Sensitive Data Leakage Path Identification System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in detecting and preventing accidental non-compliance with data privacy regulations like GDPR, particularly when sensitive data can inadvertently travel to prohibited geographic locations due to scattered content sources and inappropriate user permissions.
Innovation Solution
A system and method that identify potential leakage paths of sensitive information by discovering users with read permissions, determining additional information transfer paths, and flagging prohibited locations or users, with the capability to prevent data transfer or access through flagged paths and users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If organizations scatter content sources across multiple geographic locations to improve service accessibility, then user access convenience is improved, but the risk of sensitive data inadvertently reaching prohibited locations increases
Solution Approach 1:
The system performs preliminary analysis of information transfer paths before data actually flows through them. It proactively identifies potential leakage paths by analyzing user permissions, storage locations, and transfer routes in advance, allowing organizations to take preventive measures before compliance violations occur.
Solution Approach 2:
The system continuously monitors and analyzes information transfer paths, providing feedback about potential compliance risks. When new leakage paths are detected or when user permissions change, the system updates its analysis and alerts relevant stakeholders, enabling continuous compliance management in dynamic distributed environments.
2Measurement precision
If manual monitoring of data transfer paths is implemented to detect non-compliance, then detection capability is improved, but operational complexity and resource requirements increase significantly
Solution Approach 1:
The system automatically performs compliance analysis without requiring manual intervention. It self-configures by discovering users with read permissions, automatically analyzing information transfer paths, and generating compliance reports. The system manages its own operation by continuously monitoring permission changes and updating path analyses autonomously.
Solution Approach 2:
The patent replaces manual mechanical monitoring processes with automated computational analysis. Instead of human operators manually tracking data flows and permissions, the system uses automated algorithms to analyze user permissions, map information transfer paths, and identify compliance risks, dramatically reducing operational complexity.
3Reliability
If comprehensive analysis of all information transfer paths is performed to ensure compliance, then compliance accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The system extracts and focuses analysis only on relevant information transfer paths involving sensitive data and users with appropriate permissions. Rather than analyzing all possible data flows in the organization, it selectively identifies and analyzes only those paths that pose compliance risks, significantly reducing processing requirements while maintaining accuracy.
Solution Approach 2:
The compliance analysis is segmented into discrete, manageable components: discovering users with read permissions, identifying information transfer paths for each user, analyzing each path for compliance issues, and generating targeted reports. This segmentation allows the system to process complex compliance requirements in smaller, more efficient steps.
Data Source
AI summary
A computer-implemented method for identifying possible leakage paths of sensitive information may include (i) discovering an original set of users having permission to read the sensitive information at an originating storage device in an originating location via an original set of information transfer paths and (ii) performing a security action. The security action may include (A) determining an additional set of information transfer paths having information transfer paths other than the information transfer paths already discovered, via which the original set of users can write the sensitive information and (B) identifying an additional set of users having permission to read the sensitive information via the additional set of information transfer paths.


