Risk Analysis System for Proactive Data Leakage Prediction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for preventing data leakage are inadequate, as they rely on detecting incidents after they occur, rather than predicting them, and struggle to monitor interactions within secure data environments effectively, especially as organizations grow in size and complexity.
Innovation Solution
A method and system for analyzing risks associated with behavioral activities, which involves determining risk components related to individuals, assets, endpoints, and activity types, and measuring risk as a function of these components, using conditional probabilities and entity costs to predict potential undesired events and propagate risk scores based on commonalities across data files and persons.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional detection methods are used to guard against data leakage, then data breaches can be detected after they occur, but the system cannot predict data leakage events before they happen and cannot prevent them proactively
Solution Approach 1:
The system performs preliminary actions by establishing baselines of normal user behavior patterns before data leakage occurs. It continuously monitors and compares current activities against these pre-established baselines to detect anomalies that indicate potential data leakage, enabling early warning and preventive action before actual data breaches happen.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring user activities, comparing them against established baselines, and adjusting risk assessments in real-time. When anomalies are detected, the system provides feedback through alerts and notifications, enabling organizations to take corrective actions. The system also learns from detected incidents to refine its baselines and improve future detection accuracy.
2Reliability
If secure data environments are established with trusted individuals only, then data access is restricted, but it becomes difficult to monitor interactions and maintain security as organizations grow in size and complexity
Solution Approach 1:
The system enables self-service by allowing users to have their own behavioral baselines automatically established and maintained. Each user's normal activity patterns are learned and stored as their personal baseline, which the system uses for continuous monitoring. This eliminates the need for complex manual configuration and maintenance of security rules for each user, especially beneficial as organizations scale.
Solution Approach 2:
The system dynamically changes monitoring parameters based on user roles, data sensitivity levels, and contextual factors. Instead of applying uniform complex monitoring rules to all users, the system adjusts monitoring intensity and parameters according to individual user profiles and current risk contexts, simplifying the overall monitoring system while maintaining comprehensive security coverage.
3Measurement precision
If risk assessment considers multiple factors including user behavior, data sensitivity, and contextual elements, then comprehensive risk analysis is achieved, but the computational complexity and data processing requirements increase significantly
Solution Approach 1:
The system segments risk assessment into multiple independent components: user behavior analysis, data sensitivity evaluation, contextual factor assessment, and anomaly detection. Each component processes specific types of data independently and produces separate risk scores, which are then combined to form the overall risk assessment. This modular approach improves measurement precision while managing computational complexity through division of labor.
Data Source
AI summary
The present invention provides a method, system and computer program product for analyzing risks, for example associated with potential data leakage. Risk for activities may be measured as a function of risk components related to: persons involved in the activity; sensitivity of data at risk; endpoint receiving data at risk; and type the activity. Risk may account for the probability of a leakage event given an activity as well as a risk cost which reflects the above risk components. Manually and/or automatically tuned parameters may be used to affect the risk calculation. Risk associated with persons and/or files may be obtained by: initializing risk scores of persons or files based on a rule set; adjusting the risk scores in response to ongoing monitoring of events; identifying commonalities across persons or files; and propagating risk scores based on the commonalities.


