Heat Map for Identifying Vulnerable Data Users

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security methods fail to preemptively identify and address vulnerabilities in users within an organization that have access to sensitive data, making them susceptible to data leaks or exploitation.

Innovation Solution

A method is developed to generate a heat map by comparing monitored data against pre-configured sensitivity parameters, generating alerts for sensitive data operations, and processing these alerts to represent associations between users and sensitive data operations, thereby enabling the implementation of targeted security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional data security methods are used, then data protection is maintained, but vulnerable users cannot be preemptively identified

Engineering Contradiction:
Improvedata protectionVSAvoiduser vulnerability identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by continuously monitoring data operations and generating alerts before actual data breaches occur. The heat map visualization enables preemptive identification of vulnerable users, allowing security measures to be implemented in advance rather than reacting after incidents occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary system consisting of the monitoring module, alert generation component, and heat map visualization layer. This intermediary framework bridges the gap between raw data operation logs and actionable security insights, making user vulnerability detectable and measurable through visual representation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If all data operations are monitored to identify sensitive data, then user vulnerability can be detected, but system complexity increases

Engineering Contradiction:
Improveuser vulnerability detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system extracts only the essential information needed for vulnerability assessment from vast amounts of data operation logs. By filtering and selecting specific data operations that warrant attention, the system reduces complexity while maintaining effective vulnerability detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The heat map visualization uses color coding to represent different levels of vulnerability and data sensitivity. This visual encoding transforms complex data into intuitive color patterns, making it easier to identify vulnerable users without requiring complex analysis of individual data operations.

Inventive Principle:
Principle #32Color changes

3Reliability

If targeted security policies are implemented based on heat map, then security effectiveness improves, but implementation difficulty increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidpolicy implementation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the organization's user base into different vulnerability categories based on the heat map visualization. This segmentation enables targeted security policies to be applied to specific user groups rather than treating all users uniformly, improving effectiveness while managing implementation complexity through structured categorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The heat map provides continuous feedback about user vulnerability patterns, enabling security policies to be adjusted and refined based on actual data. This feedback mechanism ensures that security measures remain effective and can be adapted to changing organizational needs and threat landscapes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9171171B1Generating a heat map to identify vulnerable data users within an organization
Publication Date: 2015.10.27 EMC IP HLDG CO LLC
  • US9171171B1 patent drawing
  • US9171171B1 patent drawing
  • US9171171B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for generating a heat map to identify vulnerable data users within an organization are provided herein. A method includes comparing each of one or more items of data against a set of one or more pre-configured data sensitivity parameters to detect one or more sensitive data operations within the one or more items of data, generating an alert corresponding to each of the one or more sensitive data operations, wherein the alert provides one or more items of information pertaining to the corresponding sensitive data operation, and processing the one or more alerts to generate a heat map representing an association between each of multiple users and the one or more sensitive data operations usage.