Host-Based DLP Agent with Encryption Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing host-based data loss prevention systems fail to securely manage sensitive data when it leaves the organizational boundaries, as they lack effective encryption mechanisms for data channels like removable devices and email.

Innovation Solution

Integration of a data loss prevention agent with file and full disk encryption software, which queries encryption status and enforces encryption policies to secure data by allowing only encrypted files to be written to removable devices and blocking unencrypted sensitive data from being sent via email.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-based DLP agents monitor and block data loss activities within organizational boundaries, then data loss prevention capability is improved, but the system fails to secure data when it leaves the organization

Engineering Contradiction:
Improvedata loss prevention capabilityVSAvoiddata security coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges the DLP agent with encryption software to create an integrated system. The DLP agent queries the encryption software to determine encryption status of data destinations and files, combining data loss prevention functionality with encryption capabilities to secure data both within and outside organizational boundaries

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The encryption software acts as an intermediary between the DLP agent and the data storage/transmission channels. The DLP agent queries the encryption software for encryption status information, and the encryption software mediates the decision-making process for allowing or blocking data operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the DLP agent queries encryption software for encryption status detection, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption software serves multiple functions: it provides encryption operations, answers encryption status queries from the DLP agent, and enables the DLP agent to make informed decisions about data operations. This multi-functionality reduces the need for separate dedicated components

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The DLP agent queries the encryption software to obtain encryption status information, which provides feedback about the security state of data destinations and files. This feedback mechanism enables the DLP agent to dynamically adjust its blocking or allowing decisions based on current encryption status

Inventive Principle:
Principle #23Feedback

3Reliability

If the system blocks access to unencrypted data destinations, then data security is improved, but data transfer efficiency decreases

Engineering Contradiction:
Improvedata securityVSAvoiddata transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary encryption status detection before allowing data operations. The DLP agent queries the encryption software to determine if data destinations or files are encrypted before attempting to write or transmit data, preventing blocking of legitimate encrypted operations while stopping unencrypted data loss

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8893285B2Securing data using integrated host-based data loss agent with encryption detection
Publication Date: 2014.11.18 MCAFEE LLC
  • US8893285B2 patent drawing
  • US8893285B2 patent drawing
  • US8893285B2 patent drawing

AI summary

A method and system for securing data in a computer system provides the capability to secure information even when it leaves the boundaries of the organization using a data loss agent integrated with encryption software. A method for securing data in a computer system comprises detecting attempted connection or access to a data destination to which sensitive data may be written, determining an encryption status of the data destination, allowing the connection or access to the data destination when the data destination is encrypted, and taking action to secure the sensitive data when the data destination is not encrypted.