Dynamic Access Privilege Setting for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Internet security measures are inadequate in distinguishing between regular and malicious access patterns, leading to excessive stress on servers due to noise flow from frequent access denial policies that impact legitimate users.

Innovation Solution

A method and apparatus that set access privileges by identifying IP addresses with high access frequencies, acquiring access information, determining the probability of gateway access through clustering algorithms, and selectively granting privileges based on descending probability orders to differentiate between regular and malicious access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If a policy of access denial is implemented on user addresses which perform overly frequent accesses, then malicious access can be limited, but regular users may also be impacted and server stress increases due to noise flow

Engineering Contradiction:
Improvemalicious accessVSAvoidregular user access
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating access privilege settings for different IP addresses based on their individual access patterns. Instead of a uniform access denial policy, the system dynamically assigns different privilege levels (first, second, or third privilege) to each IP address based on clustering analysis of their access behavior, allowing precise control that protects against malicious access while preserving regular user access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of access privilege dynamically based on access frequency and behavior patterns. By monitoring access frequency over time units and using clustering algorithms to identify behavioral patterns, the system adjusts privilege levels in real-time, transitioning from static access control to dynamic parameter-based differentiation that resolves the contradiction between security and accessibility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If access denial policy is applied to frequent access IP addresses, then security is improved, but server stress increases due to excessive noise flow from denying many legitimate users

Engineering Contradiction:
ImprovesecurityVSAvoidserver stress
Core Design Contradiction:
ReliabilityVSStress or pressure

Solution Approach 1:

The patent implements partial action by applying access denial selectively rather than universally. Through clustering analysis, the system identifies only those IP addresses exhibiting malicious patterns and denies access to them, while granting continued access to IP addresses with legitimate patterns. This partial application of denial policy reduces server stress from noise flow while maintaining security against actual threats.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If uniform access denial policy is implemented, then malicious access is blocked, but differentiation between regular and malicious users is lost

Engineering Contradiction:
Improvemalicious access captureVSAvoidaccess pattern differentiation
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent segments the user base into distinct groups through clustering analysis based on access patterns. By dividing IP addresses into different clusters with different privilege levels (first privilege for high-confidence regular users, second privilege for uncertain cases, third privilege for suspected malicious users), the system achieves precise differentiation between regular and malicious access patterns while maintaining effective security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10547618B2Method and apparatus for setting access privilege, server and storage medium
Publication Date: 2020.01.28 BEIJING BAIDU NETCOM SCI & TECH CO LTD
  • US10547618B2 patent drawing
  • US10547618B2 patent drawing
  • US10547618B2 patent drawing

AI summary

Disclosed are a method and an apparatus for setting an access privilege. The method includes: acquiring Internet Protocol (IP) addresses having a access frequency to a target application greater than or equal to a frequency threshold, selecting IP addresses accessing more than one applications per time unit from the IP addresses as to-be-processed IP addresses to generate a to-be-processed IP address set; acquiring access information, related to an access of a target application, of the to-be-processed IP address; acquiring a plurality of target IP addresses in the to-be-processed IP address set based on the access information, determining a probability of access through a gateway by a terminal pointed by each target IP address; and selecting a preset proportion or a preset number of target IP addresses from the plurality of target IP addresses in a descending order of the probability to set the access privilege.