Cloud Resource Metadata DLP for Fast Transaction Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud storage services lack effective data loss prevention (DLP) mechanisms for resource-level transactions that do not identify resource data, allowing sensitive information to be inadvertently transferred without detection.

Innovation Solution

A metadata-based solution that generates a resource list of cloud-based resources configured under an organization's accounts, using inline proxies and endpoint policy enforcers to intercept and block resource-level transactions attempting to manipulate these resources, thereby enforcing DLP policies without scanning the actual data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If content sensitivity scans are performed to detect sensitive data, then data security is improved, but computational complexity and processing time increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and analyzes metadata from cloud resources instead of scanning the actual data content. By taking out only the necessary identification information (metadata) and performing sensitivity scans on this extracted data rather than the full content, the system maintains security detection capability while dramatically reducing computational complexity and processing time.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If resource-level transactions are monitored and blocked to prevent data loss, then data security is improved, but system performance and transaction speed deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidtransaction speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by generating a resource list of cloud-based resources configured under organization accounts before monitoring transactions. By pre-identifying and storing metadata about protected resources, the system can quickly compare incoming transactions against this pre-prepared list, enabling fast blocking decisions without complex real-time analysis, thus maintaining both security and transaction speed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive DLP policies are enforced on all cloud resources, then data security is improved, but ease of operation and system simplicity worsen

Engineering Contradiction:
Improvedata securityVSAvoidsystem simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the cloud resource monitoring system into distinct components: a resource list generation module that creates metadata profiles of protected resources, and a transaction monitoring module that compares operations against this segmented resource list. This segmentation allows comprehensive DLP coverage while maintaining operational simplicity, as each segment handles a specific task independently without requiring complex integrated analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12355817B2Data loss prevention (DLP) for cloud resources via metadata analysis
Publication Date: 2025.07.08 NETSKOPE INC
  • US12355817B2 patent drawing
  • US12355817B2 patent drawing
  • US12355817B2 patent drawing

AI summary

The technology disclosed relates to an introspector that scans an organization's accounts on cloud storage services and detects resources on the cloud storage services configured to store the organization's data, and identifies the detected resources in a resource list. The technology disclosed further includes an inline proxy that controls manipulation of the detected resources based on the resource list.