Differentiated Data Object Protection Layers for Breach Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional file access control systems fail to prevent large-scale data breaches, particularly due to insider threats, as they become cumbersome to manage with growing user and data volumes, and often disrupt collaboration within organizations.

Innovation Solution

A Data Object Protection Module (DPM) implements differentiated protection layers and user-specific data object access budgets to unobtrusively monitor and manage data access requests, classifying active and inactive data objects and charging access costs against user budgets to detect and prevent illegitimate access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional file access control systems are implemented to prevent data breaches, then security protection is provided, but the systems become cumbersome to manage and disrupt collaboration as user and data volumes grow

Engineering Contradiction:
Improvedata breach preventionVSAvoidaccess control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data objects into two distinct categories: active data objects (frequently accessed, legitimate users) and inactive data objects (rarely accessed, potential security risks). This segmentation allows the system to apply different protection strategies to each category, simplifying management while maintaining security. Active objects receive standard access controls, while inactive objects trigger additional verification processes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies differentiated protection measures based on the local characteristics of data objects. Instead of uniform access control policies, the patent implements context-specific protection: active data objects receive permissive access to maintain collaboration, while inactive data objects receive heightened scrutiny. This local quality approach optimizes both security and usability without requiring complex global management.

Inventive Principle:
Principle #3Local quality

2Reliability

If strict access controls are enforced to prevent unauthorized access, then security is improved, but legitimate collaboration and data access are disrupted

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidcollaboration efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts access control measures based on real-time data object characteristics and access patterns. When a data object transitions from active to inactive status, the system automatically applies additional verification layers. This dynamic approach ensures that legitimate collaborative access to active objects remains smooth, while potentially malicious access to inactive objects is blocked, resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary verification process that acts as a mediator between access requests and data objects. For inactive data objects, an additional verification layer is inserted that checks the legitimacy of access attempts without disrupting normal access to active objects. This intermediary mechanism provides security enhancement only where needed, preserving collaboration efficiency for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If comprehensive monitoring of all data access is implemented to detect breaches, then detection capability is improved, but system performance and user experience deteriorate

Engineering Contradiction:
Improvemalicious activity detectionVSAvoiddata access speed
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

The system applies monitoring and verification actions selectively rather than comprehensively. Instead of monitoring all data access requests uniformly, the patent implements enhanced monitoring only for inactive data objects where security risks are higher. This partial action approach maintains high detection capability for malicious activities while minimizing the performance overhead and user experience impact that would result from comprehensive monitoring of all accesses.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10382400B2Techniques for preventing large-scale data breaches utilizing differentiated protection layers
Publication Date: 2019.08.13 IMPERVA INC
  • US10382400B2 patent drawing
  • US10382400B2 patent drawing
  • US10382400B2 patent drawing

AI summary

Techniques related to preventing large-scale data breaches utilizing differentiated data object (DO) protection layers are described. A security gateway placed within a communication path between client end stations and servers receives DO access requests from the client end stations. The DOs are divided into a first subset that are currently classified as active and a second subset that are currently classified as inactive based upon a likelihood of further legitimate access to the DOs. Those of the DO access requests for DOs determined to be in the first subset are subjected to a first protection layer utilizing zero or more protection mechanisms. Those of the plurality of DO access requests for DOs not in the first subset are subjected to a second protection layer utilizing one or more protection mechanisms. Large-scale data breaches are efficiently prevented without disruption to legitimate DO access requests.