Dynamic Masking for Detecting Data Intelligence Gathering in Cloud Warehouses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity approaches focus on protecting servers and endpoints, assuming data protection, but data breaches continue to grow despite increased security spending, indicating a need for a new solution to detect hiding and data intelligence gathering in data lakes and cloud warehousing.

Innovation Solution

A computerized method is implemented to detect hiding and data intelligence gathering in data lakes or cloud warehouses through a hiding and data intelligence collection analysis phase, discovery process, data gathering process, and dynamic masking operations to identify anomalies and atypical commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing cybersecurity approaches focus on protecting servers and endpoints, then server and endpoint security is improved, but data security in data lakes and cloud warehouses deteriorates as data breaches continue to grow

Engineering Contradiction:
Improveserver and endpoint securityVSAvoiddata breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data security monitoring system as an intermediary between existing security infrastructure and data lakes/cloud warehouses. This intermediary layer implements specialized monitoring for data intelligence gathering and hiding detection, allowing the system to address data-specific threats without disrupting existing server and endpoint security architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security monitoring function into specialized components: one for general server/endpoint security and another for data-specific security in lakes and warehouses. The data security module further segments monitoring into distinct processes for detecting hiding behaviors and data intelligence gathering, allowing targeted protection strategies for each security dimension.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive monitoring is implemented to detect hiding and data intelligence gathering, then data security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic masking operations that adapt based on detected anomalies and atypical commands. The monitoring system dynamically adjusts its detection strategies and masking levels based on the severity and type of detected threats, allowing comprehensive monitoring capability while managing system complexity through adaptive rather than static configurations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary analysis of commands and data access patterns to identify atypical behavior before implementing full monitoring responses. By pre-establishing baseline behaviors and preparing detection rules in advance, the system can rapidly respond to threats without requiring complex real-time analysis for every operation.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If dynamic masking operations are performed to detect anomalies and atypical commands, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies dynamic masking selectively rather than uniformly across all data operations. The system performs full anomaly detection and masking only for identified atypical commands and suspicious patterns, while allowing normal operations to proceed with minimal intervention. This partial action approach maintains high detection accuracy for threats while minimizing processing overhead for legitimate operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250124149A1Methods and systems for detecting hiding and data intelligence gathering in data lakes and cloud warehousing
Publication Date: 2025.04.17 THEOM INC
  • US20250124149A1 patent drawing
  • US20250124149A1 patent drawing
  • US20250124149A1 patent drawing

AI summary

In one aspect, a computerized method for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising: implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse; implementing a discovery process in the data lake or the cloud warehouse; implementing a data gathering process in the data lake or the cloud warehouse; and performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.