WO2006131906A2 - Automatic management of storage access control - Google Patents

Automatic management of storage access control Download PDF

Info

Publication number
WO2006131906A2
WO2006131906A2 PCT/IL2006/000600 IL2006000600W WO2006131906A2 WO 2006131906 A2 WO2006131906 A2 WO 2006131906A2 IL 2006000600 W IL2006000600 W IL 2006000600W WO 2006131906 A2 WO2006131906 A2 WO 2006131906A2
Authority
WO
WIPO (PCT)
Prior art keywords
users
storage elements
user
data
access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/IL2006/000600
Other languages
English (en)
French (fr)
Other versions
WO2006131906A3 (en
Inventor
Yakov Faitelson
Jacob Goldberger
Ohad Korkus
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Varonis Systems Ltd
Varonis Systems Inc
Original Assignee
Varonis Systems Ltd
Varonis Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Varonis Systems Ltd , Varonis Inc filed Critical Varonis Systems Ltd
Priority to GB0723218A priority Critical patent/GB2441458B/en
Priority to DE112006001378T priority patent/DE112006001378T5/de
Priority to JP2008515373A priority patent/JP4988724B2/ja
Publication of WO2006131906A2 publication Critical patent/WO2006131906A2/en
Anticipated expiration legal-status Critical
Publication of WO2006131906A3 publication Critical patent/WO2006131906A3/en
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/316User authentication by observing the pattern of computer usage, e.g. typical user behaviour
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2101Auditing as a secondary aspect
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10TECHNICAL SUBJECTS COVERED BY FORMER USPC
    • Y10STECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10S707/00Data processing: database and file management or data structures
    • Y10S707/99931Database or file accessing
    • Y10S707/99933Query processing, i.e. searching
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10TECHNICAL SUBJECTS COVERED BY FORMER USPC
    • Y10STECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10S707/00Data processing: database and file management or data structures
    • Y10S707/99931Database or file accessing
    • Y10S707/99938Concurrency, e.g. lock management in shared database
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10TECHNICAL SUBJECTS COVERED BY FORMER USPC
    • Y10STECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10S707/00Data processing: database and file management or data structures
    • Y10S707/99931Database or file accessing
    • Y10S707/99939Privileged access
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10TECHNICAL SUBJECTS COVERED BY FORMER USPC
    • Y10STECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y10S707/00Data processing: database and file management or data structures
    • Y10S707/99941Database schema or data structure
    • Y10S707/99944Object-oriented database structure
    • Y10S707/99945Object-oriented database structure processing

