Risk Analysis System for Proactive Data Leakage Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for preventing data leakage are inadequate, as they rely on detecting incidents after they occur, rather than predicting them, and struggle to monitor interactions within secure data environments effectively, especially as organizations grow in size and complexity.

Innovation Solution

A method and system for analyzing risks associated with behavioral activities, which involves determining risk components related to individuals, assets, endpoints, and activity types, and measuring risk as a function of these components, using conditional probabilities and entity costs to predict potential undesired events and propagate risk scores based on commonalities across data files and persons.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional detection methods are used to guard against data leakage, then data breaches can be detected after they occur, but the system cannot predict data leakage events before they happen and cannot prevent them proactively

Engineering Contradiction:
Improvedata leakage detection capabilityVSAvoidtime to detect data leakage
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing baselines of normal user behavior patterns before data leakage occurs. It continuously monitors and compares current activities against these pre-established baselines to detect anomalies that indicate potential data leakage, enabling early warning and preventive action before actual data breaches happen.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring user activities, comparing them against established baselines, and adjusting risk assessments in real-time. When anomalies are detected, the system provides feedback through alerts and notifications, enabling organizations to take corrective actions. The system also learns from detected incidents to refine its baselines and improve future detection accuracy.

Inventive Principle:
Principle #23Feedback

2Reliability

If secure data environments are established with trusted individuals only, then data access is restricted, but it becomes difficult to monitor interactions and maintain security as organizations grow in size and complexity

Engineering Contradiction:
Improvedata access securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing users to have their own behavioral baselines automatically established and maintained. Each user's normal activity patterns are learned and stored as their personal baseline, which the system uses for continuous monitoring. This eliminates the need for complex manual configuration and maintenance of security rules for each user, especially beneficial as organizations scale.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes monitoring parameters based on user roles, data sensitivity levels, and contextual factors. Instead of applying uniform complex monitoring rules to all users, the system adjusts monitoring intensity and parameters according to individual user profiles and current risk contexts, simplifying the overall monitoring system while maintaining comprehensive security coverage.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If risk assessment considers multiple factors including user behavior, data sensitivity, and contextual elements, then comprehensive risk analysis is achieved, but the computational complexity and data processing requirements increase significantly

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidrisk analysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments risk assessment into multiple independent components: user behavior analysis, data sensitivity evaluation, contextual factor assessment, and anomaly detection. Each component processes specific types of data independently and produces separate risk scores, which are then combined to form the overall risk assessment. This modular approach improves measurement precision while managing computational complexity through division of labor.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10860711B2Method and system for analyzing risk
Publication Date: 2020.12.08 INTERSET SOFTWARE
  • US10860711B2 patent drawing
  • US10860711B2 patent drawing
  • US10860711B2 patent drawing

AI summary

The present invention provides a method, system and computer program product for analyzing risks, for example associated with potential data leakage. Risk for activities may be measured as a function of risk components related to: persons involved in the activity; sensitivity of data at risk; endpoint receiving data at risk; and type the activity. Risk may account for the probability of a leakage event given an activity as well as a risk cost which reflects the above risk components. Manually and/or automatically tuned parameters may be used to affect the risk calculation. Risk associated with persons and/or files may be obtained by: initializing risk scores of persons or files based on a rule set; adjusting the risk scores in response to ongoing monitoring of events; identifying commonalities across persons or files; and propagating risk scores based on the commonalities.