×

Method of and system for enterprise information asset protection through insider attack specification, monitoring and mitigation

  • US 20050071643A1
  • Filed: 09/24/2004
  • Published: 03/31/2005
  • Est. Priority Date: 09/26/2003
  • Status: Active Grant
First Claim
Patent Images

1. Apparatus for protecting an enterprise data server against insider attack, comprising:

  • at least one processor;

    code executable on a processor for generating a display interface through which an authorized entity using a given policy specification language specifies an insider attack, wherein the given policy specification language enables the authorized entity to specify at least policy filter that is associated with a given enterprise data server type and defines (a) a given action that a trusted user may attempt to take with respect to a given enterprise information asset stored on a given enterprise data server, and (b) a given response that is to be taken upon detection of the given action;

    code executable on a processor to monitor a trusted user'"'"'s given data access against a set of one or more policy filters;

    code executable by a processor to analyze the trusted user'"'"'s given data access against the set of one or more policy filters;

    code executable by a processor to determine whether the trusted user'"'"'s given data access is indicative of a given action as specified by a given policy filter in the set of policy filters; and

    code executable by a processor if the trusted user'"'"'s given data access is indicative of a given action as specified by the given policy filter for taking the given response specified by the policy filter.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×