Cloud Data Leakage Detection via Attribute Benchmarking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data leakage protection (DLP) solutions in cloud environments are coarse-grained and specific, failing to provide comprehensive protection against data breaches, particularly due to their reliance on expensive encryption methods that require users to access data through proxy solutions, which is not always feasible.

Innovation Solution

The combination of text scanners, API scanners, and cloud access security brokers (CASBs) is used to enhance data leakage protection by automating the discovery of altered data elements, improving data governance and classification, and reducing costs by enforcing DLP policies at gateways, while applying user access controls that are agnostic to specific SaaS providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption methods are used for data protection, then data security is improved, but cost increases

Engineering Contradiction:
Improvedata securityVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary actions by collecting data attributes and creating benchmark data in advance through text scanners and API scanners. This preprocessing enables later detection operations to compare against pre-established benchmarks, avoiding the need for expensive real-time encryption while maintaining security through anomaly detection based on learned normal patterns.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If proxy solutions are used for encryption and decryption, then data protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security function from complex encryption/decryption proxy systems. Instead of requiring full proxy infrastructure with encryption capabilities, the system extracts only the necessary attribute collection and benchmark comparison functions, implementing security through simplified attribute monitoring and anomaly detection against pre-created benchmarks.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If users must access data through proxy solutions, then data security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically collecting data attributes, creating benchmarks, and performing detection operations without requiring user intervention or mandatory proxy access. Users can access data through normal channels while the system independently performs security monitoring by comparing data against pre-established benchmarks, eliminating the need for users to route through complex proxy infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10178096B2Enhanced data leakage detection in cloud services
Publication Date: 2019.01.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10178096B2 patent drawing
  • US10178096B2 patent drawing
  • US10178096B2 patent drawing

AI summary

Embodiments describing an approach to receiving user data, and monitoring a user data transaction. Monitoring a user data transaction. Identifying a plurality of attribute elements associated with the user data and the user data transaction. Creating benchmark data based on one or more identified attributes and user data gathered from a user data transaction, and storing, by the one or more processors, benchmark data.