DLP Expression Building for Cloud Data Leak Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Data Loss Prevention (DLP) systems face challenges in monitoring and protecting sensitive data, especially in unstructured documents and encrypted SSL/TLS traffic, leading to increased risk of data loss due to lack of visibility and control, particularly when users access applications directly from anywhere, bypassing traditional security controls.

Innovation Solution

The implementation of a cloud-based DLP system that utilizes Indexed Document Matching (IDM) and DLP expression building, allowing for the combination of predefined and custom dictionaries through user-defined expressions, enabling detection of exact, similar, and partial content matches within unstructured documents, and performing actions based on configurable thresholds, while maintaining visibility and control across all user connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional DLP approaches using software agents and physical appliances are used, then security control is maintained within the network perimeter, but users accessing applications directly from anywhere create blind spots and bypass security controls

Engineering Contradiction:
Improvesecurity control effectivenessVSAvoiduser access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cloud-based DLP system provides universal security monitoring across multiple access points and environments. The system can monitor structured documents, unstructured documents, SSL/TLS traffic, and cloud applications through a single centralized platform, eliminating blind spots while maintaining security controls regardless of user location or access method.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If SSL/TLS traffic inspection is performed to monitor encrypted sensitive data, then visibility into encrypted traffic is achieved, but processing capability and latency are significantly increased

Engineering Contradiction:
Improvevisibility into encrypted trafficVSAvoidprocessing capability and latency
Core Design Contradiction:
Loss of informationVSPower

Solution Approach 1:

The system applies partial inspection to SSL/TLS traffic by monitoring metadata, headers, and selected portions of encrypted traffic rather than attempting to fully decrypt and inspect all content. This approach provides sufficient visibility to detect potential data loss while minimizing the processing overhead and latency associated with complete decryption and inspection.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If multiple DLP dictionaries with different violation thresholds and confidence thresholds are used, then comprehensive data detection capability is achieved, but it becomes difficult for dictionaries to work together and requires creating custom dictionaries for each expression

Engineering Contradiction:
Improvedata detection capabilityVSAvoiddictionary configuration and integration
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges multiple DLP dictionaries with different thresholds into a unified expression evaluation framework. The expression builder allows users to combine results from multiple dictionaries using logical operators (AND, OR, NOT) and configure composite thresholds, enabling comprehensive detection while simplifying the integration complexity through a standardized evaluation mechanism.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If DLP monitoring is performed only within the network perimeter using traditional appliances, then security control is maintained, but users accessing applications directly from anywhere bypass security controls creating blind spots

Engineering Contradiction:
Improvesecurity control coverageVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cloud-based DLP system acts as an intermediary between users and applications, providing security monitoring without requiring users to be within the network perimeter. The system intercepts and analyzes traffic between users and cloud applications, maintaining security controls while allowing users to access applications conveniently from any location.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11455407B2Data loss prevention expression building for a DLP engine
Publication Date: 2022.09.27 ZSCALER INC
  • US11455407B2 patent drawing
  • US11455407B2 patent drawing
  • US11455407B2 patent drawing

AI summary

Systems and methods include obtaining an expression for a Data Loss Prevention (DLP) engine, wherein the expression includes one or more DLP dictionaries that evaluate to a score for comparison with a corresponding threshold and one or more logical operators used to combine an evaluation of the one or more DLP dictionaries; storing the expression in a database associated with a DLP service; monitoring traffic from one or more users; evaluating the traffic using the DLP engine and the expression; and determining a DLP trigger based on a result of the expression that is a logical TRUE.