User-Configurable Data Leakage Isolation via Segmented Detection Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data leakage prevention technologies lack user-configurable and selectable action-based solutions, making it difficult for security professionals to effectively isolate devices involved in potential data leakage activities.

Innovation Solution

A system and method that allow user input to identify and isolate devices associated with potential data leakage activities, using a user interface to select and execute actions such as locking down, blocking access, or quarantining devices, through a network architecture that includes data leakage detection agents and policy enforcement servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If automated data leakage detection is implemented, then detection capability is improved, but user control and configurability are reduced

Engineering Contradiction:
Improvedetection capabilityVSAvoiduser control
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

The system segments the data leakage prevention functionality into distinct modular components: detection agents that identify potential leaks, policy servers that store configurable rules, and enforcement mechanisms that execute actions. This modular architecture allows independent configuration of each component while maintaining automated detection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic configurability where security policies, detection thresholds, and response actions can be modified in real-time without system restart. Users can dynamically adjust detection sensitivity, add or remove devices from monitoring, and change response protocols based on evolving security requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If comprehensive monitoring of all devices is implemented, then security coverage is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies differentiated monitoring strategies to different devices based on their risk profiles, data sensitivity, and operational characteristics. High-risk devices receive intensive monitoring with multiple detection agents, while low-risk devices use lighter monitoring approaches, optimizing resource allocation across the network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements selective monitoring where detection resources are concentrated on critical data flows and high-risk devices rather than uniformly monitoring all devices. This partial action approach maintains comprehensive security coverage for critical assets while reducing overall system complexity.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If real-time isolation actions are automatically executed, then response speed is improved, but risk of false positives and operational disruption increases

Engineering Contradiction:
Improveresponse speedVSAvoidfalse positive risk
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system pre-configures response actions and isolation protocols in advance through user-defined policies. When potential data leakage is detected, pre-programmed responses are executed based on the detected threat pattern, eliminating the need for real-time decision-making while maintaining rapid response capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where isolation actions are monitored and their effectiveness evaluated. If an isolation action appears to be a false positive, the system can automatically adjust detection thresholds or notify administrators for policy refinement, continuously improving accuracy based on operational feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10872148B2System, method, and computer program product for isolating a device associated with at least potential data leakage activity, based on user input
Publication Date: 2020.12.22 MCAFEE LLC
  • US10872148B2 patent drawing
  • US10872148B2 patent drawing
  • US10872148B2 patent drawing

AI summary

A system, method, and computer program product are provided for isolating a device associated with at least potential data leakage activity, based on user input. In operation, at least potential data leakage activity associated with a device is identified. Furthermore, at least one action is performed to isolate the device, based on user input received utilizing a user interface.