Dynamic Access Thresholds for Sensitive Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in managing user permissions for sensitive data, particularly with unstructured resources, as permissions can change over time, leading to a gradual increase in the number of users with access, which may pose a security risk without being promptly identified.
Innovation Solution
A computer-implemented method and system that identifies sensitive resources, establishes an accessibility threshold for permissions, monitors changes in user permissions, and performs security actions when access surpasses the threshold to protect the data from exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user permissions are broadly granted to facilitate collaboration and resource sharing, then productivity and ease of operation improve, but security risk and reliability deteriorate as the number of users with access increases over time
Solution Approach 1:
The system establishes an accessibility threshold in advance that defines the maximum number of users permitted to access a resource. This preliminary action prevents permission drift before it occurs by automatically detecting when the user count exceeds the threshold and triggering corrective security actions, thus maintaining security while allowing collaborative access within safe limits
Solution Approach 2:
The system continuously monitors the number of users with permission to access resources and compares this count against the pre-established accessibility threshold. When the threshold is exceeded, the system provides feedback by triggering security actions such as notifications or automatic permission revocations, creating a closed-loop control mechanism that maintains security while enabling collaboration
2Reliability
If permission monitoring is implemented continuously to detect security risks, then reliability and security protection improve, but device complexity and computational resources increase
Solution Approach 1:
The system applies monitoring selectively rather than uniformly across all resources. Accessibility thresholds are established on a per-resource basis, allowing the organization to focus intensive monitoring on high-value sensitive resources while using simpler access controls for less critical resources, thus reducing overall system complexity while maintaining security for critical assets
Solution Approach 2:
The system changes the parameter being monitored from detailed individual permission changes to a aggregate user count metric. By tracking only the number of users with access permissions rather than monitoring every permission modification event, the system achieves effective security monitoring with reduced computational overhead and simpler implementation
3Reliability
If accessibility thresholds are set low to maintain security, then reliability improves, but productivity and ease of operation worsen due to restricted resource access
Solution Approach 1:
The system enables dynamic adjustment of accessibility thresholds based on resource sensitivity and organizational needs. Thresholds can be modified over time as business requirements change, allowing the system to adapt between more restrictive and more permissive states. This dynamic capability ensures security thresholds remain appropriate while minimizing impact on productivity
Data Source
AI summary
The disclosed computer-implemented method for protecting sensitive data against data loss may include (1) identifying a resource comprising sensitive data, (2) establishing, for the resource, an accessibility threshold that indicates a limit on permissions to access the resource, (3) monitoring how the permissions to access the resource drift over time by tracking changes in users' permissions to access the resource, (4) detecting, while tracking the changes in users' permissions to access the resource, that access to the resource has surpassed the accessibility threshold, and (5) in response to detecting that the access to the resource has surpassed the accessibility threshold, performing a security action to protect the sensitive data from potentially being exposed. Various other methods, systems, and computer-readable media are also disclosed.


