Cloud-Native DLP via CASB Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security enforcement points are limited in their ability to dynamically fingerprint files in cloud-native services, making data loss prevention (DLP) less effective and scalable as organizations increasingly store sensitive files in cloud environments.
Innovation Solution
A security enforcement point is enabled to obtain and utilize DLP fingerprints generated based on files stored in cloud-native services, allowing for dynamic monitoring and protection of sensitive data across cloud storage locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional DLP fingerprinting methods are used with on-premises file shares, then DLP can effectively monitor and protect sensitive data, but the system cannot dynamically fingerprint files stored in cloud-native services
Solution Approach 1:
The patent introduces a cloud access security broker (CASB) as an intermediary component that bridges the security enforcement point and cloud-native services. The CASB dynamically generates DLP fingerprints for files stored in cloud environments and delivers them to the security enforcement point, enabling the system to monitor and protect cloud-based sensitive data without compromising DLP effectiveness
Solution Approach 2:
The system architecture is segmented into distinct functional components: the security enforcement point that performs DLP scanning, the CASB that generates and manages cloud file fingerprints, and the cloud-native services that store files. This segmentation allows each component to specialize in its function, with the CASB handling the complexity of cloud file access and fingerprint generation while the security enforcement point focuses on DLP policy enforcement
2Ease of operation
If organizations migrate sensitive files to cloud-native services, then data accessibility and collaboration improve, but existing security enforcement points cannot dynamically monitor these files
Solution Approach 1:
The system implements a feedback mechanism where the CASB continuously monitors changes in cloud-native file storage and dynamically updates DLP fingerprints in real-time. When files are added, modified, or deleted in cloud environments, the CASB detects these changes and promptly delivers updated fingerprints to the security enforcement point, ensuring continuous monitoring capability without hindering data accessibility
Solution Approach 2:
The CASB proactively generates and pre-delivers DLP fingerprints for files before they are accessed or transmitted. By establishing the fingerprint database in advance and maintaining it through continuous synchronization with cloud storage changes, the system ensures that security enforcement points can immediately detect and block sensitive data exfiltration without delay
Data Source
AI summary
Systems and methods for performing fingerprint-based data loss prevention (DLP) using information obtained from a cloud-native service are provided. In one example, DLP fingerprints are obtained by a security enforcement system (e.g., a network security appliance, a secure access service edge (SASE) platform, or a security service edge (SSE)). The DLP fingerprints may be generated locally by the security enforcement system or generated remotely from the security service edge based on a set of files stored in a cloud-native service, representing, for example, infrastructure-as-a-service (IaaS) (e.g., an object storage service) or Software-as-a-service (SaaS) (e.g., a file hosting service or a productivity platform). Based at least in part on the DLP fingerprints, DLP is performed on a file by a DLP service of the security enforcement system, in which the file is at rest on an endpoint protected by the security enforcement system or in transit through the security enforcement point.


