Forensic Analysis System Using Virtual Profiles for Data Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies and organizations face challenges in providing open access to information while protecting sensitive data, as data breaches remain common despite increased regulation, leading to revenue loss, brand damage, and litigation.

Innovation Solution

A forensic analysis system that generates structured representations of unstructured information from various sources, processes search terms, and creates virtual profiles to identify suspicious or illegal activity, using a thesaurus to classify and rank data relevance, and alerting clients to potential breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unstructured data from multiple sources is collected and analyzed to detect data breaches, then detection capability is improved, but data volume and complexity increase making analysis more difficult

Engineering Contradiction:
Improvedata breach detection capabilityVSAvoiddata structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments unstructured data from multiple sources into structured virtual profiles organized by entity types (people, organizations, locations). Each profile is divided into standardized attributes, transforming complex heterogeneous data into manageable structured units that can be systematically analyzed for breach detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the structural parameters of unstructured data by transforming it into standardized virtual profiles with consistent attributes and formats. This parameter transformation enables uniform storage, indexing, and analysis across diverse data sources, reducing complexity while maintaining detection reliability.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If search terms are processed through multiple sources to find unstructured data, then detection coverage is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata source coverageVSAvoiddata processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-processing search terms through a thesaurus to generate structured search queries before actual data collection. Virtual profiles are pre-structured with standardized attributes, enabling rapid matching and reducing real-time processing requirements when analyzing data from multiple sources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces virtual profiles as intermediary structures between raw unstructured data and analysis queries. These profiles serve as a mediating layer that standardizes data from multiple sources, enabling efficient indexing and search without requiring direct processing of all raw data, thus reducing computational time.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If structured virtual profiles are created from unstructured data, then data organization and search efficiency are improved, but data transformation complexity increases

Engineering Contradiction:
Improvesearch efficiencyVSAvoiddata transformation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system creates universal virtual profile templates that can accommodate multiple data sources and entity types through a standardized structure. These multi-functional profiles serve as a common framework for organizing diverse data, enabling efficient search and analysis while managing transformation complexity through reuse of standardized patterns.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system applies parameter changes by transforming unstructured data into standardized virtual profiles with consistent attributes, types, and formats. This systematic parameter transformation simplifies data organization and enables efficient searching while managing complexity through automated transformation processes and standardized templates.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If the system monitors all unstructured data continuously, then breach detection reliability is improved, but system resource consumption increases

Engineering Contradiction:
Improvebreach detection reliabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts only the relevant structured information needed for breach detection from unstructured data, creating virtual profiles with specific attributes. This extraction approach maintains detection reliability by focusing on critical data elements while reducing resource consumption by processing only essential information rather than all raw data continuously.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary structuring of data into virtual profiles with standardized attributes, enabling efficient indexing and search. This pre-processing allows the system to maintain reliable breach detection by having data ready in an optimized format, reducing the need for continuous heavy processing and lowering resource consumption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9135306B2System for forensic analysis of search terms
Publication Date: 2015.09.15 KROLL INFORMATION ASSURANCE LLC
  • US9135306B2 patent drawing
  • US9135306B2 patent drawing
  • US9135306B2 patent drawing

AI summary

A “data breach” or loss of sensitive data can cause an organization to lose revenues or suffer other damages. Analyzing data to locate a breach and to identify its source, however, is difficult because the data can come from many sources in an unstructured format and, typically, there is a large amount of data to analyze. A forensic analysis system, according to one embodiment, collects unstructured data from disparate sources, like the Internet, and peer-to-per filesharing and social media networks, and generates structured representations of the data, called virtual profiles. The system forms relationships among the virtual profiles. The system uses the virtual profiles and relationships to reduce the amount of information to be analyzed while including additional information that is related for analysis. By analyzing a smaller amount of related information, a cyber forensic analyst is better able to identify a data breach or other suspicious or illegal activity.