Dynamic DLP Policy Update for Outbound Data Transfer Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data loss prevention (DLP) systems are ineffective in identifying and protecting newly created sensitive information, such as design documents and pay statements, due to their reliance on exact content matching and keyword dictionaries, leading to high rates of false positives and inability to detect sensitive data leakage, especially in dynamic and complex communication environments.
Innovation Solution
A method and apparatus where a DLP agent temporarily blocks outbound data transfers and submits requests to update the DLP policy to protect information before permitting the transfer, using a DLP submission tool that integrates with email and browser applications to categorize and protect sensitive information, even if it is unknown to the DLP system a priori.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional DLP systems use described content matching techniques (regular expressions, keyword dictionaries) to protect sensitive information, then known sensitive data can be identified and protected, but new and unknown sensitive information cannot be detected, leading to high false positive rates and inability to protect newly created sensitive content
Solution Approach 1:
The system performs preliminary classification of outbound data transfers into categories (personal information, business information, etc.) before applying specific DLP rules. This preliminary action enables the system to prepare appropriate protection strategies in advance for different types of data, improving both detection accuracy and adaptability to new information types
Solution Approach 2:
The DLP system dynamically adapts its detection methods based on the category of data being transferred. Instead of using static keyword matching for all data types, the system adjusts its classification and protection rules dynamically according to the identified data category, enabling it to effectively protect both known and newly emerging sensitive information types
2Reliability
If DLP systems deploy comprehensive monitoring rules to detect all sensitive information, then detection coverage increases, but system complexity and false positive rates increase
Solution Approach 1:
The system segments the DLP process into distinct stages: preliminary classification of outbound data transfers into categories, followed by category-specific rule application. This segmentation divides the complex monitoring task into manageable segments, reducing overall system complexity while maintaining comprehensive protection coverage through structured multi-stage processing
Solution Approach 2:
Different DLP rules and classification criteria are applied to different categories of data transfers. Instead of using a single complex rule set for all data types, the system applies localized, category-specific rules that are tailored to each data type's characteristics, reducing false positives while maintaining high detection accuracy for each category
3Reliability
If DLP systems use TAGS to classify email messages to prevent forwarding, then email filtering effectiveness improves, but users can still circumvent filters by printing or copying content
Solution Approach 1:
The system classifies and marks sensitive information in outbound data transfers before the data leaves the organization. By performing this classification action preliminarily, the system ensures that sensitive information is identified and protected through multiple mechanisms before circumvention attempts can occur
Solution Approach 2:
The system introduces an intermediary classification and marking mechanism that operates between the user's data transfer action and the external destination. This intermediary layer categorizes data and applies appropriate protection measures, creating a barrier that prevents direct circumvention while maintaining controlled data flow
Data Source
AI summary
A method and apparatus submitting information to be protected before permitting an outbound data transfer with the information is described. A DLP agent, incorporating a DLP submission tool, receives information of an outbound data transfer by the client computing system. The DLP agent can temporarily block the outbound data transfer and send a request to update a DLP policy to protect the information before permitting the outbound data transfer. The DLP agent subsequently receives receiving an indication that the DLP policy is updated to protect the information. After receiving the indication, the DLP agent permits the outbound data transfer.


