to insider threats, as they become cumbersome to manage with growing user and data volumes, and often disrupt collaboration within organizations.

Innovation Solution

A Data Object Protection Module (DPM) is implemented to differentiate protection layers and utilize user-specific data object access budgets, allowing unobtrusive protection by classifying data objects as active or inactive, applying permissive or heightened protection mechanisms, and charging access costs against user budgets to detect and prevent illegitimate access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional file access control systems are implemented, then data breach prevention is attempted, but the systems become cumbersome to manage with growing user and data volumes

Engineering Contradiction:
Improvedata breach preventionVSAvoidaccess control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the access control function from complex file-level permission matrices and consolidates it into a simplified budget-based system. Instead of managing individual file permissions for each user, the system uses user-specific budgets that aggregate access rights, making management scalable and less cumbersome as data volumes grow.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access control system is designed to serve multiple functions simultaneously: it provides data breach prevention, manages user access rights, and scales with organizational growth. The budget-based approach universally applies to different data types and user roles, eliminating the need for separate access control mechanisms for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If conventional file access control systems are implemented, then data breach prevention is attempted, but they disrupt collaboration within organizations

Engineering Contradiction:
Improvedata breach preventionVSAvoiduser collaboration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system changes the parameter of access control from rigid file-level permissions to flexible budget-based quotas. This allows users to access data based on their allocated budgets rather than being blocked by restrictive permission matrices, thereby maintaining collaboration while providing breach prevention through budget enforcement.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If permissive access protection is applied to active data objects, then legitimate user access is maintained, but detection of compromised insiders is reduced

Engineering Contradiction:
Improvelegitimate user accessVSAvoidcompromised insider detection
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system continuously monitors data object access patterns and compares them against user budgets and baseline behavior. When access patterns deviate from expected norms (such as accessing inactive objects or exceeding budget allocations), the system generates feedback signals that trigger alerts, enabling detection of compromised insiders while maintaining permissive access for legitimate users.

Inventive Principle:
Principle #23Feedback

4Reliability

If heightened protection is applied to inactive data objects, then data breach prevention is improved, but legitimate access to rarely accessed data is blocked

Engineering Contradiction:
Improvedata breach preventionVSAvoidlegitimate data access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The protection level is made dynamic rather than static. The system automatically adjusts protection intensity based on data object characteristics (active vs. inactive status) and user context. Active objects receive permissive protection to maintain collaboration, while inactive objects receive heightened protection against breaches, with the ability to transition between states based on access patterns and user needs.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10404712B2Unobtrusive protection for large-scale data breaches utilizing user-specific data object access budgets
Publication Date: 2019.09.03 IMPERVA INC
  • US10404712B2 patent drawing
  • US10404712B2 patent drawing
  • US10404712B2 patent drawing

AI summary

Techniques for unobtrusively protecting against large-scale data breaches over time are described. A security gateway coupled between clients and servers receives data object (DO) access requests from the clients on behalf of users of an enterprise. Each of the users is allocated a budget for each of one or more time periods. The security gateway determines an access cost for each DO access request based on characteristics of the DO request, where lower access costs are indicative expected DO access consumption for users of the enterprise, and charges the determined access cost against the budget for that user corresponding to the time period when the DO access request was received. Alert messages are transmitted based on different ones of the users exceeding their budget(s), and the transmission of the DO access requests to the data object servers is not prevented.