Definitions

  • This invention relates to computer security. More particularly, this invention relates to the automatic creation and management of file security policies in organizations having a diversity of file access control models.
  • Data security policies typically determine who has access to an organization's stored data on various computer systems. These policies cannot be static. Users from within the or- ganization, e.g., employees, partners, contractors, can pose a threat as severe as threats from outside the organization. Thus, as the structure and personnel makeup of the organization change, the security policy should be adjusted from time to time. Yet, information technology (IT) departments lack effective tools to manage user access rights and to ensure that needed information is conveniently available, while still protecting the organization's sensitive data. Current techniques available to IT personnel include review and maintenance of access control lists, in conjunction with administration of user names, passwords, and the extension of such techniques to include biometrics, encryption, and limitation of access to a single sign- on.
  • IT information technology
  • methods and systems are provided for automatically creating and managing a data security policy in networked organizations having diverse access control models and file server protocols. Access to storage elements within the organizational network is continually monitored and analyzed in order to de- fine simultaneous data access groupings and user groupings. The actual organizational structure is learned from these groupings, and becomes the basis of a dynamic data access control policy, which is constantly adapted to organizational changes over time.
  • a decision assistance interface is provided for interactive management of the file access control, and a facility is provided for detecting and tracking abnormal user behavior. Organizations are thus able to bet- ter control access to their data and applications.
  • the techniques are augmented by semi-automatically managing file access control by coordinating the user and data access groupings and conventional access control lists to effect modifications of the lists.
  • Access control policies developed by applying the teachings of the invention have ancil- lary benefits, e.g., limiting resource use in the event of a denial-of-service attack.
  • the invention provides a method for controlling data storage access in an organization, which is carried out by recording accesses of the users to storage elements, and deriving respective user access profiles from the recorded accesses.
  • the method is further carried out by biclustering the users and the storage elements to define user clusters and data clusters, respec- tively, wherein the access profiles of the users in user clusters are mutually similar, and the storage elements in the data clusters are accessed only by users having mutually similar the access profiles.
  • the method is further carried out responsively to the biclustering, by defining a control policy for access to the storage elements by the users.
  • the control policy permits access by a user to storage elements of a data cluster only if at least one of the storage elements in that data cluster has been accessed by that user.
  • the control policy permits access by the users in a user cluster to the storage elements of a data cluster, only if at least one of the storage elements in that data cluster has been accessed by at least one of the users of that user cluster.
  • the structure of the file system of the storage system is derived from the biclustering process.
  • a further aspect of the method includes deriving patterns of usage of the file system by the users from the biclustering process.
  • One aspect of the method includes detecting aberrant patterns of usage.
  • biclustering is performed iteratively, wherein the access profiles are redetermined at each iteration, and the control policy is updated following each iteration.
  • defining a control policy is carried out by proposing a tentative version of the control policy, monitoring subsequent accesses to the storage elements by the users, determining that the subsequent accesses are in accordance with the tentative version of the control policy, and responsively to the determination, approving the tentative version as a definitive version of the control policy.
  • Another aspect of the method includes interactively modifying the control policy.
  • defining a control policy is performed automatically and substantially without human intervention.
  • Yet another aspect of the method includes referencing an access control list including at least one set of users and at least one data set of storage elements, wherein the users of the user set are included in respective ones of the user clusters, and the storage elements of the data set are included in respective ones of the data clusters.
  • the method is further carried out by de- tecting an absence of accesses by members of the respective user clusters to members of the respective data clusters, and responsively to the lack of accesses, removing at least a portion of the users from the user set and removing at least a portion of the storage elements from the data set.
  • the invention provides a computer software product, including a computer-readable medium in which computer program instructions are stored, which instructions, when read by a computer, cause the computer to perform a method for controlling data storage access, which is carried out by recording accesses of the users to the storage elements and deriving respec- tive access profiles from the recorded accesses.
  • the method is further carried out by bicluster- ing the users and the storage elements to define user clusters and data clusters, respectively, wherein the access profiles of the users in the user clusters are mutually similar, and the storage elements in the data clusters are accessed only by users having mutually similar the access profiles.
  • the method is further carried out responsively to the biclustering, by defining a control policy for access to the storage elements by the users.
  • the invention provides an apparatus for controlling data storage access in an organization having users of a file system, including a computer system operative to perform the steps of recording respective accesses of the users to the storage elements and deriving respective access profiles from the recorded accesses, biclustering the users and the storage elements to define user clusters and data clusters, respectively, wherein the access profiles of the users in the user clusters are mutually similar, and the storage elements in the data clusters are accessed only by users having mutually similar the access profiles.
  • the computer system is operative, responsively to biclustering, for defining a control policy for access to the storage elements by the users.
  • Fig. 1 is a block diagram of a data processing system, wherein data access control policies are automatically defined and managed in accordance with a disclosed embodiment of the invention
  • Fig. 2 is a block diagram illustrating a probe engine in the system shown in Fig. 1 in accordance with a disclosed embodiment of the invention
  • Fig. 3 is a block diagram illustrating another version of a probe engine in the system shown in Fig. 1 in accordance with a disclosed embodiment of the invention
  • Fig. 4 is a flow chart describing a method of user clustering in accordance with a disclosed embodiment of the invention.
  • Fig. 5 is a flow chart describing a method for storage element clustering in accordance with a disclosed embodiment of the invention
  • Fig. 6A and Fig. 6B, referred to collectively herein as Fig. 6, are a flow chart illustrating a method of semi-automatic file access control in accordance with a disclosed embodiment of the invention.
  • Software programming code which embodies aspects of the present invention, is typically maintained in permanent storage, such as a computer readable medium.
  • a client- server environment such software programming code may be stored on a client or a server.
  • the software programming code may be embodied on any of a variety of known media for use with a data processing system. This includes, but is not limited to, magnetic and optical storage devices such as disk drives, magnetic tape, compact discs (CD's), digital video discs (DVD's), and computer instruction signals embodied in a transmission medium with or without a carrier wave upon which the signals are modulated.
  • the transmission medium may include a communications network, such as the Internet.
  • the invention may be embodied in computer software, the functions necessary to implement the invention may alternatively be embodied in part or in whole using hardware components such as application-specific integrated circuits or other hardware, or some combination of hardware components and software.
  • Fig. 1 is a block diagram of a data processing system 10 wherein data access control policies are automatically defined and managed in accordance with a disclosed embodiment of the invention.
  • the system 10 may be implemented as a general purpose computer or a plurality of computers linked together in a network, for example the Internet.
  • Organization-wide data storage accessible by the system 10 is represented by an organizational file system 12.
  • the organizational file system 12 may comprise one or more co- located storage units, or may be a geographically distributed data storage system, as is known in the art. There is no requirement that individual storage units of the organizational file system 12 have the same capabilities.
  • the organizational file system 12 may be accessed by any number of users 14 using a graphical user interface application 16 (GUI), which relates to other elements of the system 10 via an application programming interface 18 (API).
  • GUI graphical user interface application
  • the users 14 are typically members of the organization, but may also include outsiders, such as customers.
  • the graphical user interface application 16 is the interface of the management system, through which the users 14 can receive the results of their actual usage analysis, as determined an analysis engine 20.
  • sufficiently qualified users e.g., administrative personnel, can view their current status, and can view changes recommended by the system. Such users may be authorized to accept or reject recommended changes. Prior to selecting any recommended changes, qualified users have the ability to view the effect of recommended changes on the system. System administrators can then select or confirm the permission set that proves most suitable.
  • a probe engine 22 is designed to collect access information from the organizational file system 12 in an ongoing manner, filter out duplicate or redundant information units and store the resulting information stream in a database 24.
  • the probe engine 22 is also utilized to collect the organization's current file security policy, the current structure of the organizational file system 12, and information about the users 14.
  • the probe engine 22 can be implemented in various environments and architectures.
  • the analysis engine 20 is a specialized module that is at the heart of the system's ability to control storage access.
  • the analysis engine 20 automatically proposes and revises the organization's security policy.
  • the front end for the analysis engine 20 is a data collector 26, which efficiently records the storage access activities in the database 24.
  • the output of the analysis engine 20 can be further manipulated using an interactive administrative interface 28 that enables system administrators to perform queries on the collected data. Using the administrative interface 28, the administrators may modify the automatically proposed security policy if necessary, and finally activate the new or revised policy.
  • a commit module 30 which verifies a proposed se- curity policy, using data collected prior to its implementation.
  • the commit module 30 references an access control list 32 (ACL). Activities of the commit module 30 are described in further details hereinbelow. Probe Engine.
  • Probe engines are tailored to particular operating systems and environments. The following are described by way of example and not of limitation.
  • FIG. 2 is a block diagram illustrating one embodiment of the probe engine 22 (Fig. 1) in accordance with a disclosed embodiment of the invention.
  • This embodiment termed herein the "Win-Probe module,” acts as a probe for the Microsoft
  • Win-Probe module that services all Windows computers in the organization.
  • the Win- Probe module operates in parallel with probe engines adapted to other operating systems.
  • a complex organization may require more than one Win-Probe module in order to assure efficient operation.
  • the Win-Probe module has a file system filter 34 (SEDFILE) that employs a kernel-mode filter driver 36 for intercepting activity of a local file system 38 and for logging it alongside security information regarding the activity intercepted.
  • SEDFILE file system filter 34
  • a service 40 (SIDFILE_SERVICE) interacts with the filter driver 36 and polls for new log entries.
  • the log entries are filtered by the service 40,
  • the service 40 is responsible for compiling statistics from the filtered log entries, and forwarding both the raw log entries and their statistics to the database 24 (Fig. 1) for further processing.
  • the filter 34 is transparent to the operating system, and its overhead is limited to extraction of associated security attributes per input/output (I/O) operation and logging. Communication between the filter driver 36 and the service 40 is accomplished using operating system mechanisms such as device I/O Control, and predefined control codes, e.g., "collect statistics".
  • FIG. 3 is a block diagram illustrating another embodiment of the probe engine 22 (Fig. 1), which is adapted to networked devices in accordance with a disclosed embodiment of the invention.
  • a network attached storage (NAS) probe 42 is responsible for collecting access data from a NAS storage device 44.
  • one NAS probe may serve an entire organization.
  • a plurality of NAS probes may be provided.
  • the probe 42 interacts with the NAS device 44 using a dedicated, typically vendor-specific protocol. The protocol causes the NAS device 44 to send a notification 46 on a requested file access operation originating from a user 48 to the probe 42.
  • the probe 42 either enables the requests to be satisfied by the NAS device 44, or denies access to the NAS device 44, according to a current governing policy.
  • a log entry 50 is made by the probe 42, documenting an enabled request, and the request is passed to the NAS device 44 for conven- tional processing, in accordance with its own operating system.
  • a denied request is simply discarded.
  • denied requests may be logged, in order to assist in tracking abnormal user behavior.
  • the user 48 receives a reply 52 to its request, either in the form of a denial of access, or an indication of the result of the requested file operation by the NAS device 44. In either case, there is minimal performance impact.
  • the analysis engine 20 (Fig. 1) is at the heart of the system 10.
  • the sta- tistics on actual accesses of the users 14, including every member of an organization to each of the data storage elements in the organizational file system 12, reported by the probe engine 22, are used to perform a simultaneous automatic bi-clustering of the users and the data storage elements.
  • the bi-clustering is done in such a manner that users who are members of the same user cluster share a similar data access profile, and data storage elements (files or directories) that are members of the same data cluster are accessed mostly by users having similar access profiles.
  • the clusters provide a global picture of the organizational structure.
  • the analysis engine 20 can also develop from the clustering results a local measure of similarity among users and a local measure of similarity among the data elements that belong to the same cluster. Moreover, the clustering process reliably predicts future data storage access by organization members. It can be assumed, with a high level of confidence, that if one of the users 14 has not accessed a certain file or storage element, and similar users have not accessed similar files, then that one user will not need access rights to the corresponding storage element in the near future.
  • the analysis engine 20 thus provides IT administrators a clear global picture of information usage patterns and can offer detailed recommendations for security policy optimiza- tion. At the same time, administrators are alerted to anomalous user behavior.
  • the analysis engine 20 can also automatically build a complete forensic trail of any suspicious activities. The result is a dramatically greater ability to ensure compliance with access and privacy poli- cies, and to assure appropriate information usage without imposing additional administrative burdens on IT personnel.
  • X stands for the set of users in the organization
  • Y is the set of file directories accessed by the members of the organization.
  • the value p(x,y) is the normalized number of times that user x approached the data storage element y during an enrollment phase.
  • p(x,y) is the normalized number of times that user x approached the data storage element y during an enrollment phase.
  • a clustering of the random variable X is a partitioning of the elements of Z into disjoint clusters denoted by X and in a similar manner denoting a partition of Y by Y'.
  • the system util- izes the mutual information criterion as a cost function to assess the quality of various clustering structures.
  • the next step is to utilize the mutual information criterion to find the optimal bicluster- ing.
  • Different strategies are used for the user set X and the data set Y.
  • user set X there is no current structure that it is necessary to maintain.
  • the data file system is based on a tree structure, which we do want to maintain, as it is likely to reflect an operational similarity between nearby directories in the tree. Therefore, storage element clustering is ac- complished by essentially pruning the tree. The process is described in further detail hereinbe- low.
  • Fig. 4 is a flow chart describing a method of user clustering in accordance with a disclosed embodiment of the invention. The method begins with a random solution and then sequentially improves the result in a monotonic manner.
  • a random partitioning of the user list into a predetermined number of clusters is chosen as a starting point. This partitioning will be used in a current set of cycles as described below.
  • the probability distribution p(y ⁇ x) stands for the normalized data access activity of the user x, i.e., p(y
  • C) we define p(y
  • step 56 one of the clusters established in initial step 54 is selected randomly.
  • step 58 one of the users is selected. Step 58 is performed iteratively, and the users are evaluated cyclically. However, the order of evaluation in a cycle is not critical.
  • step 60 the current user x is tentatively moved from its current cluster to the cluster selected in step 56 to form a tentative new clustering of the users.
  • Each user x is merged into the cluster C, which minimizes the distance d(x,C).
  • C) is modified according to the statistics of the new member x. It can be verified that minimizing the distance d(x,C) is equivalent to maximizing the mutual information between the clusters and the data activities.
  • step 62 If the determination at decision step 62 is affirmative, then control proceeds to step 64.
  • the current user x remains in the cluster that was selected in step 56, and the tentative new clustering established in step 60 is confirmed.
  • step 62 determines whether the determination at decision step 62 is negative. If the determination at decision step 62 is negative, then control proceeds to step 66. The current user x is returned to the cluster from which it was selected, and the tentative new clustering established in step 60 is rejected.
  • control now proceeds to decision step 68, where it is determined whether more users remain to be evaluated in the current cycle. If the determination at decision step 68 is affirmative, then control returns to step 58.
  • decision step 72 the user list is reset to begin another cycle in the current set of cycles. Control returns to step 56, and the new cycle begins by choosing a new cluster, using the same random partitioning established in initial step 54.
  • step 70 If the determination at decision step 70 is negative, then control proceeds to step 74.
  • the best clustering achieved in the current set of cycles is memorized.
  • the termination criterion may be completion of a predetermined number of iterations of initial step 54.
  • a performance indicator can be used as a termination criterion. If the determination at decision step 76 is negative, then control returns to initial step 54, and the method is repeated, choosing a new starting point. If the determination at decision step 76 is affirmative, then control proceeds to final step 78.
  • the best result obtained in the clusterings memorized in iterations of step 74 is reported as a final clustering that maximizes the mutual information between the user clusters and the data clusters. Data Element Clustering.
  • Fig. 5 is a flow chart describing a method for storage element clustering in accordance with a disclosed embodiment of the invention.
  • This is an ag- glomerative method based on merging clusters that are represented by sibling elements in the data file tree. It is assumed that user clustering as described above with reference to Fig. 4 has been performed.
  • sibling directories or parent- offspring directories that cannot be distinguished in terms of user access events. This stage results in a directory tree that has been pruned into a tractable number of elements.
  • Initial step 80 begins a traversal of the directories of the file tree.
  • parent-offspring directories and sibling directories and clusters thereof are considered, and are referred to collectively as "neighbors".
  • the traversal order is not critical, so long as all data elements are visited and all mutual neighbors are evaluated. Many known algorithms for tree traversal may be employed. Two neighbors are selected.
  • step 84 the candidates are merged together to form a new data cluster. This data cluster is treated as a single storage element or neighbor in subsequent iterations of initial step 80.
  • decision step 86 it is determined whether traversal of the data file tree is complete. If the determination at decision step 86 is affirmative, then control returns to initial step 80 to begin another iteration.
  • the determination at decision step 86 is negative, then one phase of the method is complete, resulting in a pruned directory tree.
  • the directories and clusters of direc- tories in the pruned tree constitute a tractable number of elements.
  • step 88 begins another phase of the method, wherein the pruned tree is traversed again, with additional merging of candidates in a manner that leads to a minimal reduction in the mutual information l(X;Y).
  • the mutual information ⁇ (X;Y) between the user clusters resulting from the method described with reference to Fig. 4 and the data clusters of the current pruned tree is memorized.
  • two candidates are selected.
  • these candidates can be clusters, directories, or combinations thereof, so long as the candidates have a sibling or parent-child relationship.
  • step 92 the current candidates are tentatively merged to form a new clustering of the users and data elements.
  • the mutual information F (X; Y) of the tentative arrangement is determined.
  • step 94 If the determination at decision step 94 is affirmative, then control proceeds to step 96.
  • the current tentative clustering is memorized, and set as a high water mark. It is the best new clustering thus far available.
  • control proceeds to decision step 98, where it is determined if more candidates remain to be evaluated in the tree. If the determination at decision step 98 is affirmative, then control returns to step 90.
  • control proceeds to decision step 100, where it is determined if a termination criterion has been met.
  • This criterion can be the establishment of a predetermined number of new clusters. Alternatively, the method may terminate when the current best reduction in mutual information is less than a predetermined threshold. If the determination at decision step 100 is negative, then the method is repeated, using the mutual information of the current best clustering as a starting point. Control returns to step 88, where a new value of the mutual information 1(X; Y) is set.
  • step 100 determines whether the determination at decision step 100 is affirmative. If the determination at decision step 100 is affirmative, then control proceeds to final step 102.
  • the clustering last stored at step 96 is reported as an optimum data element clustering.
  • both the users and the data storage elements are arranged in disjoint clusters.
  • a hierarchical tree structure is maintained among the data storage elements, while the users are distributed among a user space without having a hierarchical ar- rangement.
  • a robust similarity measure between users in the organization can then be extracted. It is said that users behave similarly if they belong to the same user cluster, which indicates that the two users are accessing similar portions of the data-storage systems. Two directories or other storage elements are considered similar if they belong to the same data cluster. Storage access control.
  • the clustering obtained using the method described above with reference to Fig. 5 can be used to automatically eliminate unnecessary access permissions. For example, permission for a user x to access a storage element y is eliminated if the user x has not accessed the element y (nor elements similar to y) during an enrollment period. It is predicted that the user x will not need to access the element y in the near future. The prediction is based on the access profile of similar members of the organization. It can be assumed that if no users with a similar access profile to the element y, who are thus in the same cluster as the user x, have accessed the element y, nor accessed storage elements similar to the element y, then the user x will not access the element v in the near future. Therefore, in order to increase the level of organiza- tional data security, access permission can be canceled for the user x with respect to the element y. Review of the users is conducted iteratively at predetermined time intervals, and the access policy updated accordingly.
  • the ACL can be viewed as a set of pairs, where each pair consists of a group of users and a group of data elements that can be accessed by the user group.
  • the procedure presented below can use the unsupervised clustering procedure discussed above to modify the current ACL and thereby obtain an improved policy.
  • the organizational structure learned from the recorded user access data is then used to eliminate unnecessary data access permissions.
  • the algorithm is based on the current ACL, and operates separately for each user- data group in the following manner: for each user we check whether access to one of the data elements defined in the pair was recorded. If not, we check whether a similar user accessed the data element during the enrollment period. Here similarity has the same meaning as given above. If no such user was found, it can be concluded that the particular user will not need to access the data element in the near future. If this is also the case for the data elements appearing in the data group, we eliminate the user from the access control pair. A second phase of the process is applied to eliminate data elements from the access control pair, as explained below.
  • Fig. 6 is a flow chart illustrating a method of partially supervised file access control in accordance with a disclosed embodiment of the invention.
  • the steps of the method are shown in an exemplary sequence in Fig. 6 for clarity of presentation. However, it will be evident to those skilled in the art that many of them can be performed in parallel, asynchronously, or in different orders.
  • the method begins at initial step 104.
  • the bi-clustering methods described above with reference to Fig. 4 and Fig. 5 are performed and applied.
  • an access control unit is selected from the ACL. This unit is a pair, composed of a group of users and a group of directories.
  • step 108 a user is chosen from the users of the current access control unit.
  • step 110 a data element is chosen from the current access control unit.
  • step 112 determines whether users determined (in the clus- tering procedure performed in initial step 104) to be similar to the current user are evaluated. Control proceeds to step 116. A similar user is selected.
  • control returns to step 116. If the determination at decision step 120 is negative, then at step 122 the current user is removed from the current access control unit.
  • step 124 it is determined if more users in the current access control unit remain to be evaluated. If the determination at decision step 124 is affirmative, then control returns to step 108 If the determination at decision step 124 is negative, then, at decision step 126 it is determined if more access control units remain to be evaluated. If the determination at decision step 126 is affirmative, then control returns to step 106 to begin a new iteration.
  • Step 114 begins a phase of the algorithm, which concerns the status of the current data element in the current access control unit. This phase is performed only if neither the current user nor any similar user has accessed the current data element.
  • the purpose of the following steps is to investigate whether data elements that are considered to be similar to the current data element (according to the clustering procedure performed in initial step 104) have been accessed by any of the users in the current access control unit. If not, then the current data element is removed from the current access control unit. Once this action is accomplished, no member of the current user group can thereafter access the current data element. A similar data element is selected from the clustering performed in initial step 104.
  • step 130 a user is again selected from the current access control unit. It is intended that all users in the current access control unit be subject to evaluation in iterations of step 130.
  • step 134 determines if there are more similar data elements to be tested against the users in the current access control unit.
  • control returns to step 114.
  • step 136 If the determination at decision step 136 is negative, then all users of the current access control unit have been tested for access against all data elements that are similar to the current data element (chosen in the last iteration of step 110). No access has been found. At step 137 the current data element is now eliminated from the current access control unit.
  • the clustering procedures described above are applied to the storage access activities collected during an enrollment or training period for the system. These procedures may be repeated from time to time, for example, following mergers and acquisitions in the underlying organization. It is desirable to assure that a proposed or tentative new or updated access control policy is valid in terms of user activity occurring following the enrollment period. Data collected after the enrollment period are used to verify the validity of the tentative policy prior to its institution. This function is carried out by the commit module 30, which records user access activities and detects violations of the tentative policy. If the user activities would not violate the tentative policy, then it is approved as a definitive storage access control policy. Otherwise it is rejected or returned for further evaluation or revision. The commit module 30 thus provides a cross-validation mechanism to check the quality of a proposed storage access control policy before its actual implementation.
  • the commit module 30 is adapted to perform this function following the implementation of a storage access control. Abnormal behavior may be identified if a user acts inconsistently with other users belonging to the same user cluster.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Business, Economics & Management (AREA)
  • Health & Medical Sciences (AREA)
  • Accounting & Taxation (AREA)
  • Bioethics (AREA)
  • Strategic Management (AREA)
  • Automation & Control Theory (AREA)
  • General Business, Economics & Management (AREA)
  • Finance (AREA)
  • Databases & Information Systems (AREA)
  • Social Psychology (AREA)
  • Storage Device Security (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
PCT/IL2006/000600 2005-06-07 2006-05-21 Automatic management of storage access control Ceased WO2006131906A2 (en)

