×

Real-time mitigation of data access insider intrusions

  • US 20050071642A1
  • Filed: 09/24/2004
  • Published: 03/31/2005
  • Est. Priority Date: 09/26/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method of protecting an enterprise information asset against insider attack, comprising:

  • specifying a policy filter that defines (a) a given action that a trusted user may attempt to take with respect to a given enterprise information asset stored on a given enterprise data server, and (b) a given risk mitigation response that is to be taken upon detection of the given action;

    monitoring a trusted user'"'"'s given data access with respect to the given enterprise data server;

    analyzing the given data access against the policy filter;

    determining whether the trusted user'"'"'s given data access is indicative of the given action as specified by the policy filter;

    if the trusted user'"'"'s given data access is indicative of the given action as specified in the policy filter, taking the given mitigation response as specified in the policy filter.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×