Data Transfer Risk Identification via Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in systematically detecting and preventing unauthorized data transfers between computing systems, which increases the risk of data breaches and loss incidents due to the complexity of managing data transfer restrictions across numerous devices and jurisdictions.

Innovation Solution

A method and system that analyze data transfer logs to determine authorized transfer restrictions, prevent unauthorized data transfers by blocking network communications, and provide an interface for requesting and overriding transfer restrictions based on location, jurisdiction, or data breach history, ensuring compliance with legal and industry standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data transfer restrictions are enforced across numerous devices and jurisdictions, then data security and compliance are improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between computing systems to enforce data transfer restrictions. This intermediary analyzes data transfer requests, determines compliance with restrictions, and facilitates or blocks transfers accordingly, thereby improving data security without requiring each individual system to implement complex restriction logic

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where data transfer attempts are monitored, analyzed against established restrictions, and results are fed back to control future transfers. This continuous feedback loop enables automated enforcement of security policies across distributed systems, reducing manual management complexity

Inventive Principle:
Principle #23Feedback

2Reliability

If automated detection and prevention of unauthorized data transfers is implemented, then data breach risk is reduced, but processing time and operational overhead increase

Engineering Contradiction:
Improvedata breach preventionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing data transfer restrictions and authorization criteria before actual data transfers occur. By having restrictions defined in advance and automatically applying them to transfer requests, the system enables rapid automated detection and prevention without requiring time-consuming manual review of each transfer

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated system performs self-service by independently analyzing data transfer requests, determining compliance with restrictions, and making enforcement decisions without human intervention. This self-service capability reduces operational overhead while maintaining rapid processing speeds through algorithmic decision-making

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12052289B2Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
Publication Date: 2024.07.30 ONETRUST LLC
  • US12052289B2 patent drawing
  • US12052289B2 patent drawing
  • US12052289B2 patent drawing

AI summary

A data transfer analysis system is disclosed that analyzes data transfer log entries to determine whether a data transfer is authorized. The system determines information about the data assets involved in the data transfer (e.g., network address, geographical location, etc.) and uses a data map to determine if data transfers are authorized between the two data assets. If not, the system may take one or more actions, such as generating a notification, terminating the data transfer, restricting the access of the user that initiated the transfer, modifying network communications capabilities between the assets to prevent future transfers, and storing metadata that can be used to prevent future such transfers.