Intrusion Detection via Asynchronous Sensors and Bayesian Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for detecting and preventing intrusions in data at rest systems are inadequate as they primarily focus on post-attack detection rather than real-time prevention and do not effectively address unauthorized access by authorized users.
Innovation Solution
A method that utilizes intrusion detection profiles with item access rules and Bayesian inference patterns to monitor and prevent unauthorized data access in real-time by adjusting user authorization and logging, incorporating sensors and an access control manager to analyze network traffic and historical data access records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network-based detection tools are used to monitor suspicious behavior, then intrusion detection capability is improved, but system performance degradation occurs
Solution Approach 1:
The patent introduces sensors as intermediary components that monitor data access operations between users and the data at rest system. These sensors capture access requests and results without becoming part of the critical data access path, enabling intrusion detection while maintaining system performance through asynchronous monitoring architecture
2Reliability
If intrusion detection profiles with access rules are implemented, then unauthorized access prevention is improved, but device complexity increases
Solution Approach 1:
The access control manager performs multiple functions: it generates intrusion detection profiles, distributes them to sensors, collects access results, evaluates violations, and updates profiles based on learned patterns. This multi-functional approach consolidates what would otherwise require separate systems, reducing overall complexity while maintaining comprehensive security
Solution Approach 2:
The system implements self-service through automated profile updates using Bayesian inference. The access control manager automatically learns from access patterns and updates intrusion detection profiles without requiring manual intervention, reducing operational complexity while improving detection accuracy over time
3Reliability
If real-time monitoring of data access operations is performed, then intrusion prevention capability is improved, but loss of time in processing increases
Solution Approach 1:
The system uses periodic evaluation where sensors collect access operations and results over time intervals, then batch them for evaluation against intrusion detection profiles. This periodic processing approach maintains real-time prevention capability while avoiding continuous monitoring overhead, reducing processing time loss
Data Source
AI summary
Systems and methods are provided for the detection and prevention of intrusions in data at rest systems such as file systems and web servers. Item requests are examined to determine if the request and/or the result violates an item access rule. If either the request or the result violates the item access rule, an access control manager is alerted and appropriate action is taken such as not complying with the item request. Embodiments of the invention also produce a scorecard to represent the severity of an intrusion threat.


