Graph Database Security Policy Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing environments face challenges in rapidly storing and accessing large volumes of data in real-time to effectively respond to data security risks, which hinders the ability of analytical tools to provide timely insights and mitigate potential threats.

Innovation Solution

The method involves using a graph database to store and analyze data, where entities and events are represented as vertices and edges, allowing for the prediction of risks and generation of alerts based on risk indicators and scores, enabling real-time policy evaluation and action triggering to mitigate security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If large volumes of data are stored and accessed for real-time security analysis, then the ability to detect and respond to security risks is improved, but the speed of data access and processing deteriorates due to the complexity of managing large datasets

Engineering Contradiction:
Improvesecurity risk detection capabilityVSAvoiddata access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the security analysis system into multiple specialized components: graph database for structured entity relationships, machine learning models for risk prediction, and rule engines for policy evaluation. Each component handles specific data types and operations, enabling parallel processing and improving overall system speed while maintaining comprehensive security analysis capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer between data storage and analysis that includes data preprocessing, feature extraction, and caching mechanisms. This intermediary layer transforms raw data into optimized formats for rapid querying and analysis, significantly improving data access speed without compromising the depth of security risk detection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data is collected and analyzed for accurate risk prediction, then the precision of risk assessment is improved, but the time required for analysis increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-processing data during ingestion, pre-computing risk scores for known entities, and pre-establishing relationship graphs. This advance preparation enables the system to deliver accurate risk assessments in real-time by eliminating the need for complex computations during critical analysis moments

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically adjusts analysis parameters such as data sampling rates, model complexity levels, and query depth based on risk thresholds and resource availability. This allows the system to maintain high accuracy for critical risks while reducing analysis time for lower-priority events, effectively balancing precision and speed

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11704364B2Evaluation of security policies in real-time for entities using graph as datastore
Publication Date: 2023.07.18 CITRIX SYSTEMS INC
  • US11704364B2 patent drawing
  • US11704364B2 patent drawing
  • US11704364B2 patent drawing

AI summary

A method for policy-based analytics includes retrieving, from a graph database, first data representing a first entity in a computing environment, a second entity in the computing environment, and an event associated with the first entity and the second entity; predicting, according to a risk indicator model, a risk associated with the first entity based at least in part on the event; and updating the graph database to include second data representing the risk and a risk indicator. The first and second entities are stored as properties of a first vertex and a second vertex, respectively, and the event is stored as a property of an edge between the first vertex and the second vertex. The risk indicator is stored as a property of a third vertex. The risk is stored as a property of an edge between the first vertex and the third vertex.