Data Positioning and Alerting System for Confidential File Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention technologies cannot effectively track the usage and location of confidential files within a computer network, nor can they adequately prevent intentional or malicious leakage of sensitive information, and they often waste CPU cycles by separate scanning for malware, spam, and data leakage detection.

Innovation Solution

A data positioning and alerting system that assigns unique identifiers to confidential files, creates file policies for monitoring activities, and uses a software agent to track and block risky actions, allowing for real-time monitoring and approval processes to prevent unauthorized data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based DLP products are used to prevent data leakage, then data leakage prevention capability is improved, but the system cannot track file usage and location

Engineering Contradiction:
Improvedata leakage prevention capabilityVSAvoidfile usage and location tracking
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the DLP system into two distinct components: signature-based detection mechanisms for identifying sensitive files, and a file activity monitoring component using file system hooks to track usage and location. This segmentation allows each component to specialize in its strength while the integrated system provides both prevention and tracking capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges signature-based DLP detection with file activity monitoring into a unified system. The file activity monitor combines information from multiple sources (file system hooks, process monitors, network monitors) to create a comprehensive view of file usage, merging previously separate functions into one integrated solution that provides both leakage prevention and tracking.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple separate scanning systems are used for malware detection, spam detection, and data leakage prevention, then comprehensive security coverage is improved, but CPU cycles are wasted

Engineering Contradiction:
Improvesecurity coverageVSAvoidCPU cycle consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges multiple security scanning functions into a single integrated system that performs malware detection, spam detection, and data leakage prevention simultaneously. By consolidating these separate scanning operations into one unified security platform, the system maintains comprehensive security coverage while reducing redundant CPU cycles through coordinated processing and shared resources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security platform that performs multiple security functions through a single system architecture. The file activity monitor and policy enforcement mechanism serve as a multi-functional core that handles various security threats (malware, spam, data leakage) using shared detection and response capabilities, eliminating the need for separate dedicated systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8499152B1Data positioning and alerting system
Publication Date: 2013.07.30 TREND MICRO INC
  • US8499152B1 patent drawing
  • US8499152B1 patent drawing
  • US8499152B1 patent drawing

AI summary

A file policy is created for each confidential file in a server computer including a list of events and a corresponding action. The file policies for the confidential files are sent to each client computer in the computer network. A software agent on each client computer detects when an activity occurs that affects one of the confidential files having a file policy. The activity is reported to the server computer and, if the activity matches an event in the policy, the corresponding action is taken. Events include: copying a file, printing, accessing, sending via e-mail, renaming, etc. Actions include: alerting an administrator, temporary blocking the activity or preventing the activity. If the activity is temporarily blocked from occurring, the agent queries the user as to whether the user wishes to request approval, and forwards that requests on to the server computer. If the activity is approved then the software agent removes the temporary block from the user activity and allows the user's activity concerning the confidential file to occur.