Sidecar Intruder Detection for Data Source Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security models protect data by creating a secure perimeter around organizations, but applications remain vulnerable, and managing access to data sources is complex and expensive.

Innovation Solution

Implementing a protective layer, or sidecar, at the data source that functions as a secure perimeter, validating clients through authentication, behavioral baselining, tokenization, and multifactor authentication, while intercepting and analyzing data queries to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure perimeter is created around the organization to protect data, then data security is improved, but managing access to data sources becomes complex and expensive

Engineering Contradiction:
Improvedata securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces sidecars as intermediary components deployed at data sources that act as mediators between clients and data sources. These sidecars handle authentication, authorization, and access control locally, eliminating the need for complex centralized perimeter security management while maintaining strong security controls at the data level

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security management function from the centralized perimeter security model and places it directly at the data sources through sidecars. This extraction allows security policies to be enforced locally where data resides, simplifying overall access management while improving security effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If conventional perimeter security is used to protect data, then organizational security is improved, but applications remain vulnerable to intruders

Engineering Contradiction:
Improveorganizational securityVSAvoidapplication vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing security controls specifically at the data source level rather than uniformly across the entire organization. Sidecars are deployed only where data sources are located, providing targeted protection against application-level intruders while maintaining organizational perimeter security

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary anti-action by having sidecars perform authentication and authorization checks before allowing any access to data sources. This pre-emptive security measure blocks potential intruders at the application level before they can compromise data, complementing the organizational perimeter security

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11991192B2Intruder detection for a network
Publication Date: 2024.05.21 CYRAL INC
  • US11991192B2 patent drawing
  • US11991192B2 patent drawing
  • US11991192B2 patent drawing

AI summary

A technique for intruder detection is described. Communications for a data source in an organization are intercepted and analyzed to identify an intruder detection signature. An intrusion is determined based on the intruder detection signature and an alarm generated based on the intrusion.