Data Loss Prevention System Source Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data loss prevention (DLP) systems struggle to accurately identify and protect unstructured sensitive data and intellectual property, such as product formulas, source code, and sales reports, as they fail to recognize new items or modifications, leading to inadequate monitoring and protection.

Innovation Solution

The system tracks and accounts for the points of entry and sources of files on networks protected by DLP techniques, differentiating between corporate and personal data by generating unique identifiers and looking up sources in a database, applying DLP policies based on the file's source, thereby improving accuracy with minimal computing resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If fingerprinting and describing technologies are used to protect sensitive data, then existing data can be identified, but new items of sensitive data and modifications cannot be accurately identified

Engineering Contradiction:
Improveaccuracy of identifying sensitive dataVSAvoidability to identify new sensitive data
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by tracking and recording the source of files when they are first introduced into the network. This creates a database of file sources that enables later identification of sensitive data without requiring pre-existing knowledge of the data content. The source tracking is established in advance, allowing the system to adapt to new sensitive data types as they appear.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - a database that stores the relationship between file sources and file identifiers. This intermediary enables the system to identify sensitive data by referencing the stored source information rather than relying solely on content analysis, thereby improving both accuracy and adaptability to new data types.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If source tracking and database lookups are implemented to improve DLP accuracy, then identification accuracy improves, but computing resource consumption increases

Engineering Contradiction:
Improveaccuracy of file source identificationVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs source tracking and database entry creation as a preliminary action when files are first introduced. By establishing the source-information linkage upfront, the system avoids the need for continuous, resource-intensive analysis of file contents during subsequent security assessments, thereby reducing ongoing computing resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of repeatedly analyzing the actual file contents to determine sensitivity, the system uses a lightweight copy approach by storing and referencing file source information in a database. This allows rapid identification of sensitive files through simple database lookups rather than computationally expensive content analysis.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9245132B1Systems and methods for data loss prevention
Publication Date: 2016.01.26 GEN DIGITAL INC
  • US9245132B1 patent drawing
  • US9245132B1 patent drawing
  • US9245132B1 patent drawing

AI summary

A computer-implemented method for data loss prevention may include (1) identifying a network configured with a data loss prevention system, (2) identifying a file subject to a data loss prevention assessment within the network, (3) identifying an origin of the file, (4) determining that the origin of the file is outside the network, and (5) determining that the origin of the second file does not contain sensitive information intended to be protected by the data loss prevention system. Various other methods, systems, and computer-readable media are also disclosed.