Dynamic Access Policy Inoculation for Database Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information security solutions for databases are vulnerable to advanced hacking techniques and insider attacks, as they lack knowledge of database protocols and structures, and real-time monitoring systems can be evaded by malicious users with elevated privileges, allowing them to obtain information by moving between database servers.

Innovation Solution

A database access control system that dynamically updates access restriction policies across a set of database servers and their storage devices in real-time upon detection of a policy violation, using an existing database table extrusion rule to generate a new access policy and propagate it across all servers to prevent further compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If real-time monitoring systems are used to detect policy violations, then response time is improved, but malicious users with elevated privileges can still evade detection and obtain information by moving between database servers

Engineering Contradiction:
Improveresponse timeVSAvoiddetection effectiveness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent combines multiple database server monitoring into a unified system where policy violations at one server trigger immediate policy updates across all servers in the set. This merging of monitoring and response mechanisms ensures that when a violation is detected at any server, the entire system responds collectively, preventing attackers from exploiting individual server vulnerabilities by moving between them.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary action by proactively updating access policies across all database servers immediately upon detecting a policy violation at any single server. This preliminary update occurs before attackers can exploit the vulnerability at other servers, effectively inoculating the entire system against the identified threat vector in advance of potential attacks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access policies are updated dynamically across all database servers upon violation detection, then system-wide protection is improved, but policy propagation overhead increases

Engineering Contradiction:
Improvesystem-wide protectionVSAvoidpolicy propagation overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the database server system into distinct sets, where each set shares common access policies. When a policy violation is detected, the system updates policies only within the relevant set rather than forcing updates across the entire enterprise infrastructure. This segmentation reduces the scope of policy propagation and minimizes overhead while maintaining effective system-wide protection through targeted updates.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If traditional security solutions are used without database protocol knowledge, then system complexity is reduced, but detection precision deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent introduces a policy manager as an intermediary component that specializes in database protocol knowledge and security policy enforcement. This intermediary sits between the monitoring system and the database servers, providing expert-level detection capabilities without requiring complex modifications to the database servers themselves. The policy manager handles the complexity of protocol analysis and policy generation, maintaining low overall system complexity while achieving high detection precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11347871B2Dynamic cybersecurity protection mechanism for data storage devices
Publication Date: 2022.05.31 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11347871B2 patent drawing
  • US11347871B2 patent drawing
  • US11347871B2 patent drawing

AI summary

A mechanism that dynamically creates a new access policy for a set of database servers when a policy violation has been identified in a database access response issued by any database in the set. The new access policy is then propagated in real-time and instantiated across the set of database servers so as to inoculate the other database servers and pre-empt any new compromise of information based on the intruder's actions that were found to have produced the policy violation in the first instance. Thus, the approach uses a response policy violation at one database server of a set to trigger generation of a new request access policy that is then instantiated across one or more other database servers. This response policy violation-to-request access policy instantiation occurs in substantially real-time so that the intruder cannot use a prior successful access request to obtain information from other databases using a similar strategy.