File System Object Risk Assessment via Depth and Access Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in determining the actual risk of data exposure in file systems, as existing methods rely on content categorization, which is not effective in identifying potential security breaches in real-time, especially with varying information handling systems and user access permissions.

Innovation Solution

A method that monitors file systems for risk-assessment events and determines a content-independent risk of exposure for file-system objects based on their depth in the file system and the set of users who can access them, using a combination of security settings, access analysis, and metadata, enabling real-time security auditing and reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If content categorization methods are used to secure sensitive data, then data segregation and permission assignment are improved, but the ability to perform real-time analysis of actual exposure risk deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidreal-time risk analysis capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the risk assessment into multiple independent components: file system object identification, depth calculation, user access analysis, and risk scoring. Each component processes specific attributes separately and combines results to generate comprehensive risk assessments, enabling real-time analysis without requiring full content categorization of all files.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk assessment system that sits between the file system and users. This intermediary monitors file access patterns, calculates exposure risk based on file system object attributes (depth, permissions, user sets), and provides real-time risk information without requiring direct content analysis of protected files, thus maintaining security while enabling risk visibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security methods with content categorization are used, then data protection policies are established, but the complexity of monitoring and assessing actual exposure risk increases

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity monitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the risk assessment function from content-based security systems. Instead of analyzing file contents to determine risk, the system extracts and analyzes only metadata attributes such as file system object depth, permission settings, and user access patterns. This extraction simplifies the monitoring system by removing the need for complex content analysis while maintaining protective capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameters used for security assessment from content-based attributes to structure-based attributes. Rather than categorizing files by their content sensitivity, the system uses file system object depth, permission bit settings, and user set compositions as parameters. This parameter transformation reduces monitoring complexity while providing actionable risk insights.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If content-based security categorization is implemented, then sensitive data is identified and protected, but the system cannot determine actual exposure risk in real-time

Engineering Contradiction:
Improvedata protectionVSAvoidexposure risk assessment
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements dynamic risk assessment that continuously updates exposure risk measurements based on current file system state. The system calculates real-time risk scores by dynamically analyzing the intersection of user access sets, file system object depths, and permission configurations. This dynamic approach provides precise, up-to-date exposure risk measurements rather than static content-based categorizations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes a feedback loop where risk assessment results are continuously generated and fed back to security administrators. The system monitors file access events, recalculates exposure risk based on current user permissions and file system structure, and provides feedback on actual risk levels. This feedback mechanism enables precise measurement of exposure risk by continuously comparing intended access patterns against actual file system configurations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9760713B1System and method for content-independent determination of file-system-object risk of exposure
Publication Date: 2017.09.12 QUEST SOFTWARE INC
  • US9760713B1 patent drawing
  • US9760713B1 patent drawing
  • US9760713B1 patent drawing

AI summary

In one embodiment, a method is performed by a computer system comprising computer hardware. The method includes monitoring a file system for risk-assessment events. The method further includes, responsive to a real-time determination of at least one risk-assessment event, determining a content-independent risk of exposure for a file-system object associated with the risk-assessment event. The determining of the content-independent risk of exposure is based, at least in part, on a depth of the file-system object in the file system and a set of users who can access the file-system object.