Network Access Activity Categorization for Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional review analysis approaches face efficiency, accuracy, and scalability issues in identifying and certifying access-related activities, often missing or mischaracterizing important and sensitive data due to the large volume of data that needs to be examined.

Innovation Solution

A computer-implemented method for risk analysis and access activity categorization across multiple data structures, which analyzes access activity data, categorizes it into predefined review analysis categories, processes the data into corresponding data structures, generates visualizations, and facilitates access certification actions through a graphical user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a reviewer examines all access-related activity data individually, then access certification can be performed, but the reviewer may overlook or mischaracterize important and sensitive data due to the large volume of data

Engineering Contradiction:
Improveaccuracy of access certificationVSAvoidvolume of access activity data
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments access activity data into multiple categories (e.g., privileged access, sensitive data access, routine access) based on risk attributes. This segmentation allows reviewers to focus on high-risk categories while reducing the overall volume of data requiring individual examination, thereby improving accuracy without being overwhelmed by data volume.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and highlights specific high-risk access activities and sensitive data items from the large dataset. By extracting only the most critical items for reviewer attention, the system ensures that important and sensitive data is not overlooked while significantly reducing the quantity of data that requires manual review.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If a reviewer individually certifies each access instance, then access certification can be performed, but the process becomes time-consuming and less efficient

Engineering Contradiction:
Improveaccess certification reliabilityVSAvoidreview analysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting access activities into risk-based categories, the system enables reviewers to efficiently process data within each category using appropriate methods (manual review for high-risk, automated review for low-risk), thereby maintaining reliability while significantly improving productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs self-service by automatically analyzing access activity data, categorizing it by risk attributes, and generating summaries or highlights that assist reviewers. This automation handles routine tasks, allowing reviewers to focus on critical decisions and maintaining certification reliability while improving efficiency.

Inventive Principle:
Principle #25Self-service

3Loss of information

If access activity data is not categorized by risk attributes, then the data remains in its original form, but important and sensitive data can be buried in large sets of data

Engineering Contradiction:
Improveimportance of sensitive dataVSAvoiddata structure complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies segmentation by organizing access activity data into multiple structured categories based on risk attributes (e.g., data sensitivity, access privilege level). This structured segmentation prevents important and sensitive data from being buried while maintaining manageable complexity through standardized classification schemes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by assigning different levels of detail and review requirements to different data segments based on their risk characteristics. High-risk data receives enhanced attention and detailed review, while low-risk data can be processed more simply, thereby preventing information loss without uniformly increasing complexity across all data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11178180B2Risk analysis and access activity categorization across multiple data structures for use in network security mechanisms
Publication Date: 2021.11.16 EMC IP HLDG CO LLC
  • US11178180B2 patent drawing
  • US11178180B2 patent drawing
  • US11178180B2 patent drawing

AI summary

Methods, apparatus, and processor-readable storage media for risk analysis and access activity categorization across data structures for use in network security mechanisms are provided herein. An example computer-implemented method includes analyzing data, derived from a first set of data structures within a network, pertaining to items of access activity within the network; categorizing, based at least in part on the data analysis, the access activity into multiple review analysis categories; processing, based at least in part on the categorization, the analyzed data into a second set of multiple data structures corresponding to the review analysis categories; generating a visualization of the access activity categorized into the review analysis categories, wherein the visualization comprises displayed access to the second set of multiple data structures; outputting the generated visualization to a user via a GUI; and facilitating, based on user inputs via the GUI, access certification actions within the network.