IP Library Granted Patent US 7,673,147
Granted Patent B2
US 7,673,147 · App. 10/950,069 · Granted Mar 2, 2010

Real-time mitigation of data access insider intrusions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,673,147
App. No.
10/950,069
Granted
Mar 2, 2010
Kind
B2
Abstract

The present invention provides a policy specification framework to enable an enterprise to specify a given insider attack using a holistic view of a given data access, as well as the means to specify and implement one or more intrusion mitigation methods in response to the detection of such an attack. The policy specification provides for the use of “anomaly” and “signature” attributes that capture sophisticated behavioral characteristics of illegitimate data access. When the attack occurs, a previously-defined administrator (or system-defined) mitigation response (e.g., verification, disconnect, de-provision, network re-routing, or the like) is then implemented.

Claims (17)

1. A machine-implemented method of protecting an enterprise information asset against insider attack, comprising:

specifying an insider attack policy filter that defines (a) a given action that a trusted user may attempt to take with respect to a given enterprise information asset stored on a given enterprise data server, and (b) a given risk mitigation response that is to be performed upon detection of the given action, wherein the policy filter is based on a policy specification language;

monitoring a trusted user's given data access with respect to the given enterprise data server;

analyzing the given data access against the policy filter;

determining whether the trusted user's given data access is indicative of the given action as specified by the policy filter;

if the trusted user's given data access is indicative of the given action as specified in the policy filter, performing the given mitigation response as specified in the policy filter.

2. The machine-implemented method as described in claim 1 wherein the given mitigation response interrogates the trusted user for at least one additional credential.

3. The machine-implemented method as described in claim 2 wherein the trusted user is interrogated directly and in real-time.

4. The machine-implemented method as described in claim 2 wherein the trusted user is interrogated indirectly and in real-time.

5. The machine-implemented method as described in claim 2 wherein the trusted user is interrogated indirectly and in other than real-time.

6. The machine-implemented method as described in claim 1 wherein the given mitigation response disconnects the trusted user from the enterprise data server.

7. The machine-implemented method as described in claim 1 wherein the given mitigation response de-provisions the trusted user from a given enterprise resource that otherwise enables the trusted user to obtain access to the enterprise information asset.

8. The machine-implemented method as described in claim 7 wherein the given enterprise resource is a directory.

9. The machine-implemented method as described in claim 1 wherein the given mitigation response initiates a forensic evaluation of prior data accesses of the trusted user.

10. The machine-implemented method as described in claim 1 wherein the forensic evaluation is performed to facilitate determination of a given mitigation response.

11. The machine-implemented method as described in claim 1 wherein the given mitigation response quarantines the trusted user.

12. The machine-implemented method as described in claim 11 wherein the trusted user is quarantined by network re-routing.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2025
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: WORKDAY, INC.
Reel/Frame 073051/0916 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 17, 2018
From: IBM INTERNATIONAL GROUP B.V.
To: IBM INTERNATIONAL C.V.
Reel/Frame 047794/0779 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 17, 2018
From: IBM INTERNATIONAL C.V.
To: IBM ATLANTIC C.V.
Reel/Frame 047794/0927 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 17, 2018
From: IBM ATLANTIC C.V.
To: IBM TECHNOLOGY CORPORATION
Reel/Frame 047795/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2012
From: NETEZZA CORPORATION
To: IBM INTERNATIONAL GROUP B.V.
Reel/Frame 027642/0172 →
REQUEST FOR CORRECTED NOTICE OF RECORDATION TO REMOVE PATENT NO. 7.415,729 PREVIOUSLY INCORRECTLY LISTED ON ELECTRONICALLY FILED RECORDATION COVERSHEET, RECORDED 12/23/2011 AT REEL 027439, FRAMES 0867-0870-COPIES ATTACHED Recorded Jan 19, 2012
From: TIZOR SYSTEMS, INC.
To: NETEZZA CORPORATION
Reel/Frame 027614/0356 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2011
From: TIZOR SYSTEMS, INC.
To: NETEZZA CORPORATION
Reel/Frame 027439/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2011
From: TIZOR SYSTEMS, INC.
To: NETEZZA CORPORATION
Reel/Frame 027232/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2011
From: MOGHE, PRATYUSH; SMITH, PETER T.
To: TIZOR SYSTEMS, INC.
Reel/Frame 027206/0515 →