Data Security Agent Correlating User Activity with Process Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software-based security solutions fail to effectively block or eradicate all malware, leaving data vulnerable to access at the point of access, and consume significant computing resources for traffic analysis and file scanning.
Innovation Solution
A data security agent on user devices correlates user activity data with process access attempts to determine if access is initiated by a human user, reducing resource consumption by selectively granting access based on user interaction data, historic data, and command-line data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing software-based security solutions analyze traffic and scan files to detect malware, then malware detection capability is improved, but computing resource consumption increases significantly
Solution Approach 1:
The patent extracts the essential characteristic of legitimate processes (user interaction) from the complex analysis of traffic patterns and file contents. Instead of analyzing all traffic and scanning all files, the system only checks whether a process has associated user activity data, which is a simplified and more efficient verification method that reduces computing resource consumption while maintaining security effectiveness.
Solution Approach 2:
The system uses the process itself to provide security verification by checking its own user activity data associations. Each process is evaluated based on whether it has corresponding user interaction records, allowing the system to self-validate process legitimacy without requiring extensive external analysis resources.
2Reliability
If existing security solutions scan all files and analyze all traffic, then data protection is improved, but processing speed decreases
Solution Approach 1:
The patent extracts only the critical verification element (user activity data association) from the comprehensive file scanning and traffic analysis process. This selective approach checks only whether a process has corresponding user interaction records, dramatically improving processing speed while maintaining data protection through the verification of legitimate user-initiated processes.
3Measurement precision
If security solutions perform comprehensive traffic analysis and file scanning, then malware detection accuracy is improved, but resource consumption increases
Solution Approach 1:
The patent extracts the key indicator of legitimacy (user activity data association) from the comprehensive analysis of traffic patterns, file contents, and process behaviors. This focused verification method maintains high detection accuracy by identifying whether processes correspond to actual user interactions, while consuming significantly fewer computing resources compared to exhaustive scanning and analysis approaches.
Data Source
AI summary
A device may obtain user activity data associated with a plurality of processes being run by the device, where the user activity data identifies user interactions with one or more user input devices, where the plurality of processes is associated with a plurality of process identifiers, and where the user activity data is associated with the plurality of process identifiers. The device may detect an attempt, initiated by a first process having a first process identifier, to access a data file of a file system, and may compare the first process identifier and the plurality of process identifiers to determine whether the first process is associated with a first user interaction included in the user activity data, and may selectively grant the first process access to the data file based on determining whether the first process is associated with the first user interaction.


