Insider Attack Policy Framework for Data Access Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies lack effective real-time monitoring and protection mechanisms against insider intrusions in enterprise repositories, as they rely on outdated methods that fail to detect sophisticated behavioral changes in data access patterns, leading to significant corporate risks and financial losses.

Innovation Solution

A policy specification framework that uses a declarative grammar to define insider attack signatures, enabling real-time monitoring and mitigation through user interrogation, disconnect, and privilege de-provisioning, capturing temporal and relative changes in data access properties to prevent unauthorized data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional anomaly detection methods are used to monitor data access patterns, then the system can detect deviations from learned sequences, but the effectiveness decreases over time as content changes and similarity-based learning becomes less accurate

Engineering Contradiction:
Improvedetection accuracyVSAvoideffectiveness over time
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent transitions from similarity-based detection to statistical parameter analysis, monitoring specific access parameters (time, frequency, volume, pattern) against learned statistical models. This allows detection to adapt to content changes while maintaining accuracy through continuous statistical learning rather than fixed similarity thresholds.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system dynamically updates statistical models of normal access behavior as content changes over time. Rather than using static similarity measures, the system continuously adapts its detection parameters to reflect evolving content characteristics, maintaining effectiveness despite content changes.

Inventive Principle:
Principle #15Dynamics

2Difficulty of detecting and measuring

If policy languages are used to specify security policies, then external intrusion problems can be addressed, but insider intrusions remain difficult to detect due to authenticated access

Engineering Contradiction:
Improveinsider intrusion detectionVSAvoidsecurity monitoring
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent segments access monitoring into multiple independent dimensions: user identity, access time, data volume, access patterns, and content characteristics. By analyzing each dimension separately and looking for statistical anomalies across dimensions, the system can detect insider intrusions that would be invisible to traditional single-point monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces statistical learning models as an intermediary between raw access logs and intrusion detection. These models translate authenticated access behavior into risk assessments by comparing observed patterns against learned normal behavior, enabling detection of insider threats without compromising legitimate access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If simple binary matching is used to characterize authorized access, then the system is simple to implement, but sophisticated insider intrusions cannot be detected

Engineering Contradiction:
Improveaccess management systemVSAvoidinsider attack detection
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent adds multiple analytical dimensions to access monitoring: temporal patterns, volumetric characteristics, frequency distributions, and sequence analysis. By transforming simple binary access logs into multi-dimensional statistical data, the system gains the ability to detect sophisticated intrusions while maintaining implementation simplicity through standardized statistical techniques.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8880893B2Enterprise information asset protection through insider attack specification, monitoring and mitigation
Publication Date: 2014.11.04 WORKDAY INC
  • US8880893B2 patent drawing
  • US8880893B2 patent drawing
  • US8880893B2 patent drawing

AI summary

The present invention provides a policy specification framework to enable an enterprise to specify a given insider attack using a holistic view of a given data access, as well as the means to specify and implement one or more intrusion mitigation methods in response to the detection of such an attack. The policy specification provides for the use of “anomaly” and “signature” attributes that capture sophisticated behavioral characteristics of illegitimate data access. When the attack occurs, a previously-defined administrator (or system-defined) mitigation response (e.g., verification, disconnect, de-provision, or the like) is then implemented.