Context-Based External Storage Copy Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions for monitoring data copy operations to external devices are overly restrictive, blocking all copy transactions rather than just malicious ones, which inhibits legitimate data transfer and lacks context-based differentiation.
Innovation Solution
A system and method that monitor external storage device connections and user activities to detect file copy operations, logging events and generating alerts only for suspicious or unauthorized data transfers, allowing legitimate copies to proceed while alerting administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all copy operations to external devices are blocked, then data security is improved, but legitimate data transfer is inhibited
Solution Approach 1:
The patent applies local quality by differentiating between malicious and legitimate copy operations through context analysis. Instead of uniformly blocking all copy operations, the system analyzes specific characteristics of each copy event (source file type, destination device, user behavior patterns, timing) to determine whether to allow or block the operation. This selective approach maintains security while permitting legitimate transfers.
Solution Approach 2:
The system changes parameters by monitoring multiple contextual variables simultaneously (file type, device identifier, user activity state, copy frequency, time of day) rather than relying on a single binary block/allow decision. By evaluating changes in these parameters across multiple dimensions, the system can distinguish between normal and suspicious copy behaviors and respond appropriately.
2Reliability
If encryption is applied to all data copied to external devices, then data protection is improved, but operational flexibility is reduced
Solution Approach 1:
The patent applies local quality by applying encryption selectively rather than universally. The system evaluates each copy operation's context and applies encryption only to those identified as potentially malicious or high-risk, while leaving legitimate operations unencrypted. This targeted approach maintains data protection for sensitive information while preserving operational flexibility for routine transfers.
3Measurement precision
If comprehensive monitoring of user activities is implemented, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the monitoring system into distinct functional modules: event loggers that capture raw data, analysis engines that process specific event types, pattern recognition components that identify suspicious behaviors, and response systems that execute appropriate actions. This modular architecture improves detection accuracy through specialized processing while managing complexity through clear separation of concerns.
Solution Approach 2:
The system performs preliminary action by pre-establishing baselines of normal user behavior and pre-defining suspicious patterns before actual copy operations occur. By having detection rules and analysis frameworks ready in advance, the system can quickly evaluate copy events without complex real-time computation, improving detection accuracy while reducing operational complexity.
Data Source
AI summary
A system and method monitors access of an external storage device connected to a target device. A notification of a connection of the external storage device to the target device is received, a notification of an external file access on the external storage device is received, and activity of a user on the target device is monitored to detect a user operation accessing a source file stored on the target device. Events are logged based upon the connection, the user operation, and the external file access. Two or more of the events are associated with a copy of the source file to the external connected storage device and the source file history. An alert regarding the association is forwarded to a monitor application in communication with the target device.


