Intrusion Detection via Asynchronous Sensors and Bayesian Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for detecting and preventing intrusions in data at rest systems are inadequate as they primarily focus on post-attack detection rather than real-time prevention and do not effectively address unauthorized access by authorized users.

Innovation Solution

A method that utilizes intrusion detection profiles with item access rules and Bayesian inference patterns to monitor and prevent unauthorized data access in real-time by adjusting user authorization and logging, incorporating sensors and an access control manager to analyze network traffic and historical data access records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-based detection tools are used to monitor suspicious behavior, then intrusion detection capability is improved, but system performance degradation occurs

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces sensors as intermediary components that monitor data access operations between users and the data at rest system. These sensors capture access requests and results without becoming part of the critical data access path, enabling intrusion detection while maintaining system performance through asynchronous monitoring architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If intrusion detection profiles with access rules are implemented, then unauthorized access prevention is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control manager performs multiple functions: it generates intrusion detection profiles, distributes them to sensors, collects access results, evaluates violations, and updates profiles based on learned patterns. This multi-functional approach consolidates what would otherwise require separate systems, reducing overall complexity while maintaining comprehensive security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service through automated profile updates using Bayesian inference. The access control manager automatically learns from access patterns and updates intrusion detection profiles without requiring manual intervention, reducing operational complexity while improving detection accuracy over time

Inventive Principle:
Principle #25Self-service

3Reliability

If real-time monitoring of data access operations is performed, then intrusion prevention capability is improved, but loss of time in processing increases

Engineering Contradiction:
Improveintrusion prevention capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses periodic evaluation where sensors collect access operations and results over time intervals, then batch them for evaluation against intrusion detection profiles. This periodic processing approach maintains real-time prevention capability while avoiding continuous monitoring overhead, reducing processing time loss

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS7594266B2Data security and intrusion detection
Publication Date: 2009.09.22 PROTEGRITY US HLDG LLC
  • US7594266B2 patent drawing
  • US7594266B2 patent drawing
  • US7594266B2 patent drawing

AI summary

Systems and methods are provided for the detection and prevention of intrusions in data at rest systems such as file systems and web servers. Item requests are examined to determine if the request and/or the result violates an item access rule. If either the request or the result violates the item access rule, an access control manager is alerted and appropriate action is taken such as not complying with the item request. Embodiments of the invention also produce a scorecard to represent the severity of an intrusion threat.