Priority Applications (3)

Application Number Priority Date Filing Date Title
GB0723218A GB2441458B (en) 2005-06-07 2006-05-21 Automatic management of storage access control
DE112006001378T DE112006001378T5 (de) 2005-06-07 2006-05-21 Automatische Verwaltung einer Speicherzugriffssteuerung
JP2008515373A JP4988724B2 (ja) 2005-06-07 2006-05-21 データ記憶アクセスの制御方法

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US68848605P 2005-06-07 2005-06-07
US60/688,486 2005-06-07
US11/258,256 US7606801B2 (en) 2005-06-07 2005-10-25 Automatic management of storage access control
US11/258,256 2005-10-25

Publications (2)

Publication Number Publication Date
WO2006131906A2 true WO2006131906A2 (en) 2006-12-14
WO2006131906A3 WO2006131906A3 (en) 2009-05-22

Family

ID=37495353

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/IL2006/000600 Ceased WO2006131906A2 (en) 2005-06-07 2006-05-21 Automatic management of storage access control

Country Status (5)

Country Link
US (2) US7606801B2 (enExample)
JP (2) JP4988724B2 (enExample)
DE (1) DE112006001378T5 (enExample)
GB (1) GB2441458B (enExample)
WO (1) WO2006131906A2 (enExample)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2461160A (en) * 2008-06-27 2009-12-30 Bank Of America Managing entitlements
JP2010049541A (ja) * 2008-08-22 2010-03-04 Nec Corp 機密情報管理システム、機密情報管理方法、及びプログラム
CN101938497A (zh) * 2010-09-26 2011-01-05 深圳大学 多级保密文档组结构及其文件访问控制和密钥管理用户终端、服务终端、系统和方法
GB2474091A (en) * 2009-07-24 2011-04-06 Bank Of America Dynamically managing entitlements by grouping entities into communities
US8225416B2 (en) 2008-06-27 2012-07-17 Bank Of America Corporation Dynamic entitlement manager
US10320798B2 (en) 2013-02-20 2019-06-11 Varonis Systems, Inc. Systems and methodologies for controlling access to a file system
US10764299B2 (en) 2017-06-29 2020-09-01 Microsoft Technology Licensing, Llc Access control manager

