发明名称 NEED-TO-KNOW INFORMATION ACCESS USING QUANTIFIED RISK
摘要 Embodiments of the invention related to access control to sensitive data records, and in particular need-to-know information access using quantified risk. In one aspect of the invention access control includes retrieving a list of accesses to data by a plurality of users for a certain purpose during a specified period of time. The access patterns are derived based on said accesses and the derived access patterns are stored. A risk score is computed, for each of the plurality of users based on each of the plurality of users' need to access the data for said certain purpose, and the risk scores are stored. An aggregated total risk score for each of the plurality of users is created based on each respective user's computed risk score in a specified number of recent periods of time. A risk tolerance threshold is determined based on the aggregated total risk score for each of the plurality of users. A warning is issued if the aggregated total risk score for any of the plurality of users exceeds a risk-tolerance threshold.
申请公布号 US2013018921(A1) 申请公布日期 2013.01.17
申请号 US201113182317 申请日期 2011.07.13
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION;JIN HONGXIA;WANG QIHUA 发明人 JIN HONGXIA;WANG QIHUA
分类号 G06F7/00;G06F17/00 主分类号 G06F7/00
代理机构 代理人
主权项
地址