EP1566010A1

Method of query return data analysis for early warning indicators of possible security exposures

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 17 October 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

46 claims: 8 independent, 38 dependent

  1. 1
    Claims of equivalent WO 2004043000 A1 WHAT IS CLAIMED IS:1. A method of providing security with respect to data, comprising: receiving a query issued against a database by a user;and determining whether a security violation pattern exists based on at least one of: (i) pre-execution comparative analysis of the query with respect to at least one other previously issued query from the user;and (ii) post-execution comparative analysis of results returned from execution of the query and results returned from execution of the at least one other previously issued query.
  2. 14
    A method of providing security with respect to data, comprising:receiving a plurality of queries from a user;executing the plurality of queries against a database;receiving a subsequent query issued against the database by the user;and based on the plurality of queries and the subsequent query, programmatically determining whether a user effort to access an unauthorized amount of data from the database is identifiable.
  3. 16
    A method of providing security with respect to data, comprising:receiving a plurality of queries from a user;executing the plurality of queries against a database;receiving a subsequent query issued against the database by the user;executing the subsequent query;and based on the plurality of queries and the subsequent query, programmatically determining whether a user effort to bypass security constraints preventing unique identification of individuals is identifiable.
  4. 19
    A method of providing security to data having a particular physical data representation, comprising:providing a query specification comprising a plurality of logical fields for defining abstract queries;providing mapping rules which map the plurality of logical fields to physical entities of the data;providing security rules;receiving an abstract query issued against the data by a user, wherein the abstract query is defined according to the query specification and is configured with at least one logical field value;and analyzing the abstract query with respect to the at least one previously received abstract query from the user to detect an existence of security violation activity prompting invocation of a security rule.
  5. 23
    A computer-readable medium containing instructions which, when executed, perform a security violation identification operation, comprising:receiving a query issued against a database ' by a user;and determining whether a security violation pattern exists based on at least one of: (i) pre-execution comparative analysis of the query with respect to at least one other previously issued query from the user;and (ii) post-execution comparative analysis of results returned from execution of the query and results returned from execution of the at least one other previously issued query.
  6. 36
    A computer-readable medium containing security validation instructions which, when executed, performs a security validation operation comprising:receiving a plurality of plurality queries from a user;executing the plurality of queries against a database;receiving a subsequent query issued against the database by the user;and based on the plurality of queries and the subsequent query, programmatically determining whether a user effort to access an unauthorized amount of data from the database is identifiable.
  7. 38
    A computer-readable medium containing security validation instructions which, when executed, performs a security validation operation comprising:receiving a plurality of queries from a user;executing the plurality of queries against a database;receiving a subsequent query issued against the database by the user;executing the subsequent query;and based on the plurality of queries and the subsequent query, programmatically determining whether a user effort to bypass security constraints preventing unique identification of individuals is identifiable.
  8. 41
    A computer-readable medium, comprising information stored thereon, the information comprising:a query specification comprising a plurality of logical fields for defining abstract queries;a plurality of mapping rules which map the plurality of logical fields to physical entities of data;a plurality of security rules;a runtime component executable to perform a security violation activity detection operation in response to receiving an abstract query issued against the data by a user, wherein the abstract query is defined according to the query specification and is configured with at least one logical field value, the security violation activity detection operation comprising: receiving an abstract query issued against the data by a user, wherein the abstract query is defined according to the query specification and is configured with at least one logical field value;and analyzing the abstract query with respect to at least one previously received abstract query from the user to detect an existence of security violation activity prompting invocation of a security rule.