Application Wrapper for Targeted Data Loss Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional data loss prevention (DLP) systems are ineffective on unmanaged computing devices, as they require organizational control over all devices, which is not always feasible, especially when employees use personal devices to access sensitive data, leading to potential data exposure.
Innovation Solution
Implementing wrapped applications with application wrappers that intercept system calls and apply DLP policies specifically to sensitive data, rather than installing DLP endpoint agents on the entire device, thereby providing targeted protection without intrusive scans on personal data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DLP systems are deployed on unmanaged computing devices, then data loss prevention coverage is improved, but device complexity and user acceptance deteriorate due to intrusive scanning of personal data
Solution Approach 1:
The patent segments the DLP system into two distinct components: a lightweight agent installed on the unmanaged device that only monitors sensitive data, and a centralized server that processes the monitoring data. This segmentation allows the agent to remain minimal and non-intrusive while the server handles the complex DLP policy enforcement and analysis.
Solution Approach 2:
The patent extracts the complex DLP policy processing and data analysis functions from the unmanaged device and relocates them to a centralized server. The agent on the unmanaged device only performs simple data collection and transmission, eliminating the need for complex local scanning and processing that would cause intrusion and performance issues.
2Reliability
If DLP endpoint agents are installed on unmanaged devices, then data protection is improved, but ease of operation deteriorates due to invasive scanning of personal data
Solution Approach 1:
The patent applies local quality by differentiating between personal data and sensitive organizational data. The agent selectively monitors only the sensitive data identified through file extensions, document types, and data patterns, while leaving personal data untouched and unmonitored, thus maintaining user comfort and ease of operation.
Solution Approach 2:
The patent introduces a centralized server as an intermediary between the unmanaged device and the DLP policy enforcement. The server receives data from the lightweight agent, processes it according to DLP policies, and makes determination decisions, thereby eliminating the need for complex local scanning and improving user experience.
3Reliability
If comprehensive DLP agents are deployed, then data exfiltration prevention is improved, but adaptability deteriorates when employees use personal devices
Solution Approach 1:
The patent applies partial action by implementing DLP monitoring only for specific sensitive data types and contexts rather than comprehensive monitoring of all data on the device. The agent monitors data based on file extensions, document types, and patterns relevant to organizational sensitivity, providing sufficient protection without the excessive intrusion of full-device scanning.
Data Source
AI summary
A computer-implemented method for providing targeted data loss prevention on unmanaged computing devices may include (1) identifying a data loss prevention policy that defines permissible data handling within set bounds to prevent unauthorized data exfiltration from the set bounds, (2) identifying an application to install on at least one unmanaged endpoint device, where (i) the unmanaged endpoint device lacks a data loss prevention agent configured to apply the data loss prevention policy to the entire unmanaged endpoint device and (ii) the application is to be provided to the unmanaged endpoint device to operate on sensitive data from within the set bounds, and (3) wrapping the application in an application wrapper that intercepts system calls from the application and applies the data loss prevention policy to sensitive data implicated in the system calls. Various other methods, systems, and computer-readable media are also disclosed.


