Document Sensitivity Detection via Communication Path Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting and preventing the unauthorized distribution of sensitive documents, such as outtrusion, are prone to errors and costs due to manual processes, and struggle to accurately differentiate between sensitive and public documents, especially when content is copied or repurposed.
Innovation Solution
A method that determines and monitors the communication path of electronic documents, computing their sensitivity based on the trust levels of senders and recipients, and applies this sensitivity to limit distribution within and across an organization's perimeter, using a combination of tracking internal communication and machine-learning to differentiate between benign and malicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If explicit identification of classified documents is used, then document sensitivity detection is achieved, but manual work cost and error rate increase
Solution Approach 1:
The system performs self-service by automatically analyzing document content, communication paths, and recipient trust levels to determine sensitivity. The compliance monitoring system autonomously computes sensitivity degrees without requiring manual classification processes, thereby eliminating manual work costs while maintaining detection accuracy.
Solution Approach 2:
Manual mechanical classification processes are replaced with automated electronic analysis systems. The system uses computational methods to analyze document content, track communication paths, and calculate sensitivity degrees, substituting human manual work with automated information processing.
2Ease of operation
If form-based identification is used, then detection process is simplified, but accuracy decreases when content is copied or repurposed
Solution Approach 1:
The system moves from two-dimensional form-based detection (looking for keywords in document structure) to multi-dimensional analysis by incorporating communication path analysis and recipient trust level assessment. This additional dimension allows accurate detection even when document content is copied or repurposed, as the system tracks the document's journey and recipient credentials.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring communication paths and recipient responses. When a document is distributed, the system tracks its path through the organization and assesses recipient trust levels, providing continuous feedback that refines sensitivity assessments and enables accurate detection of copied or repurposed content.
3Extent of automation
If content-based identification is used, then automated detection is achieved, but difficulty in distinguishing sensitive from public documents increases
Solution Approach 1:
The system applies dynamic assessment by computing sensitivity degrees based on real-time communication path analysis and recipient trust levels. Rather than using static content-based rules, the system dynamically adjusts sensitivity assessments based on who receives the document and through what path, making it easier to distinguish sensitive from public documents automatically.
Solution Approach 2:
The system achieves universality by using a multi-functional approach that combines content analysis, communication path tracking, and recipient assessment. This universal method can handle various types of documents and distribution scenarios, automatically differentiating sensitive from public documents across diverse contexts.
4Reliability
If compliance monitoring systems are deployed to detect outtrusion, then security detection capability is improved, but system complexity and cost increase
Solution Approach 1:
The system merges multiple functions into a single integrated compliance monitoring platform that combines document analysis, communication path tracking, recipient trust level assessment, and sensitivity computation. This consolidation improves outtrusion detection capability while reducing overall system complexity by eliminating the need for separate manual processes and multiple independent systems.
Data Source
AI summary
In the distribution of electronic documents within an organization or across the perimeter of the organization, security is an important issue as the documents may be sensitive to a larger and a smaller degree. The distribution specifically takes place between individual persons and groups of persons either within or outside the organization, and on data communication networks including both intranets and extranets. In order to improve the security communication paths are determined for each distributed document on the basis of the set of all mappings of communication relations between senders or documents providers and all potential and actual recipients of the documents, including temporal parameters. Determined communication paths are used to compute a degree of sensitivity for the document, and this degree of sensitivity is used to monitor and limit the distribution of the document in compliance with an established security scheme for the organization.