File Anomaly Detection via Violation Count Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data leakage protection technologies fail to effectively account for the risk of data leakage prior to an event, do not facilitate preventative actions, and lack comprehensive analysis of data leakage events, providing incomplete protection for classified files.
Innovation Solution
A method and system that utilize file classification information to determine violations of an access control policy by calculating a risk parameter based on the number of classified files, classification categories, unauthorized files, and unauthorized categories, enabling refined and flexible access control policy determination and comprehensive data leakage protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional data leakage protection technologies are used to prevent unauthorized access in real-time, then real-time prevention of data leaks is improved, but the ability to account for risk prior to data leaking events and facilitate preventative actions deteriorates
Solution Approach 1:
The system performs preliminary risk assessment by analyzing file classification information, unauthorized access patterns, and user behavior before actual data leakage occurs. This enables preventative actions to be taken in advance, addressing the technical contradiction by preparing protective measures beforehand rather than only reacting in real-time
2Reliability
If file classification information is analyzed to determine access control policy violations, then comprehensive data leakage protection is improved, but system complexity increases
Solution Approach 1:
The system segments the data leakage protection process into distinct functional modules: file classification information analysis, unauthorized access detection, risk parameter calculation, and access control policy violation determination. Each module handles a specific aspect of the protection mechanism, making the overall complex system more manageable and maintainable while providing comprehensive protection
Data Source
AI summary
File classification information for a set of files are obtained. The file classification information defines (1) a number of classified files within the set of files, (2) a number of classification categories associated with the classified files, (3) a number of unauthorized classified files that do not match an access privilege of a user, and (4) a number of unauthorized classification categories associated with the unauthorized classified files. A violation of an access control policy is determined based on the file classification information.


