IP Library › Granted Patent US 12,411,964
Granted Patent B2
US 12,411,964 · App. 17/523,720 · Granted Sep 9, 2025

Securing data lakes via object store monitoring

Inventor: Ori Nakar (Givat Shemuel, IL)
Assignee: Imperva, Inc.
G06F21/6218G06F16/2358G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,411,964
App. No.
17/523,720
Granted
Sep 9, 2025
Kind
B2
Abstract

Embodiments of the present disclosure provide a method for detecting security incidents in an object store by aggregating log files generated by a monitoring program of the object store and monitoring the aggregated log data. A processing device may periodically execute database operations to access data stored in the object store. In response to each database operation, an access log set may be generated and stored in an access log storage. The processing device may periodically aggregate access log data from a plurality of access log sets currently stored in the access log storage to generate aggregated log data. The processing device may then monitor the aggregated log data over time to identify one or more security incidents of the object store.

Claims (40)

1. A method comprising:

periodically executing database operations, each database operation to access data stored in an object store;

in response to each database operation, generating an access log set and storing the access log set in an access log storage;

periodically aggregating, by a processing device, access log data from a plurality of access log sets currently stored in the access log storage to generate aggregated log data; and

monitoring the aggregated log data over time to identify one or more security incidents of the object store, wherein

the access log data from each of the plurality of access log sets corresponds to one or more access events, and includes a set of characteristics of each of the one or more access events, the set of characteristics include:

a source from which the access event originated, a user, a role, or a group who initiated the access e vent, prefixes accessed by the access event, partitions accessed by the access event, sub-partitions accessed by the access event, a time of the access event, and a number of bytes transferred during the access event, and

the access log data from each of the plurality of access log sets is aggregated based on a set of characteristics of each of the one or more access events from each of the plurality of access log sets.

2. The method of claim 1 , wherein the aggregated log data represents a single event and indicates for the single event: a source from which the single event originated, a user, role, or group who initiated the single event, prefixes accessed by the single event, partitions accessed by the single event, sub-partitions accessed by the single event, a time of the single event, and a number of bytes transferred during the single event.

3. The method of claim 2 , wherein monitoring the aggregated log data over time comprises:

identifying security incidents based on one or more of a source from which the single event originated, a user, role, or group who initiated the single event, prefixes accessed by the single event, partitions accessed by the single event, sub-partitions accessed by the single event, a time of the single event, and a number of bytes transferred during the single event.

4. The method of claim 1 , wherein the access log data from a plurality of access log sets currently stored in the access log storage is aggregated at regular intervals.

5. The method of claim 1 , wherein the object store is a data lake comprising multiple data repositories.

6. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, the processing device to:

periodically execute database operations, each database operation to access data stored in an object store;

in response to each database operation, generate an access log set and storing the access log set in an access log storage;

periodically aggregate access log data from a plurality of access log sets currently stored in the access log storage to generate aggregated log data; and

monitor the aggregated log data over time to identify one or more security incidents of the object store, wherein

the access log data from each of the plurality of access log sets corresponds to one or more access events, and includes a set of characteristics of each of the one or more access events, the set of characteristics include:

a source from which the access event originated, a user a role, or a group who initiated the access event, prefixes accessed by the access event, partitions accessed by the access event, sub-partitions accessed by the access event, a time of the access event, and a number of bytes transferred during the access event, and

the access log data from each of the plurality of access log sets is aggregated based on a set of characteristics of each of the one or more access events from each of the plurality of access log sets.

7. The system of claim 6 , wherein the aggregated log data represents a single event and indicates for the single event: a source from which the single event originated, a user, role, or group who initiated the single event, prefixes accessed by the single event, partitions accessed by the single event, sub-partitions accessed by the single event, a time of the single event, and a number of bytes transferred during the single event.

8. The system of claim 7 , wherein to monitor the aggregated log data over time, the processing device is to:

identify security incidents based on one or more of a source from which the single event originated, a user, role, or group who initiated the single event, prefixes accessed by the single event, partitions accessed by the single event, sub-partitions accessed by the single event, a time of the single event, and a number of bytes transferred during the single event.

9. The system of claim 6 , wherein the access log data from a plurality of access log sets currently stored in the access log storage is aggregated at regular intervals.

10. The system of claim 6 , wherein the object store is a data lake comprising multiple data repositories.

11. A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to:

periodically execute database operations, each database operation to access data stored in an object store;

in response to each database operation, generate an access log set and storing the access log set in an access log storage;

periodically aggregate, by the processing device, access log data from a plurality of access log sets currently stored in the access log storage to generate aggregated log data; and

monitor the aggregated log data over time to identify one or more security incidents of the object store, wherein

the access log data from each of the plurality of access log sets corresponds to one or more access events, and includes a set of characteristics of each of the one or more access events, the set of characteristics include:

a source from which the access event originated, a user, a role, or a group who initiated the access event, prefixes accessed by the access event, partitions accessed by the access event, sub-partitions accessed by the access event, a time of the access event, and a number of bytes transferred during the access event, and

the access log data from each of the plurality of access log sets is aggregated based on a set of characteristics of each of the one or more access events from each of the plurality of access log sets.

12. The non-transitory computer-readable medium of claim 11 , wherein the aggregated log data represents a single event and indicates for the single event: a source from which the single event originated, a user, role, or group who initiated the single event, prefixes accessed by the single event, partitions accessed by the single event, sub-partitions accessed by the single event, a time of the single event, and a number of bytes transferred during the single event.

13. The non-transitory computer-readable medium of claim 12 , wherein to monitor the aggregated log data over time, the processing device is to:

identify security incidents based on one or more of a source from which the single event originated, a user, role, or group who initiated the single event, prefixes accessed by the single event, partitions accessed by the single event, sub-partitions accessed by the single event, a time of the single event, and a number of bytes transferred during the single event.

14. The non-transitory computer-readable medium of claim 11 , wherein the access log data from a plurality of access log sets currently stored in the access log storage is aggregated at regular intervals.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2021
From: NAKAR, ORI
To: IMPERVA, INC.
Reel/Frame 058090/0899 →
Continuity (1)
Related Publication 20230142344A1 · May 11, 2023
References Cited (2)
US 20100111094A1 · Tanikawa · 2010 [cited by examiner]
US 20150310215A1 · McBride · 2015 [cited by examiner]