Families Citing this family (270)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7778981B2 (en) * 2000-12-01 2010-08-17 Netapp, Inc. Policy engine to control the servicing of requests received by a storage server
US8417678B2 (en) 2002-07-30 2013-04-09 Storediq, Inc. System, method and apparatus for enterprise policy management
US7610329B2 (en) 2002-07-30 2009-10-27 Storediq, Inc. Method and apparatus for managing file systems and file-based data storage
US8612404B2 (en) * 2002-07-30 2013-12-17 Stored Iq, Inc. Harvesting file system metsdata
US7805449B1 (en) 2004-10-28 2010-09-28 Stored IQ System, method and apparatus for enterprise policy management
US8571289B2 (en) 2002-11-27 2013-10-29 Hologic, Inc. System and method for generating a 2D image from a tomosynthesis data set
US7617211B2 (en) * 2004-08-02 2009-11-10 International Business Machines Corporation System and method for automatically synchronizing security-relevant information between a relational database and a multidimensional database
US8510331B1 (en) 2004-10-28 2013-08-13 Storediq, Inc. System and method for a desktop agent for use in managing file systems
US7844582B1 (en) 2004-10-28 2010-11-30 Stored IQ System and method for involving users in object management
US8126856B2 (en) * 2005-05-26 2012-02-28 Hewlett-Packard Development Company, L.P. File access management system
US7606801B2 (en) * 2005-06-07 2009-10-20 Varonis Inc. Automatic management of storage access control
US20070088717A1 (en) * 2005-10-13 2007-04-19 International Business Machines Corporation Back-tracking decision tree classifier for large reference data set
US7962513B1 (en) * 2005-10-31 2011-06-14 Crossroads Systems, Inc. System and method for defining and implementing policies in a database system
US10008184B2 (en) 2005-11-10 2018-06-26 Hologic, Inc. System and method for generating a 2D image using mammography and/or tomosynthesis image data
MY149346A (en) * 2005-11-17 2013-08-30 Koninkl Philips Electronics Nv System for managing proprietary data
US8321437B2 (en) 2005-12-29 2012-11-27 Nextlabs, Inc. Detecting behavioral patterns and anomalies using activity profiles
WO2007095330A2 (en) 2006-02-15 2007-08-23 Hologic Inc Breast biopsy and needle localization using tomosynthesis systems
US20070226131A1 (en) * 2006-03-09 2007-09-27 Decker Katherine K Data processing method and apparatus for mitigating risk in financing purchases of goods including but not limited to automobiles
US8561146B2 (en) 2006-04-14 2013-10-15 Varonis Systems, Inc. Automatic folder access management
US8584195B2 (en) * 2006-11-08 2013-11-12 Mcafee, Inc Identities correlation infrastructure for passive network monitoring
US8220023B2 (en) * 2007-02-21 2012-07-10 Nds Limited Method for content presentation
US8239925B2 (en) * 2007-04-26 2012-08-07 Varonis Systems, Inc. Evaluating removal of access permissions
US8341104B2 (en) * 2007-08-16 2012-12-25 Verizon Patent And Licensing Inc. Method and apparatus for rule-based masking of data
US8621573B2 (en) 2007-08-28 2013-12-31 Cisco Technology, Inc. Highly scalable application network appliances with virtualized services
US8131784B1 (en) 2007-09-26 2012-03-06 Network Appliance, Inc. Multiple node quota filter
US7783666B1 (en) * 2007-09-26 2010-08-24 Netapp, Inc. Controlling access to storage resources by using access pattern based quotas
US7831621B1 (en) 2007-09-27 2010-11-09 Crossroads Systems, Inc. System and method for summarizing and reporting impact of database statements
US8438611B2 (en) 2007-10-11 2013-05-07 Varonis Systems Inc. Visualization of access permission status
DE102007052180A1 (de) * 2007-10-31 2009-05-07 Fujitsu Siemens Computers Gmbh Verfahren, Rechnersystem und Computerprogrammprodukt
US8438612B2 (en) * 2007-11-06 2013-05-07 Varonis Systems Inc. Visualization of access permission status
US8295198B2 (en) * 2007-12-18 2012-10-23 Solarwinds Worldwide Llc Method for configuring ACLs on network device based on flow information
US20090265780A1 (en) * 2008-04-21 2009-10-22 Varonis Systems Inc. Access event collection
US9456054B2 (en) 2008-05-16 2016-09-27 Palo Alto Research Center Incorporated Controlling the spread of interests and content in a content centric network
US8667556B2 (en) * 2008-05-19 2014-03-04 Cisco Technology, Inc. Method and apparatus for building and managing policies
US8190734B2 (en) * 2008-05-21 2012-05-29 Mcafee, Inc. System and method for network monitoring of internet protocol (IP) networks
US8639570B2 (en) * 2008-06-02 2014-01-28 Microsoft Corporation User advertisement click behavior modeling
FR2932043B1 (fr) * 2008-06-03 2010-07-30 Groupe Ecoles Telecomm Procede de tracabilite et de resurgence de flux pseudonymises sur des reseaux de communication, et procede d'emission de flux informatif apte a securiser le trafic de donnees et ses destinataires
US20100070471A1 (en) * 2008-09-17 2010-03-18 Rohati Systems, Inc. Transactional application events
US8463730B1 (en) 2008-10-24 2013-06-11 Vmware, Inc. Rapid evaluation of numerically large complex rules governing network and application transactions
US9559800B1 (en) 2008-10-24 2017-01-31 Vmware, Inc. Dynamic packet filtering
US9330374B2 (en) * 2009-03-27 2016-05-03 Bank Of America Corporation Source-to-processing file conversion in an electronic discovery enterprise system
US9721227B2 (en) 2009-03-27 2017-08-01 Bank Of America Corporation Custodian management system
US9641334B2 (en) * 2009-07-07 2017-05-02 Varonis Systems, Inc. Method and apparatus for ascertaining data access permission of groups of users to groups of data elements
US20110055276A1 (en) * 2009-08-26 2011-03-03 Brocade Communications Systems, Inc. Systems and methods for automatic inclusion of entities into management resource groups
US9742778B2 (en) 2009-09-09 2017-08-22 International Business Machines Corporation Differential security policies in email systems
US10229191B2 (en) 2009-09-09 2019-03-12 Varonis Systems Ltd. Enterprise level data management
US20110061093A1 (en) * 2009-09-09 2011-03-10 Ohad Korkus Time dependent access permissions
US8578507B2 (en) 2009-09-09 2013-11-05 Varonis Systems, Inc. Access permissions entitlement review
WO2011030324A1 (en) 2009-09-09 2011-03-17 Varonis Systems, Inc. Enterprise level data management
US8640195B2 (en) * 2009-09-30 2014-01-28 International Business Machines Corporation Method and system for automating security policy definition based on recorded transactions
US10595954B2 (en) 2009-10-08 2020-03-24 Hologic, Inc. Needle breast biopsy system and method for use
US8923293B2 (en) 2009-10-21 2014-12-30 Palo Alto Research Center Incorporated Adaptive multi-interface use for content networking
EP2515496A4 (en) * 2009-12-15 2013-07-03 Telefonica Sa SYSTEM AND METHOD OF TRUSTING TRUST BETWEEN DATA NETWORKING USERS
US8448221B2 (en) * 2010-03-12 2013-05-21 Mcafee, Inc. System, method, and computer program product for displaying network events in terms of objects managed by a security appliance and/or a routing device
US8533787B2 (en) 2011-05-12 2013-09-10 Varonis Systems, Inc. Automatic resource ownership assignment system and method
US10296596B2 (en) 2010-05-27 2019-05-21 Varonis Systems, Inc. Data tagging
US9870480B2 (en) 2010-05-27 2018-01-16 Varonis Systems, Inc. Automatic removal of global user security groups
CN103026334A (zh) 2010-05-27 2013-04-03 瓦欧尼斯系统有限公司 数据分类
US9177167B2 (en) 2010-05-27 2015-11-03 Varonis Systems, Inc. Automation framework
US8959115B2 (en) * 2010-07-09 2015-02-17 Symantec Corporation Permission tracking systems and methods
US9147180B2 (en) 2010-08-24 2015-09-29 Varonis Systems, Inc. Data governance for email systems
US9141808B1 (en) 2010-10-29 2015-09-22 Symantec Corporation Data loss prevention
WO2012071429A1 (en) 2010-11-26 2012-05-31 Hologic, Inc. User interface for medical image review workstation
WO2012090189A1 (en) * 2010-12-29 2012-07-05 Varonis Systems, Inc. Method and apparatus for ascertaining data access permission of groups of users to groups of data elements
US8739279B2 (en) * 2011-01-17 2014-05-27 International Business Machines Corporation Implementing automatic access control list validation using automatic categorization of unstructured text
US8909673B2 (en) 2011-01-27 2014-12-09 Varonis Systems, Inc. Access permissions management system and method
US9680839B2 (en) 2011-01-27 2017-06-13 Varonis Systems, Inc. Access permissions management system and method
CN103314355B (zh) 2011-01-27 2018-10-12 凡诺尼斯系统有限公司 访问权限管理系统及方法
JP5740260B2 (ja) * 2011-02-02 2015-06-24 株式会社日立ソリューションズ セキュリティポリシー管理サーバ、セキュリティ監視システム
CA2829349C (en) 2011-03-08 2021-02-09 Hologic, Inc. System and method for dual energy and/or contrast enhanced breast imaging for screening, diagnosis and biopsy
US8452819B1 (en) * 2011-03-22 2013-05-28 Amazon Technologies, Inc. Methods and apparatus for optimizing resource utilization in distributed storage systems
JP5708131B2 (ja) * 2011-03-29 2015-04-30 日本電気株式会社 アクセス制御システム、アクセス制御方法、認可装置およびそのプログラム、ならびに、サービス提供装置
EP2782505B1 (en) 2011-11-27 2020-04-22 Hologic, Inc. System and method for generating a 2d image using mammography and/or tomosynthesis image data
US9208156B2 (en) * 2011-12-06 2015-12-08 Honeywell International Inc. Acquiring statistical access models
EP2807583B1 (en) * 2012-01-24 2018-07-25 Varonis Systems, Inc. A method and apparatus for authentication of file read events
ES2641456T3 (es) 2012-02-13 2017-11-10 Hologic, Inc. Sistema y método para navegar por una pila de tomosíntesis usando datos de imágenes sintetizadas
CN104662510B (zh) 2012-04-04 2017-11-28 瓦欧尼斯系统有限公司 企业级数据元素检查系统和方法
US9286316B2 (en) 2012-04-04 2016-03-15 Varonis Systems, Inc. Enterprise level data collection systems and methodologies
US9588835B2 (en) 2012-04-04 2017-03-07 Varonis Systems, Inc. Enterprise level data element review systems and methodologies
US11151515B2 (en) 2012-07-31 2021-10-19 Varonis Systems, Inc. Email distribution list membership governance method and system
CN104685511B (zh) 2012-09-26 2017-10-24 株式会社东芝 策略管理系统、id提供者系统以及策略评价装置
WO2014049741A1 (ja) 2012-09-26 2014-04-03 株式会社 東芝 ポリシ更新システム及びポリシ更新装置
US9124619B2 (en) 2012-12-08 2015-09-01 International Business Machines Corporation Directing audited data traffic to specific repositories
US10430839B2 (en) 2012-12-12 2019-10-01 Cisco Technology, Inc. Distributed advertisement insertion in content-centric networks
US10129607B2 (en) 2012-12-19 2018-11-13 Arris Enterprises Llc Using analytical models to inform policy decisions
WO2014110283A1 (en) 2013-01-10 2014-07-17 Hologic, Inc. System and method for reducing data transmission volume in tomosynthesis
CN105451657A (zh) 2013-03-15 2016-03-30 霍罗吉克公司 用于导航断层合成堆叠的包括自动聚焦的系统和方法
JP6388347B2 (ja) 2013-03-15 2018-09-12 ホロジック, インコーポレイテッドHologic, Inc. 腹臥位におけるトモシンセシス誘導生検
US9264442B2 (en) * 2013-04-26 2016-02-16 Palo Alto Research Center Incorporated Detecting anomalies in work practice data by combining multiple domains of information
US9935791B2 (en) 2013-05-20 2018-04-03 Cisco Technology, Inc. Method and system for name resolution across heterogeneous architectures
CN105264520B (zh) 2013-06-04 2019-07-16 瓦欧尼斯系统有限公司 委送一机构的相似数据至一连结装置的方法
US9444722B2 (en) 2013-08-01 2016-09-13 Palo Alto Research Center Incorporated Method and apparatus for configuring routing paths in a custodian-based routing architecture
JP2016533803A (ja) 2013-10-24 2016-11-04 アンドリュー ピー. スミス, X線誘導胸部生検をナビゲートするためのシステムおよび方法
US9407549B2 (en) 2013-10-29 2016-08-02 Palo Alto Research Center Incorporated System and method for hash-based forwarding of packets with hierarchically structured variable-length identifiers
US9276840B2 (en) 2013-10-30 2016-03-01 Palo Alto Research Center Incorporated Interest messages with a payload for a named data network
US9401864B2 (en) 2013-10-31 2016-07-26 Palo Alto Research Center Incorporated Express header for packets with hierarchically structured variable-length identifiers
US10101801B2 (en) 2013-11-13 2018-10-16 Cisco Technology, Inc. Method and apparatus for prefetching content in a data stream
US10129365B2 (en) 2013-11-13 2018-11-13 Cisco Technology, Inc. Method and apparatus for pre-fetching remote content based on static and dynamic recommendations
US9311377B2 (en) 2013-11-13 2016-04-12 Palo Alto Research Center Incorporated Method and apparatus for performing server handoff in a name-based content distribution system
US10089655B2 (en) 2013-11-27 2018-10-02 Cisco Technology, Inc. Method and apparatus for scalable data broadcasting
US9298914B1 (en) * 2013-12-03 2016-03-29 Symantec Corporation Enterprise data access anomaly detection and flow tracking
US9503358B2 (en) 2013-12-05 2016-11-22 Palo Alto Research Center Incorporated Distance-based routing in an information-centric network
US9379979B2 (en) 2014-01-14 2016-06-28 Palo Alto Research Center Incorporated Method and apparatus for establishing a virtual interface for a set of mutual-listener devices
US10098051B2 (en) 2014-01-22 2018-10-09 Cisco Technology, Inc. Gateways and routing in software-defined manets
US10172068B2 (en) 2014-01-22 2019-01-01 Cisco Technology, Inc. Service-oriented routing in software-defined MANETs
US9374304B2 (en) 2014-01-24 2016-06-21 Palo Alto Research Center Incorporated End-to end route tracing over a named-data network
US9954678B2 (en) 2014-02-06 2018-04-24 Cisco Technology, Inc. Content-based transport security
US9678998B2 (en) 2014-02-28 2017-06-13 Cisco Technology, Inc. Content name resolution for information centric networking
JP6506769B2 (ja) 2014-02-28 2019-04-24 ホロジック, インコーポレイテッドHologic, Inc. トモシンセシス画像スラブを生成し表示するためのシステムおよび方法
US10089651B2 (en) 2014-03-03 2018-10-02 Cisco Technology, Inc. Method and apparatus for streaming advertisements in a scalable data broadcasting system
US9836540B2 (en) 2014-03-04 2017-12-05 Cisco Technology, Inc. System and method for direct storage access in a content-centric network
US9473405B2 (en) 2014-03-10 2016-10-18 Palo Alto Research Center Incorporated Concurrent hashes and sub-hashes on data streams
US9391896B2 (en) 2014-03-10 2016-07-12 Palo Alto Research Center Incorporated System and method for packet forwarding using a conjunctive normal form strategy in a content-centric network
US9626413B2 (en) 2014-03-10 2017-04-18 Cisco Systems, Inc. System and method for ranking content popularity in a content-centric network
US9407432B2 (en) 2014-03-19 2016-08-02 Palo Alto Research Center Incorporated System and method for efficient and secure distribution of digital content
US9916601B2 (en) 2014-03-21 2018-03-13 Cisco Technology, Inc. Marketplace for presenting advertisements in a scalable data broadcasting system
US9363179B2 (en) 2014-03-26 2016-06-07 Palo Alto Research Center Incorporated Multi-publisher routing protocol for named data networks
US9363086B2 (en) 2014-03-31 2016-06-07 Palo Alto Research Center Incorporated Aggregate signing of data in content centric networking
US9716622B2 (en) 2014-04-01 2017-07-25 Cisco Technology, Inc. System and method for dynamic name configuration in content-centric networks
US9390289B2 (en) 2014-04-07 2016-07-12 Palo Alto Research Center Incorporated Secure collection synchronization using matched network names
US10075521B2 (en) 2014-04-07 2018-09-11 Cisco Technology, Inc. Collection synchronization using equality matched network names
US9473576B2 (en) 2014-04-07 2016-10-18 Palo Alto Research Center Incorporated Service discovery using collection synchronization with exact names
US9451032B2 (en) 2014-04-10 2016-09-20 Palo Alto Research Center Incorporated System and method for simple service discovery in content-centric networks
US9992281B2 (en) 2014-05-01 2018-06-05 Cisco Technology, Inc. Accountable content stores for information centric networks
US9609014B2 (en) 2014-05-22 2017-03-28 Cisco Systems, Inc. Method and apparatus for preventing insertion of malicious content at a named data network router
US9455835B2 (en) 2014-05-23 2016-09-27 Palo Alto Research Center Incorporated System and method for circular link resolution with hash-based names in content-centric networks
US10659523B1 (en) * 2014-05-23 2020-05-19 Amazon Technologies, Inc. Isolating compute clusters created for a customer
US9516144B2 (en) 2014-06-19 2016-12-06 Palo Alto Research Center Incorporated Cut-through forwarding of CCNx message fragments with IP encapsulation
US9537719B2 (en) 2014-06-19 2017-01-03 Palo Alto Research Center Incorporated Method and apparatus for deploying a minimal-cost CCN topology
CN104077371B (zh) * 2014-06-24 2019-03-29 用友优普信息技术有限公司 监测数据库异常数据的方法及系统
US9426113B2 (en) 2014-06-30 2016-08-23 Palo Alto Research Center Incorporated System and method for managing devices over a content centric network
US9699198B2 (en) 2014-07-07 2017-07-04 Cisco Technology, Inc. System and method for parallel secure content bootstrapping in content-centric networks
US9621354B2 (en) 2014-07-17 2017-04-11 Cisco Systems, Inc. Reconstructable content objects
US9959156B2 (en) 2014-07-17 2018-05-01 Cisco Technology, Inc. Interest return control message
US9590887B2 (en) 2014-07-18 2017-03-07 Cisco Systems, Inc. Method and system for keeping interest alive in a content centric network
US9729616B2 (en) 2014-07-18 2017-08-08 Cisco Technology, Inc. Reputation-based strategy for forwarding and responding to interests over a content centric network
US9535968B2 (en) 2014-07-21 2017-01-03 Palo Alto Research Center Incorporated System for distributing nameless objects using self-certifying names
US9621558B2 (en) * 2014-07-27 2017-04-11 Varonis Systems, Ltd. Granting collaboration permissions in a computerized system
