Heuristic Data Security System with Segmented Admin Roles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional data security systems are inadequate in preventing data leakage from within an organization, as system administrators often have full access and unique user identifiers can be compromised, leading to unauthorized access to sensitive data.

Innovation Solution

A system and method for securing data on a server through heuristic analysis, where information about access attempts is recorded and analyzed to identify suspicious patterns, and the data is secured based on these analyses to prevent potential data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If system administrators are granted full access to data for system management, then system operation and maintenance become easier, but the risk of unauthorized data leakage increases

Engineering Contradiction:
Improvesystem operationVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments administrative access rights by creating separate roles (system administrator and data administrator) with distinct permission sets. System administrators can manage system operations while data administrators handle data access control, thereby maintaining operational ease while reducing data leakage risk through divided responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a data administrator who acts as a mediator between system administrators and sensitive data. This intermediary layer provides an additional control point that prevents direct unauthorized access while allowing legitimate system operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique user identifiers are used for data access control, then data security is improved, but the system becomes vulnerable to identifier compromise

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing different security measures for different data sensitivity levels. Sensitive data is protected with enhanced controls including separate administrator roles and audit logging, while non-sensitive data uses standard access control. This localized approach maintains security for critical data without over-complicating the entire system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms through audit logging that tracks data access attempts and administrator actions. This feedback loop enables detection of identifier compromise attempts and allows for real-time security adjustments, transforming static identifier-based security into a dynamic, monitorable system.

Inventive Principle:
Principle #23Feedback

3Device complexity

If traditional access control methods are used, then implementation simplicity is maintained, but effectiveness in preventing internal data leakage is insufficient

Engineering Contradiction:
Improvesystem complexityVSAvoiddata leakage prevention
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the traditional monolithic administrator role into distinct functional roles (system administrator and data administrator), creating a more complex but effective access control structure that specifically addresses internal data leakage risks while maintaining clear operational responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by establishing data classification schemes and pre-defining access control policies before data leakage incidents occur. Audit logging is also configured in advance to automatically track suspicious activities, enabling proactive rather than reactive security management.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8776252B2System, method, and computer program product for securing data on a server based on a heuristic analysis
Publication Date: 2014.07.08 MCAFEE LLC
  • US8776252B2 patent drawing
  • US8776252B2 patent drawing
  • US8776252B2 patent drawing

AI summary

A system, method, and computer program product are provided for securing data on a server based on a heuristic analysis. In use, information associated with attempts to access data on a server is recorded. Additionally, the information is heuristically analyzed. Further, the data is secured on the server based on the heuristic analysis.