Agentless Sensitive Data Detection With Security Graph Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions fail to provide an efficient and user-friendly visualization of sensitive data storage and exposure in cloud computing environments, leading to potential data breaches due to the dynamic nature of these environments and the overwhelming amount of network elements that administrators must sift through.

Innovation Solution

A system and method for agentless detection of sensitive data in cloud environments, involving the inspection of disks for cybersecurity objects, extraction of data schemas, classification, and generation of visual representations in a security database, allowing for the identification and mitigation of sensitive data such as PII, PHI, and PCI, with the ability to initiate deletion actions when unauthorized storage is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If existing cybersecurity solutions provide comprehensive visibility into network elements, then complete information about sensitive data storage is obtained, but the amount of information becomes overwhelming and unusable for administrators

Engineering Contradiction:
Improvevisibility of sensitive dataVSAvoidusability of visualization solution
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent extracts only the critical information about sensitive data storage locations and exposure risks from the comprehensive network visibility data, filtering out unnecessary details. This allows administrators to see only the essential information needed to secure sensitive data without being overwhelmed by the full scope of network elements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The solution applies different levels of detail and visualization to different parts of the data based on their sensitivity and risk level. High-priority sensitive data receives prominent visualization and detailed information, while less critical data receives simplified representation, creating a differentiated information presentation that optimizes usability.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If administrators manually sift through network elements to find sensitive data, then complete inspection is possible, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improvedetection accuracy of sensitive dataVSAvoidtime to locate sensitive data
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary automated inspection and classification of network elements to identify sensitive data storage locations before administrators need to search for them. Data classification labels and risk assessments are pre-computed, allowing administrators to immediately see where sensitive data is stored without manual inspection of each element.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary automated analysis layer between the raw network data and the administrator. This intermediary system processes comprehensive network visibility data, identifies sensitive data patterns, and presents processed results to administrators, eliminating the need for manual sifting while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If cloud computing environments expand with more virtual instances and services, then functionality and service capability increase, but deployment complexity and monitoring difficulty increase

Engineering Contradiction:
Improveservice capabilityVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal detection mechanism that works across multiple cloud environments, virtual instance types, and storage configurations simultaneously. The same sensitive data detection and classification system adapts to various cloud platforms and deployment scenarios without requiring separate solutions for each, reducing overall system complexity despite environmental diversity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12547765B2System and method for agentless detection of sensitive data in computing environments
Publication Date: 2026.02.10 WIZ INC
  • US12547765B2 patent drawing
  • US12547765B2 patent drawing
  • US12547765B2 patent drawing

AI summary

A system and method for agentless detection of sensitive data in a cloud computing environment. The method includes detecting a first data object including a data schema and a content in a cloud computing environment; detecting a second data object, having the data schema of the first data object; generating in a security graph: a first data object node representing the first data object, a second data object node representing the second data object, and a data schema node representing the data schema; storing a classification based on the content in the security graph, wherein the content is classified as sensitive data or non-sensitive data; and rendering an output based on the classification and the data schema node, in lieu of the first data object node and the second data object node, in response to receiving a query to detect a node representing a data object classified as sensitive data.