Automatic Policy Manager for Data Loss Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Data Loss Prevention (DLP) solutions require manual creation and management of policies, which is labor-intensive and often requires specialized knowledge, posing challenges for small businesses without dedicated IT Security Officers.

Innovation Solution

The Automatic Policy Manager (APM) system automatically creates and adjusts DLP policies by monitoring data flows, detecting sensitive data, and generating rules based on user justification, thereby reducing the need for manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual policy creation and management is used, then policy accuracy and customization can be achieved, but labor intensity and time consumption increase significantly

Engineering Contradiction:
Improvepolicy accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service by automatically monitoring data flows, detecting sensitive information, and generating DLP policies without requiring manual intervention. The policy management system performs self-configuration by analyzing organizational data patterns and autonomously creating appropriate protection rules, eliminating the need for dedicated security personnel to manually craft policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where policy effectiveness is monitored and measured. Data flows are tracked against existing policies, and the system automatically adjusts and refines policies based on observed data patterns, policy violations, and organizational changes. This feedback mechanism ensures policies remain accurate and up-to-date without requiring manual review.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If manual policy creation is used, then policies can be customized to organizational needs, but specialized knowledge is required

Engineering Contradiction:
Improvepolicy customizationVSAvoidknowledge requirement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs self-configuration by automatically analyzing organizational data flows, identifying sensitive information types, and generating customized policies tailored to the specific organization's needs. The system adapts to organizational structures, data patterns, and compliance requirements autonomously, eliminating the need for specialized security knowledge to create customized policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of organizational data flows, user roles, and compliance requirements before policy creation. By pre-configuring policy templates based on detected data patterns and organizational structure, the system prepares customized policy frameworks in advance, reducing the complexity of policy deployment and ensuring adaptability to organizational needs.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If DLP solutions are deployed without policies, then deployment speed increases, but data protection effectiveness decreases

Engineering Contradiction:
Improvedeployment speedVSAvoidprotection effectiveness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary monitoring and analysis of data flows immediately upon deployment, gathering information about organizational data patterns, sensitive information types, and user behaviors. This preliminary action enables the system to automatically generate appropriate policies without requiring manual configuration, achieving both fast deployment and effective protection from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and feedback mechanisms that automatically detect sensitive data flows and trigger policy creation or adjustment. This real-time feedback ensures that protection effectiveness is maintained by dynamically adapting policies to actual data usage patterns, even during the initial deployment phase before manual policies exist.

Inventive Principle:
Principle #23Feedback

4Ease of manufacture

If integration service is used to provide policies, then initial policy setup is simplified, but ongoing maintenance requires vendor dependency

Engineering Contradiction:
Improvepolicy setup easeVSAvoidindependence
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system enables organizations to independently manage and maintain their own DLP policies through automated policy creation and adjustment capabilities. The self-service architecture allows organizations to autonomously adapt policies to changing needs without requiring vendor intervention, eliminating ongoing dependency while maintaining ease of policy management through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12255924B2Policy creation and adjustment methods
Publication Date: 2025.03.18 ACRONIS INT
  • US12255924B2 patent drawing
  • US12255924B2 patent drawing
  • US12255924B2 patent drawing

AI summary

A system to create Data Loss Prevention (DLP) policies and adjust DLP policies over time in a computing system using agents running at an endpoint to intercept a data transfer in a network traffic. New data flow/DLP policy rules are created and updated with reference to behavior data of trusted and untrusted users.