Context-Based External Storage Copy Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for monitoring data copy operations to external devices are overly restrictive, blocking all copy transactions rather than just malicious ones, which inhibits legitimate data transfer and lacks context-based differentiation.

Innovation Solution

A system and method that monitor external storage device connections and user activities to detect file copy operations, logging events and generating alerts only for suspicious or unauthorized data transfers, allowing legitimate copies to proceed while alerting administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all copy operations to external devices are blocked, then data security is improved, but legitimate data transfer is inhibited

Engineering Contradiction:
Improvedata securityVSAvoidlegitimate data transfer
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating between malicious and legitimate copy operations through context analysis. Instead of uniformly blocking all copy operations, the system analyzes specific characteristics of each copy event (source file type, destination device, user behavior patterns, timing) to determine whether to allow or block the operation. This selective approach maintains security while permitting legitimate transfers.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters by monitoring multiple contextual variables simultaneously (file type, device identifier, user activity state, copy frequency, time of day) rather than relying on a single binary block/allow decision. By evaluating changes in these parameters across multiple dimensions, the system can distinguish between normal and suspicious copy behaviors and respond appropriately.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encryption is applied to all data copied to external devices, then data protection is improved, but operational flexibility is reduced

Engineering Contradiction:
Improvedata protectionVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by applying encryption selectively rather than universally. The system evaluates each copy operation's context and applies encryption only to those identified as potentially malicious or high-risk, while leaving legitimate operations unencrypted. This targeted approach maintains data protection for sensitive information while preserving operational flexibility for routine transfers.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If comprehensive monitoring of user activities is implemented, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the monitoring system into distinct functional modules: event loggers that capture raw data, analysis engines that process specific event types, pattern recognition components that identify suspicious behaviors, and response systems that execute appropriate actions. This modular architecture improves detection accuracy through specialized processing while managing complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-establishing baselines of normal user behavior and pre-defining suspicious patterns before actual copy operations occur. By having detection rules and analysis frameworks ready in advance, the system can quickly evaluate copy events without complex real-time computation, improving detection accuracy while reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12164625B2Context based authorized external device copy detection
Publication Date: 2024.12.10 PROOFPOINT INC
  • US12164625B2 patent drawing
  • US12164625B2 patent drawing
  • US12164625B2 patent drawing

AI summary

A system and method monitors access of an external storage device connected to a target device. A notification of a connection of the external storage device to the target device is received, a notification of an external file access on the external storage device is received, and activity of a user on the target device is monitored to detect a user operation accessing a source file stored on the target device. Events are logged based upon the connection, the user operation, and the external file access. Two or more of the events are associated with a copy of the source file to the external connected storage device and the source file history. An alert regarding the association is forwarded to a monitor application in communication with the target device.