Automated Data Tagging for Breach Source Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face challenges in detecting and mitigating security breaches related to the dissemination of protected data, as manual breach detection processes are costly, time-consuming, and often fail to identify the source of the breach.

Innovation Solution

A method and system that analyze electronic information communicated to a secured network from external sources to identify protected data and determine anomalous receipt, thereby identifying sources of egress and taking preventive actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual breach detection processes are used to identify security breaches, then security personnel can investigate potential breaches, but the process is costly, time-consuming, and frequently fails to identify the source of the breach

Engineering Contradiction:
Improvebreach detection accuracyVSAvoidbreach detection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary data classification and tagging within the secured network before breaches occur. When protected data is identified, it is pre-tagged with unique identifiers and metadata, creating a foundation for rapid automated tracking. This preliminary action enables the system to automatically trace data movements and identify breach sources without manual intervention, resolving the contradiction by enabling fast, accurate detection through pre-configured automated responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where data movements are monitored, analyzed, and used to update security policies in real-time. When potential breaches are detected, the system automatically traces the data lineage, identifies the source, and provides feedback to security personnel with actionable intelligence. This feedback mechanism eliminates the need for manual investigation while improving both speed and accuracy of breach detection.

Inventive Principle:
Principle #23Feedback

2Reliability

If DLP policies are implemented to monitor egress channels and prevent movement of protected data, then data protection is enhanced, but security breaches still occur through unauthorized channels

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidbreach prevention coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements a universal tagging mechanism that can identify and track protected data across multiple egress channels and communication protocols. The same tagging infrastructure works for email, file transfers, cloud uploads, and other data movement vectors, providing comprehensive coverage without requiring separate solutions for each channel. This multi-functionality resolves the contradiction by enabling broad breach prevention coverage while maintaining strong data protection through a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces data tagging as an intermediary mechanism that bridges the gap between DLP policies and actual data movements. Instead of directly blocking all potential egress channels, the system uses tags to mark protected data and automatically traces its journey through the network. This intermediary approach allows the system to adapt to various breach vectors while maintaining effective data protection, resolving the contradiction between protection effectiveness and prevention coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security systems monitor and block data egress to prevent breaches, then data exfiltration is reduced, but the system cannot identify the source of breaches when they occur

Engineering Contradiction:
Improvebreach prevention capabilityVSAvoidbreach source identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary tagging of protected data with unique identifiers and metadata before any breach can occur. This pre-configured tagging creates a traceable lineage for all protected data movements, enabling automatic source identification when breaches are detected. The preliminary action of tagging resolves the contradiction by making breach source identification as easy as data protection itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback tracking of tagged data through the network, automatically recording all movements and access points. When breaches are detected, the feedback mechanism provides immediate information about the data's journey, automatically identifying the source without requiring additional investigation. This feedback loop resolves the contradiction by making breach source identification as effective as the prevention capability itself.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11134087B2System identifying ingress of protected data to mitigate security breaches
Publication Date: 2021.09.28 FORCEPOINT LLC
  • US11134087B2 patent drawing
  • US11134087B2 patent drawing
  • US11134087B2 patent drawing

AI summary

A method, system and computer-usable medium for mitigating security breaches associated with dissemination of protected data. In certain embodiments, the method includes receiving information communicated to a secured network from a source external to the secured network and determining whether the received information includes protected data. If the received information includes protected data, a determination is made as to whether the receipt of the protected data is anomalous. If the receipt of the protected data is anomalous, one or more sources of egress of the protected data from the secured network are identified. By identifying the sources of egress, actions may be taken to prevent future egress of the protected data.