Graph Visualization for Malicious Data Access Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data access systems face challenges in efficiently managing and enforcing security policies due to complex data geometries and the difficulty in manually evaluating malicious access requests, which often result in blind spots leading to unwanted access.
Innovation Solution
The implementation of a system that uses metadata about users, data requests, and data assets to generate data access rules and policies, coupled with a graph-based visualization approach to represent user behavior and highlight risky access attempts, thereby reducing the time needed to diagnose and act on potential security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual evaluation of malicious access requests is performed, then security administrators can understand user behavior context, but the process becomes tedious and time-consuming
Solution Approach 1:
The patent replaces the manual mechanical process of reviewing text-based audit logs with an automated visual graph-based system. The graph service automatically processes metadata and generates visual representations of user behavior patterns, eliminating the need for administrators to manually parse and comprehend text logs while preserving contextual understanding through visual relationships.
Solution Approach 2:
The patent introduces a graph service as an intermediary between the audit logging system and security administrators. This intermediary automatically processes raw metadata, generates visual graph representations, and highlights risky behavior patterns, serving as a mediator that transforms complex text data into intuitive visual insights without requiring direct manual analysis.
2Loss of information
If text-based audit logs are reviewed manually, then detailed access information can be examined, but the process becomes cumbersome and laborious
Solution Approach 1:
The patent replaces the manual mechanical process of reading and analyzing text-based audit logs with an automated visual graph-based analysis system. The graph service processes metadata and generates visual representations that automatically present access request details in an easily comprehensible format, eliminating the laborious text parsing process while preserving all relevant information.
Solution Approach 2:
The patent transforms one-dimensional text-based log data into two-dimensional visual graph representations. By mapping users, data assets, and access requests as nodes and relationships in a visual graph, the system adds spatial and relational dimensions to the data, making complex access patterns immediately visible and easier to comprehend at a glance.
3Reliability
If security policies are defined manually for complex data systems, then access control can be enforced, but blind spots lead to unwanted access
Solution Approach 1:
The patent introduces a graph service as an intermediary that automatically analyzes complex data geometries and access patterns. This intermediary processes metadata about users, data requests, and data assets to generate visual representations that reveal relationships and potential blind spots in security policies, enabling administrators to identify and address unwanted access paths that would be difficult to detect manually.
Solution Approach 2:
The patent implements a feedback mechanism where the graph service continuously monitors and visualizes user behavior patterns against security policies. By highlighting risky behavior and unusual access patterns in the visual graph, the system provides real-time feedback that enables administrators to adjust and refine security policies to close blind spots and address emerging threats.
Data Source
AI summary
One example method includes monitoring a data access pattern, registering a data access request directed to data, comparing metadata associated with the data access request to a rule, based on a result of the comparing, sending a trigger to a graph service, and using information in the trigger to generate a visual representation of the data access request, wherein the visual representation indicates an extent to which the data access request is considered to constitute a potential threat to the data.


