Data Protection Workflow System for Network Inventory Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security approaches, particularly data loss prevention (DLP), face challenges in efficiently managing and protecting large volumes of unstructured data due to lack of visibility and the labor-intensive process of identifying and categorizing sensitive information within networks, often leading to over-inclusive or under-inclusive data protection policies.

Innovation Solution

A data protection workflows system that utilizes metadata and classification techniques to inventory, classify, and protect data within a network environment through analytics, allowing for remediation and registration tasks, enabling efficient data management and protection by applying policies based on detailed metadata analysis and user-defined categories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual methods are used to identify and categorize sensitive information in a network, then data protection can be implemented, but the process becomes labor-intensive and time-consuming

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidtime to identify and categorize data
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical processes of identifying and categorizing sensitive data with automated electronic systems. The system uses metadata analysis, classification algorithms, and automated policy application to substitute human labor with computational processes, thereby reducing time loss while maintaining protection effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service data protection by automatically discovering, classifying, and applying protection policies to sensitive data without requiring manual intervention. The automated classification system independently identifies sensitive information and applies appropriate protection measures, making the system self-sufficient in data protection tasks.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive data protection policies are applied to all data in the network, then data security is improved, but the complexity of managing and enforcing these policies increases

Engineering Contradiction:
Improvedata securityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by tailoring data protection policies to specific data characteristics rather than applying uniform policies across all data. The system classifies data into different categories based on sensitivity and applies appropriate protection measures to each category, reducing overall policy management complexity while maintaining comprehensive security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters by dynamically adjusting protection levels based on data classification results. Different protection parameters (encryption, access control, monitoring) are applied according to the sensitivity level of each data category, making policy management more manageable through parameterized approaches.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If detailed classification and metadata analysis are performed on all data, then visibility and control over sensitive information is improved, but the processing time and computational resources increase

Engineering Contradiction:
Improvevisibility of sensitive dataVSAvoidprocessing time for classification
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies partial action by performing detailed metadata analysis and classification only on data that requires protection, rather than processing all data uniformly. The system identifies and focuses computational resources on sensitive data categories, achieving necessary visibility without the overhead of comprehensive processing of all network data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system segments data processing by dividing the network data into different categories and subsets based on sensitivity levels. This segmentation allows the system to apply different processing intensities to different data segments, improving visibility into sensitive data while reducing overall processing time through selective analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8700561B2System and method for providing data protection workflows in a network environment
Publication Date: 2014.04.15 MCAFEE LLC
  • US8700561B2 patent drawing
  • US8700561B2 patent drawing
  • US8700561B2 patent drawing

AI summary

A method is provided in one example and includes receiving first sets of metadata elements representing an inventory of objects in a data storage location of a network environment and presenting an inventory view of the objects to a user. The inventory view includes a first summary of the inventory objects. The method further includes receiving a request from the user to manipulate the inventory view based on a first selected dimension group and presenting to the user a manipulated inventory view that includes a second summary of a first subset of the inventory objects. In more specific embodiments, the method includes receiving a request from the user to perform a protection task on objects of the first subset and initiating the protection task. The protection task includes one of applying a remediation policy to the objects of the first subset and registering the objects of the first subset.