Dynamic DLP Policy Update for Outbound Data Transfer Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data loss prevention (DLP) systems are ineffective in identifying and protecting newly created sensitive information, such as design documents and pay statements, due to their reliance on exact content matching and keyword dictionaries, leading to high rates of false positives and inability to detect sensitive data leakage, especially in dynamic and complex communication environments.

Innovation Solution

A method and apparatus where a DLP agent temporarily blocks outbound data transfers and submits requests to update the DLP policy to protect information before permitting the transfer, using a DLP submission tool that integrates with email and browser applications to categorize and protect sensitive information, even if it is unknown to the DLP system a priori.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional DLP systems use described content matching techniques (regular expressions, keyword dictionaries) to protect sensitive information, then known sensitive data can be identified and protected, but new and unknown sensitive information cannot be detected, leading to high false positive rates and inability to protect newly created sensitive content

Engineering Contradiction:
Improvedetection accuracy of sensitive informationVSAvoidability to detect new unknown sensitive information
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary classification of outbound data transfers into categories (personal information, business information, etc.) before applying specific DLP rules. This preliminary action enables the system to prepare appropriate protection strategies in advance for different types of data, improving both detection accuracy and adaptability to new information types

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The DLP system dynamically adapts its detection methods based on the category of data being transferred. Instead of using static keyword matching for all data types, the system adjusts its classification and protection rules dynamically according to the identified data category, enabling it to effectively protect both known and newly emerging sensitive information types

Inventive Principle:
Principle #15Dynamics

2Reliability

If DLP systems deploy comprehensive monitoring rules to detect all sensitive information, then detection coverage increases, but system complexity and false positive rates increase

Engineering Contradiction:
Improveprotection coverage of sensitive dataVSAvoidcomplexity of DLP system and rules
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the DLP process into distinct stages: preliminary classification of outbound data transfers into categories, followed by category-specific rule application. This segmentation divides the complex monitoring task into manageable segments, reducing overall system complexity while maintaining comprehensive protection coverage through structured multi-stage processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different DLP rules and classification criteria are applied to different categories of data transfers. Instead of using a single complex rule set for all data types, the system applies localized, category-specific rules that are tailored to each data type's characteristics, reducing false positives while maintaining high detection accuracy for each category

Inventive Principle:
Principle #3Local quality

3Reliability

If DLP systems use TAGS to classify email messages to prevent forwarding, then email filtering effectiveness improves, but users can still circumvent filters by printing or copying content

Engineering Contradiction:
Improveemail filter effectivenessVSAvoiddata leakage through circumvention methods
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system classifies and marks sensitive information in outbound data transfers before the data leaves the organization. By performing this classification action preliminarily, the system ensures that sensitive information is identified and protected through multiple mechanisms before circumvention attempts can occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary classification and marking mechanism that operates between the user's data transfer action and the external destination. This intermediary layer categorizes data and applies appropriate protection measures, creating a barrier that prevents direct circumvention while maintaining controlled data flow

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8990882B1Pre-calculating and updating data loss prevention (DLP) policies prior to distribution of sensitive information
Publication Date: 2015.03.24 CA TECH INC
  • US8990882B1 patent drawing
  • US8990882B1 patent drawing
  • US8990882B1 patent drawing

AI summary

A method and apparatus submitting information to be protected before permitting an outbound data transfer with the information is described. A DLP agent, incorporating a DLP submission tool, receives information of an outbound data transfer by the client computing system. The DLP agent can temporarily block the outbound data transfer and send a request to update a DLP policy to protect the information before permitting the outbound data transfer. The DLP agent subsequently receives receiving an indication that the DLP policy is updated to protect the information. After receiving the indication, the DLP agent permits the outbound data transfer.