RU2581559C2 (ru) 2014-08-01 2016-04-20 Закрытое акционерное общество "Лаборатория Касперского" Система и способ применения политик безопасности к накопителю в сети
US9516028B1 (en) * 2014-08-06 2016-12-06 Amazon Technologies, Inc. Hierarchical policy-based shared resource access control
US9882964B2 (en) 2014-08-08 2018-01-30 Cisco Technology, Inc. Explicit strategy feedback in name-based forwarding
US9503365B2 (en) 2014-08-11 2016-11-22 Palo Alto Research Center Incorporated Reputation-based instruction processing over an information centric network
US9729662B2 (en) 2014-08-11 2017-08-08 Cisco Technology, Inc. Probabilistic lazy-forwarding technique without validation in a content centric network
US9391777B2 (en) 2014-08-15 2016-07-12 Palo Alto Research Center Incorporated System and method for performing key resolution over a content centric network
US9800637B2 (en) 2014-08-19 2017-10-24 Cisco Technology, Inc. System and method for all-in-one content stream in content-centric networks
US9467492B2 (en) 2014-08-19 2016-10-11 Palo Alto Research Center Incorporated System and method for reconstructable all-in-one content stream
US9497282B2 (en) 2014-08-27 2016-11-15 Palo Alto Research Center Incorporated Network coding for content-centric network
US10204013B2 (en) 2014-09-03 2019-02-12 Cisco Technology, Inc. System and method for maintaining a distributed and fault-tolerant state over an information centric network
US9553812B2 (en) 2014-09-09 2017-01-24 Palo Alto Research Center Incorporated Interest keep alives at intermediate routers in a CCN
CN104268481A (zh) * 2014-10-10 2015-01-07 中国联合网络通信集团有限公司 一种实现智能手机预警的方法及装置
US10069933B2 (en) 2014-10-23 2018-09-04 Cisco Technology, Inc. System and method for creating virtual interfaces based on network characteristics
US10665120B2 (en) * 2014-11-10 2020-05-26 AO Kaspersky Lab System and method for encouraging studying by controlling student's access to a device based on results of studying
US9590948B2 (en) 2014-12-15 2017-03-07 Cisco Systems, Inc. CCN routing using hardware-assisted hash tables
US9536059B2 (en) 2014-12-15 2017-01-03 Palo Alto Research Center Incorporated Method and system for verifying renamed content using manifests in a content centric network
US10237189B2 (en) 2014-12-16 2019-03-19 Cisco Technology, Inc. System and method for distance-based interest forwarding
US9846881B2 (en) 2014-12-19 2017-12-19 Palo Alto Research Center Incorporated Frugal user engagement help systems
US9473475B2 (en) 2014-12-22 2016-10-18 Palo Alto Research Center Incorporated Low-cost authenticated signing delegation in content centric networking
US10003520B2 (en) 2014-12-22 2018-06-19 Cisco Technology, Inc. System and method for efficient name-based content routing using link-state information in information-centric networks
US9660825B2 (en) 2014-12-24 2017-05-23 Cisco Technology, Inc. System and method for multi-source multicasting in content-centric networks
US9916457B2 (en) 2015-01-12 2018-03-13 Cisco Technology, Inc. Decoupled name security binding for CCN objects
US9954795B2 (en) 2015-01-12 2018-04-24 Cisco Technology, Inc. Resource allocation using CCN manifests
US9832291B2 (en) 2015-01-12 2017-11-28 Cisco Technology, Inc. Auto-configurable transport stack
US9602596B2 (en) 2015-01-12 2017-03-21 Cisco Systems, Inc. Peer-to-peer sharing in a content centric network
US9946743B2 (en) 2015-01-12 2018-04-17 Cisco Technology, Inc. Order encoded manifests in a content centric network
US9462006B2 (en) 2015-01-21 2016-10-04 Palo Alto Research Center Incorporated Network-layer application-specific trust model
US9552493B2 (en) 2015-02-03 2017-01-24 Palo Alto Research Center Incorporated Access control framework for information centric networking
US10333840B2 (en) 2015-02-06 2019-06-25 Cisco Technology, Inc. System and method for on-demand content exchange with adaptive naming in information-centric networks
US10412106B2 (en) * 2015-03-02 2019-09-10 Verizon Patent And Licensing Inc. Network threat detection and management system based on user behavior information
US10075401B2 (en) 2015-03-18 2018-09-11 Cisco Technology, Inc. Pending interest table behavior
US10437515B2 (en) 2015-03-31 2019-10-08 Pure Storage, Inc. Selecting storage units in a dispersed storage network
US10116605B2 (en) 2015-06-22 2018-10-30 Cisco Technology, Inc. Transport stack name scheme and identity management
US10075402B2 (en) 2015-06-24 2018-09-11 Cisco Technology, Inc. Flexible command and control in content centric networks
US10701038B2 (en) 2015-07-27 2020-06-30 Cisco Technology, Inc. Content negotiation in a content centric network
US9986034B2 (en) 2015-08-03 2018-05-29 Cisco Technology, Inc. Transferring state in content centric network stacks
US10610144B2 (en) 2015-08-19 2020-04-07 Palo Alto Research Center Incorporated Interactive remote patient monitoring and condition management intervention system
US9832123B2 (en) 2015-09-11 2017-11-28 Cisco Technology, Inc. Network named fragments in a content centric network
US10355999B2 (en) 2015-09-23 2019-07-16 Cisco Technology, Inc. Flow control with network named fragments
US10313227B2 (en) 2015-09-24 2019-06-04 Cisco Technology, Inc. System and method for eliminating undetected interest looping in information-centric networks
US9977809B2 (en) 2015-09-24 2018-05-22 Cisco Technology, Inc. Information and data framework in a content centric network
US9705884B2 (en) 2015-09-25 2017-07-11 International Business Machines Corporation Intelligent access control
US20170091471A1 (en) * 2015-09-25 2017-03-30 Qualcomm Incorporated Clustering A Repository Based On User Behavioral Data
US10454820B2 (en) 2015-09-29 2019-10-22 Cisco Technology, Inc. System and method for stateless information-centric networking
US10263965B2 (en) 2015-10-16 2019-04-16 Cisco Technology, Inc. Encrypted CCNx
US9794238B2 (en) 2015-10-29 2017-10-17 Cisco Technology, Inc. System for key exchange in a content centric network
US9807205B2 (en) 2015-11-02 2017-10-31 Cisco Technology, Inc. Header compression for CCN messages using dictionary
US10009446B2 (en) 2015-11-02 2018-06-26 Cisco Technology, Inc. Header compression for CCN messages using dictionary learning
US10021222B2 (en) 2015-11-04 2018-07-10 Cisco Technology, Inc. Bit-aligned header compression for CCN messages using dictionary
US10097521B2 (en) 2015-11-20 2018-10-09 Cisco Technology, Inc. Transparent encryption in a content centric network
US9912776B2 (en) 2015-12-02 2018-03-06 Cisco Technology, Inc. Explicit content deletion commands in a content centric network
US10097346B2 (en) 2015-12-09 2018-10-09 Cisco Technology, Inc. Key catalogs in a content centric network
US10078062B2 (en) 2015-12-15 2018-09-18 Palo Alto Research Center Incorporated Device health estimation by combining contextual information with sensor data
US10257271B2 (en) 2016-01-11 2019-04-09 Cisco Technology, Inc. Chandra-Toueg consensus in a content centric network
US9949301B2 (en) 2016-01-20 2018-04-17 Palo Alto Research Center Incorporated Methods for fast, secure and privacy-friendly internet connection discovery in wireless networks
US10305864B2 (en) 2016-01-25 2019-05-28 Cisco Technology, Inc. Method and system for interest encryption in a content centric network
US10043016B2 (en) 2016-02-29 2018-08-07 Cisco Technology, Inc. Method and system for name encryption agreement in a content centric network
US10038633B2 (en) 2016-03-04 2018-07-31 Cisco Technology, Inc. Protocol to query for historical network information in a content centric network
US10051071B2 (en) 2016-03-04 2018-08-14 Cisco Technology, Inc. Method and system for collecting historical network information in a content centric network
US10742596B2 (en) 2016-03-04 2020-08-11 Cisco Technology, Inc. Method and system for reducing a collision probability of hash-based names using a publisher identifier
US10003507B2 (en) 2016-03-04 2018-06-19 Cisco Technology, Inc. Transport session state protocol
US9832116B2 (en) 2016-03-14 2017-11-28 Cisco Technology, Inc. Adjusting entries in a forwarding information base in a content centric network
US10212196B2 (en) 2016-03-16 2019-02-19 Cisco Technology, Inc. Interface discovery and authentication in a name-based network
US10067948B2 (en) 2016-03-18 2018-09-04 Cisco Technology, Inc. Data deduping in content centric networking manifests
US11436656B2 (en) 2016-03-18 2022-09-06 Palo Alto Research Center Incorporated System and method for a real-time egocentric collaborative filter on large datasets
US10091330B2 (en) 2016-03-23 2018-10-02 Cisco Technology, Inc. Interest scheduling by an information and data framework in a content centric network
US10033639B2 (en) 2016-03-25 2018-07-24 Cisco Technology, Inc. System and method for routing packets in a content centric network using anonymous datagrams
US10320760B2 (en) 2016-04-01 2019-06-11 Cisco Technology, Inc. Method and system for mutating and caching content in a content centric network
US9930146B2 (en) 2016-04-04 2018-03-27 Cisco Technology, Inc. System and method for compressing content centric networking messages
US10425503B2 (en) 2016-04-07 2019-09-24 Cisco Technology, Inc. Shared pending interest table in a content centric network
US10027578B2 (en) 2016-04-11 2018-07-17 Cisco Technology, Inc. Method and system for routable prefix queries in a content centric network
WO2017187379A1 (en) * 2016-04-27 2017-11-02 Cymmetria, Inc. Supply chain cyber-deception
US10404450B2 (en) 2016-05-02 2019-09-03 Cisco Technology, Inc. Schematized access control in a content centric network
US10320675B2 (en) 2016-05-04 2019-06-11 Cisco Technology, Inc. System and method for routing packets in a stateless content centric network
US10547589B2 (en) 2016-05-09 2020-01-28 Cisco Technology, Inc. System for implementing a small computer systems interface protocol over a content centric network
US10084764B2 (en) 2016-05-13 2018-09-25 Cisco Technology, Inc. System for a secure encryption proxy in a content centric network
US10063414B2 (en) 2016-05-13 2018-08-28 Cisco Technology, Inc. Updating a transport stack in a content centric network
US10103989B2 (en) 2016-06-13 2018-10-16 Cisco Technology, Inc. Content object return messages in a content centric network
US10305865B2 (en) 2016-06-21 2019-05-28 Cisco Technology, Inc. Permutation-based content encryption with manifests in a content centric network
US10148572B2 (en) 2016-06-27 2018-12-04 Cisco Technology, Inc. Method and system for interest groups in a content centric network
US10009266B2 (en) 2016-07-05 2018-06-26 Cisco Technology, Inc. Method and system for reference counted pending interest tables in a content centric network
US9992097B2 (en) 2016-07-11 2018-06-05 Cisco Technology, Inc. System and method for piggybacking routing information in interests in a content centric network
US11706227B2 (en) * 2016-07-20 2023-07-18 Varonis Systems Inc Systems and methods for processing access permission type-specific access permission requests in an enterprise
US10122624B2 (en) 2016-07-25 2018-11-06 Cisco Technology, Inc. System and method for ephemeral entries in a forwarding information base in a content centric network
US10069729B2 (en) 2016-08-08 2018-09-04 Cisco Technology, Inc. System and method for throttling traffic based on a forwarding information base in a content centric network
US10956412B2 (en) 2016-08-09 2021-03-23 Cisco Technology, Inc. Method and system for conjunctive normal form attribute matching in a content centric network
US10033642B2 (en) 2016-09-19 2018-07-24 Cisco Technology, Inc. System and method for making optimal routing decisions based on device-specific parameters in a content centric network
US10212248B2 (en) 2016-10-03 2019-02-19 Cisco Technology, Inc. Cache management on high availability routers in a content centric network
US10447805B2 (en) 2016-10-10 2019-10-15 Cisco Technology, Inc. Distributed consensus in a content centric network
US10135948B2 (en) 2016-10-31 2018-11-20 Cisco Technology, Inc. System and method for process migration in a content centric network
US10243851B2 (en) 2016-11-21 2019-03-26 Cisco Technology, Inc. System and method for forwarder connection information in a content centric network
US10841337B2 (en) 2016-11-28 2020-11-17 Secureworks Corp. Computer implemented system and method, and computer program product for reversibly remediating a security risk
US11017687B2 (en) 2017-01-31 2021-05-25 Ent. Services Development Corporation Lp Information technology user behavior monitoring rule generation
AU2018223809B2 (en) * 2017-02-27 2022-12-15 Ivanti, Inc. Systems and methods for role-based computer security configurations
WO2018183548A1 (en) * 2017-03-30 2018-10-04 Hologic, Inc. System and method for hierarchical multi-level feature image synthesis and representation
CN110662489B (zh) 2017-03-30 2024-08-02 豪洛捷公司 用于靶向对象增强以生成合成乳房组织图像的系统和方法
US11455754B2 (en) 2017-03-30 2022-09-27 Hologic, Inc. System and method for synthesizing low-dimensional image data from high-dimensional image data using an object grid enhancement
US11403483B2 (en) 2017-06-20 2022-08-02 Hologic, Inc. Dynamic self-learning medical image method and system
US10735470B2 (en) 2017-11-06 2020-08-04 Secureworks Corp. Systems and methods for sharing, distributing, or accessing security data and/or security applications, models, or analytics
US10594713B2 (en) 2017-11-10 2020-03-17 Secureworks Corp. Systems and methods for secure propagation of statistical models within threat intelligence communities
US12121304B2 (en) 2018-05-04 2024-10-22 Hologic, Inc. Introducer and localization wire visualization
AU2019262183B2 (en) 2018-05-04 2025-01-09 Hologic, Inc. Biopsy needle visualization
US10938845B2 (en) 2018-05-10 2021-03-02 International Business Machines Corporation Detection of user behavior deviation from defined user groups
US10785238B2 (en) 2018-06-12 2020-09-22 Secureworks Corp. Systems and methods for threat discovery across distinct organizations
US11003718B2 (en) 2018-06-12 2021-05-11 Secureworks Corp. Systems and methods for enabling a global aggregated search, while allowing configurable client anonymity
CA3055993C (en) * 2018-09-20 2024-01-02 Idera, Inc. Database access, monitoring, and control system and method for reacting to suspicious database activities
EP3856031B1 (en) 2018-09-24 2025-06-11 Hologic, Inc. Breast mapping and abnormality localization
AU2019346527B2 (en) 2018-09-28 2025-03-06 Hologic, Inc. System and method for synthetic breast tissue image generation by high density element suppression
EP3884499A1 (en) 2018-11-25 2021-09-29 Hologic, Inc. Multimodality hanging protocols
CN113574609A (zh) 2019-03-29 2021-10-29 豪洛捷公司 剪切触发的数字图像报告生成
US11144395B2 (en) 2019-04-08 2021-10-12 International Business Machines Corporation Automatic data preservation for potentially compromised encoded data slices
US11310268B2 (en) 2019-05-06 2022-04-19 Secureworks Corp. Systems and methods using computer vision and machine learning for detection of malicious actions
US11418524B2 (en) 2019-05-07 2022-08-16 SecureworksCorp. Systems and methods of hierarchical behavior activity modeling and detection for systems-level security
US11115421B2 (en) * 2019-06-26 2021-09-07 Accenture Global Solutions Limited Security monitoring platform for managing access rights associated with cloud applications
US11883206B2 (en) 2019-07-29 2024-01-30 Hologic, Inc. Personalized breast imaging system
DE202020006045U1 (de) 2019-09-27 2024-07-02 Hologic Inc. KI-System zum Vorhersagen von Lesezeit und Lesekomplexität zum Überprüfen von 2D-/3D-Brustbildern
US11381589B2 (en) 2019-10-11 2022-07-05 Secureworks Corp. Systems and methods for distributed extended common vulnerabilities and exposures data management
US11522877B2 (en) 2019-12-16 2022-12-06 Secureworks Corp. Systems and methods for identifying malicious actors or activities
US11481038B2 (en) 2020-03-27 2022-10-25 Hologic, Inc. Gesture recognition in controlling medical hardware or software
US11588834B2 (en) 2020-09-03 2023-02-21 Secureworks Corp. Systems and methods for identifying attack patterns or suspicious activity in client networks
US11528294B2 (en) 2021-02-18 2022-12-13 SecureworksCorp. Systems and methods for automated threat detection
US12135789B2 (en) 2021-08-04 2024-11-05 Secureworks Corp. Systems and methods of attack type and likelihood prediction
US12034751B2 (en) 2021-10-01 2024-07-09 Secureworks Corp. Systems and methods for detecting malicious hands-on-keyboard activity via machine learning
US12186119B2 (en) 2021-10-05 2025-01-07 Hologic, Inc. Interactive model interface for image selection in medical imaging systems
WO2023064744A1 (en) 2021-10-11 2023-04-20 Odna, Llc System and method for computer system security authorization interfaces
US12254586B2 (en) 2021-10-25 2025-03-18 Hologic, Inc. Auto-focus tool for multimodality image review
WO2023097279A1 (en) 2021-11-29 2023-06-01 Hologic, Inc. Systems and methods for correlating objects of interest
US12423170B2 (en) 2022-01-19 2025-09-23 Secureworks Corp. Systems and methods for generating a system log parser
US12015623B2 (en) 2022-06-24 2024-06-18 Secureworks Corp. Systems and methods for consensus driven threat intelligence
CN116881960A (zh) * 2023-07-10 2023-10-13 实道时代(北京)科技有限公司 一种基于互联网大数据的业务管理方法
WO2025212901A1 (en) 2024-04-03 2025-10-09 Hologic, Inc. Reducing tomosynthesis file sizes
US20250371188A1 (en) * 2024-05-31 2025-12-04 Servicenow, Inc. Configuring instances for data observability and access

