DLP Expression Building for Cloud Data Leak Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Data Loss Prevention (DLP) systems face challenges in monitoring and protecting sensitive data, especially in unstructured documents and encrypted SSL/TLS traffic, leading to increased risk of data loss due to lack of visibility and control, particularly when users access applications directly from anywhere, bypassing traditional security controls.
Innovation Solution
The implementation of a cloud-based DLP system that utilizes Indexed Document Matching (IDM) and DLP expression building, allowing for the combination of predefined and custom dictionaries through user-defined expressions, enabling detection of exact, similar, and partial content matches within unstructured documents, and performing actions based on configurable thresholds, while maintaining visibility and control across all user connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional DLP approaches using software agents and physical appliances are used, then security control is maintained within the network perimeter, but users accessing applications directly from anywhere create blind spots and bypass security controls
Solution Approach 1:
The cloud-based DLP system provides universal security monitoring across multiple access points and environments. The system can monitor structured documents, unstructured documents, SSL/TLS traffic, and cloud applications through a single centralized platform, eliminating blind spots while maintaining security controls regardless of user location or access method.
2Loss of information
If SSL/TLS traffic inspection is performed to monitor encrypted sensitive data, then visibility into encrypted traffic is achieved, but processing capability and latency are significantly increased
Solution Approach 1:
The system applies partial inspection to SSL/TLS traffic by monitoring metadata, headers, and selected portions of encrypted traffic rather than attempting to fully decrypt and inspect all content. This approach provides sufficient visibility to detect potential data loss while minimizing the processing overhead and latency associated with complete decryption and inspection.
3Measurement precision
If multiple DLP dictionaries with different violation thresholds and confidence thresholds are used, then comprehensive data detection capability is achieved, but it becomes difficult for dictionaries to work together and requires creating custom dictionaries for each expression
Solution Approach 1:
The system merges multiple DLP dictionaries with different thresholds into a unified expression evaluation framework. The expression builder allows users to combine results from multiple dictionaries using logical operators (AND, OR, NOT) and configure composite thresholds, enabling comprehensive detection while simplifying the integration complexity through a standardized evaluation mechanism.
4Reliability
If DLP monitoring is performed only within the network perimeter using traditional appliances, then security control is maintained, but users accessing applications directly from anywhere bypass security controls creating blind spots
Solution Approach 1:
The cloud-based DLP system acts as an intermediary between users and applications, providing security monitoring without requiring users to be within the network perimeter. The system intercepts and analyzes traffic between users and cloud applications, maintaining security controls while allowing users to access applications conveniently from any location.
Data Source
AI summary
Systems and methods include obtaining an expression for a Data Loss Prevention (DLP) engine, wherein the expression includes one or more DLP dictionaries that evaluate to a score for comparison with a corresponding threshold and one or more logical operators used to combine an evaluation of the one or more DLP dictionaries; storing the expression in a database associated with a DLP service; monitoring traffic from one or more users; evaluating the traffic using the DLP engine and the expression; and determining a DLP trigger based on a result of the expression that is a logical TRUE.


