Automatic Storage Access Control via Biclustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security policies in organizations with diverse access control models are inefficient and impractical, leading to unacceptably high proportions of users having incorrect access privileges and issues with redundant access rights and orphan accounts, as existing techniques lack effective tools for managing user access rights and ensuring data protection amidst organizational changes.

Innovation Solution

The system automatically creates and manages data security policies by monitoring and analyzing user access to storage elements, using biclustering to define user and data clusters based on access profiles, and dynamically adapting access control policies to organizational changes, with a decision assistance interface for interactive management and detection of abnormal behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review and maintenance of access control lists is used, then data security can be maintained, but the system becomes inefficient and impractical in large, complex organizations

Engineering Contradiction:
Improvedata securityVSAvoidaccess management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically monitors user access patterns and self-adjusts access control policies without manual intervention. The biclustering algorithm continuously analyzes access data and autonomously updates access control lists, eliminating the need for manual review while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous monitoring of user access patterns and uses this feedback to dynamically adjust access control policies. The biclustering algorithm processes access data in real-time and automatically modifies access rights based on observed behavior, creating a closed-loop control system.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If access control policies are made dynamic to adapt to organizational changes, then security accuracy improves, but system complexity increases

Engineering Contradiction:
Improveaccess privilege accuracyVSAvoidpolicy management system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical processes of access control list management with an automated computational system. The biclustering algorithm uses mathematical optimization to automatically determine access policies, substituting human administrative effort with algorithmic processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The biclustering algorithm serves multiple functions simultaneously: it clusters users based on access patterns, identifies appropriate access policies, detects anomalies, and updates access control lists. This multi-functional approach reduces overall system complexity by consolidating multiple security functions into a single unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If conventional access control techniques are extended to include biometrics and encryption, then security is strengthened, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity strengthVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically manages access control decisions without requiring user intervention or complex authentication processes. Access rights are dynamically adjusted based on monitored behavior patterns, eliminating the need for users to manually request or manage their own access permissions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7606801B2Automatic management of storage access control
Publication Date: 2009.10.20 VARONIS SYSTEMS INC
  • US7606801B2 patent drawing
  • US7606801B2 patent drawing
  • US7606801B2 patent drawing

AI summary

Methods and systems are provided for defining and creating an automatic file security policy and a semi-automatic method of managing file access control in organizations with multiple diverse access control models and multiple diverse file server protocols. The system monitors access to storage elements within the network. The recorded data traffic is analyzed to assess simultaneous data access groupings and user groupings, which reflect the actual organizational structure. The learned structure is then transformed into a dynamic file security policy, which is constantly adapted to organizational changes over time. The system provides a decision assistance interface for interactive management of the file access control and for tracking abnormal user behavior.