Family Cites Families (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5465387A (en) * 1993-10-08 1995-11-07 At&T Corp. Adaptive fraud monitoring and control
US20030051026A1 (en) * 2001-01-19 2003-03-13 Carter Ernst B. Network surveillance and security system
US7068592B1 (en) * 2001-05-10 2006-06-27 Conexant, Inc. System and method for increasing payload capacity by clustering unloaded bins in a data transmission system
US7194445B2 (en) * 2002-09-20 2007-03-20 Lenovo (Singapore) Pte. Ltd. Adaptive problem determination and recovery in a computer system
JP4393762B2 (ja) * 2002-12-19 2010-01-06 株式会社日立製作所 データベース処理方法及び装置並びにその処理プログラム
US7403925B2 (en) * 2003-03-17 2008-07-22 Intel Corporation Entitlement security and control
US20040249847A1 (en) * 2003-06-04 2004-12-09 International Business Machines Corporation System and method for identifying coherent objects with applications to bioinformatics and E-commerce
US20050086529A1 (en) * 2003-10-21 2005-04-21 Yair Buchsbaum Detection of misuse or abuse of data by authorized access to database
US20050108206A1 (en) * 2003-11-14 2005-05-19 Microsoft Corporation System and method for object-oriented interaction with heterogeneous data stores
US8600920B2 (en) * 2003-11-28 2013-12-03 World Assets Consulting Ag, Llc Affinity propagation in adaptive network-based systems
US8078481B2 (en) * 2003-12-05 2011-12-13 John Steinbarth Benefits administration system and methods of use and doing business
US20050203881A1 (en) * 2004-03-09 2005-09-15 Akio Sakamoto Database user behavior monitor system and method
US7421740B2 (en) * 2004-06-10 2008-09-02 Sap Ag Managing user authorizations for analytical reporting based on operational authorizations
CN1291569C (zh) 2004-09-24 2006-12-20 清华大学 一种附网存储设备中用户访问行为的异常检测方法
US20060184459A1 (en) * 2004-12-10 2006-08-17 International Business Machines Corporation Fuzzy bi-clusters on multi-feature data
US8245280B2 (en) * 2005-02-11 2012-08-14 Samsung Electronics Co., Ltd. System and method for user access control to content in a network
US7606801B2 (en) * 2005-06-07 2009-10-20 Varonis Inc. Automatic management of storage access control

