Insider Attack Policy Framework for Data Access Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies lack effective real-time monitoring and protection mechanisms against insider intrusions in enterprise repositories, as they rely on outdated methods that fail to detect sophisticated behavioral changes in data access patterns, leading to significant corporate risks and financial losses.
Innovation Solution
A policy specification framework that uses a declarative grammar to define insider attack signatures, enabling real-time monitoring and mitigation through user interrogation, disconnect, and privilege de-provisioning, capturing temporal and relative changes in data access properties to prevent unauthorized data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional anomaly detection methods are used to monitor data access patterns, then the system can detect deviations from learned sequences, but the effectiveness decreases over time as content changes and similarity-based learning becomes less accurate
Solution Approach 1:
The patent transitions from similarity-based detection to statistical parameter analysis, monitoring specific access parameters (time, frequency, volume, pattern) against learned statistical models. This allows detection to adapt to content changes while maintaining accuracy through continuous statistical learning rather than fixed similarity thresholds.
Solution Approach 2:
The system dynamically updates statistical models of normal access behavior as content changes over time. Rather than using static similarity measures, the system continuously adapts its detection parameters to reflect evolving content characteristics, maintaining effectiveness despite content changes.
2Difficulty of detecting and measuring
If policy languages are used to specify security policies, then external intrusion problems can be addressed, but insider intrusions remain difficult to detect due to authenticated access
Solution Approach 1:
The patent segments access monitoring into multiple independent dimensions: user identity, access time, data volume, access patterns, and content characteristics. By analyzing each dimension separately and looking for statistical anomalies across dimensions, the system can detect insider intrusions that would be invisible to traditional single-point monitoring.
Solution Approach 2:
The system introduces statistical learning models as an intermediary between raw access logs and intrusion detection. These models translate authenticated access behavior into risk assessments by comparing observed patterns against learned normal behavior, enabling detection of insider threats without compromising legitimate access.
3Device complexity
If simple binary matching is used to characterize authorized access, then the system is simple to implement, but sophisticated insider intrusions cannot be detected
Solution Approach 1:
The patent adds multiple analytical dimensions to access monitoring: temporal patterns, volumetric characteristics, frequency distributions, and sequence analysis. By transforming simple binary access logs into multi-dimensional statistical data, the system gains the ability to detect sophisticated intrusions while maintaining implementation simplicity through standardized statistical techniques.
Data Source
AI summary
The present invention provides a policy specification framework to enable an enterprise to specify a given insider attack using a holistic view of a given data access, as well as the means to specify and implement one or more intrusion mitigation methods in response to the detection of such an attack. The policy specification provides for the use of “anomaly” and “signature” attributes that capture sophisticated behavioral characteristics of illegitimate data access. When the attack occurs, a previously-defined administrator (or system-defined) mitigation response (e.g., verification, disconnect, de-provision, or the like) is then implemented.


