Data Loss Prevention Policy Conflict Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data loss prevention systems face challenges in managing conflicting policies and determining the appropriate action when resources match multiple definitions for sensitive content categories, leading to policy precedence issues and increased complexity in managing overlapping policies.
Innovation Solution
A technique that creates an effective policy by combining the most permissive enforcement actions from each applicable content category and then selecting the least permissive action to determine whether a user action is permitted on a resource, thereby addressing the policy precedence problem without requiring explicit rules for handling conflicts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple content categories are used to define sensitive information, then the coverage of data protection is improved, but the complexity of policy management increases due to overlapping policies and precedence issues
Solution Approach 1:
The patent segments the policy management process into distinct steps: identifying applicable content categories, determining their intersections, and applying policies in a structured sequence. This segmentation breaks down the complex problem of overlapping policies into manageable components, allowing each content category to be evaluated independently while maintaining overall policy coherence.
Solution Approach 2:
The patent performs preliminary actions by pre-identifying and categorizing content categories before policy enforcement. By establishing the hierarchy and intersections of content categories in advance, the system prepares the policy evaluation framework beforehand, eliminating the need for complex real-time precedence resolution during actual data protection operations.
2Measurement precision
If explicit rules are created to handle policy conflicts, then the precision of policy enforcement is improved, but the difficulty of policy management increases
Solution Approach 1:
The patent implements a self-service mechanism where the system automatically determines policy applicability by identifying content categories and their intersections. Instead of requiring explicit conflict-resolution rules, the system serves itself by evaluating which content categories apply to each data element and enforcing policies based on this automatic classification, thereby achieving precise enforcement without increasing management complexity.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of content category identification and intersection analysis. This intermediary layer sits between the raw data and the policy enforcement logic, automatically determining which policies apply based on the data's classification. This intermediary eliminates the need for complex explicit conflict-resolution rules while maintaining precise policy enforcement.
3Measurement precision
If comprehensive content inspection is performed to identify sensitive information, then the accuracy of data loss prevention is improved, but the processing time increases
Solution Approach 1:
The patent performs preliminary classification of data into content categories before detailed policy evaluation. By pre-identifying the relevant content categories and their intersections, the system prepares the evaluation framework in advance, allowing for accurate sensitive information detection without requiring time-consuming comprehensive inspection of all policies for every data element.
Solution Approach 2:
The patent segments the inspection process into distinct phases: content category identification, intersection determination, and policy application. This segmentation allows the system to focus computational resources on identifying relevant content categories first, then applying only the applicable policies, thereby maintaining high detection accuracy while reducing overall processing time compared to exhaustive inspection of all policies.
Data Source
AI summary
A technique for performing data loss prevention includes creating for a user, using a data processing system, respective permissive policies with a most permissive enforcement action for each content category of a resource. In this case, the content category includes at least two categories. The technique also includes forming, using the data processing system, a policy set based on the respective permissive policies. The technique further includes creating, using the data processing system, an effective policy from the policy set using a least permissive enforcement action. Finally, the technique includes applying, using the data processing system, the effective policy to determine whether a user action is permitted on the resource.