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2461160A (en) * 2008-06-27 2009-12-30 Bank Of America Managing entitlements
US8225416B2 (en) 2008-06-27 2012-07-17 Bank Of America Corporation Dynamic entitlement manager
US8316453B2 (en) 2008-06-27 2012-11-20 Bank Of America Corporation Dynamic community generator
GB2461160B (en) * 2008-06-27 2013-01-02 Bank Of America Dynamic entitlement manager
US8763069B2 (en) 2008-06-27 2014-06-24 Bank Of America Corporation Dynamic entitlement manager
US8881299B2 (en) 2008-06-27 2014-11-04 Bank Of America Corporation Dynamic community generator
JP2010049541A (ja) * 2008-08-22 2010-03-04 Nec Corp 機密情報管理システム、機密情報管理方法、及びプログラム
GB2474091A (en) * 2009-07-24 2011-04-06 Bank Of America Dynamically managing entitlements by grouping entities into communities
CN101938497A (zh) * 2010-09-26 2011-01-05 深圳大学 多级保密文档组结构及其文件访问控制和密钥管理用户终端、服务终端、系统和方法
US10320798B2 (en) 2013-02-20 2019-06-11 Varonis Systems, Inc. Systems and methodologies for controlling access to a file system
US10764299B2 (en) 2017-06-29 2020-09-01 Microsoft Technology Licensing, Llc Access control manager

Also Published As

Publication number Publication date
JP2009500697A (ja) 2009-01-08
GB2441458B (en) 2010-02-10
US7606801B2 (en) 2009-10-20
US20060277184A1 (en) 2006-12-07
US20070094265A1 (en) 2007-04-26
JP4988724B2 (ja) 2012-08-01
WO2006131906A3 (en) 2009-05-22
GB2441458A (en) 2008-03-05
GB0723218D0 (en) 2008-01-09
US7555482B2 (en) 2009-06-30
JP5108155B2 (ja) 2012-12-26
DE112006001378T5 (de) 2008-04-17
JP2012108934A (ja) 2012-06-07

Similar Documents

Publication Publication Date Title
US7606801B2 (en) Automatic management of storage access control
US10491630B2 (en) System and method for providing data-driven user authentication misuse detection
US10686829B2 (en) Identifying changes in use of user credentials
EP2884715B1 (en) Correlation based security risk identification
US20080271157A1 (en) Evaluating removal of access permissions
CN102598021B (zh) 用于管理安全对象的方法和系统
US20040064731A1 (en) Integrated security administrator
US20110314549A1 (en) Method and apparatus for periodic context-aware authentication
US20110314558A1 (en) Method and apparatus for context-aware authentication
JP2005259140A (ja) データベースを監視するための方法、命令の1つ以上のシーケンスを保持するコンピュータ読み取り可能な媒体、および装置
US20080086473A1 (en) Computerized management of grouping access rights
CN119939637B (zh) 结合多级加密策略联合调度的服务器集群安全控制方法
CN117195292B (zh) 一种基于数据融合和边缘计算的电力业务评估方法
CN120030515B (zh) 一种基于区块链的电商运营数据安全保护系统及方法
CN120105469A (zh) 基于云控平台的数据访问方法、装置及电子设备
CN119853990A (zh) 一种微信运营自动化综合服务平台
Colombini et al. Network profiling: Content analysis of users behavior in digital communication channel
Chapple et al. Authentication anomaly detection: A case study on a virtual private network
CN119622714B (zh) 用于计算机终端数据交互的数据智能安全防护方法及系统
Maroc et al. Towards security effectiveness evaluation for cloud services selection following a risk-driven approach
CN118784328B (zh) 用于电子商务的交易数据安全监管系统和方法
Pöhn et al. Towards Improving Identity and Access Management with the IdMSecMan Process Framework
CN120090864A (zh) 基于网络安全数据的复杂策略访问控制方法
CN120378163A (zh) 一种基于端到端加密通信的权限分配方法及系统
CN120567526A (zh) 一种基于多维权限控制的网络数据安全防护方法及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 0723218.4

Country of ref document: GB

WWE Wipo information: entry into national phase

Ref document number: 1120060013785

Country of ref document: DE

WWE Wipo information: entry into national phase

Ref document number: 2008515373

Country of ref document: JP

RET De translation (de og part 6b)

Ref document number: 112006001378

Country of ref document: DE

Date of ref document: 20080417

Kind code of ref document: P

122 Ep: pct application non-entry in european phase

Ref document number: 06745111

Country of ref document: EP

Kind code of ref document: A2