Dynamic Data Loss Prevention Policy Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in effectively managing data security risks due to the increasing use of personal devices accessing corporate information from hybrid networks, leading to ineffective data loss prevention policies that are often overly restrictive and inflexible.

Innovation Solution

A method and system for determining user context to dynamically select and apply data loss prevention policies, monitoring communication events, and taking actions based on content-based classifications and risk assessments to mitigate risks in a context-aware manner.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data loss prevention policies are applied to all users and devices uniformly, then data security is maintained, but flexibility and user convenience deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidpolicy flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic DLP policies that automatically adjust security measures based on real-time user context, device characteristics, and communication event risks. Instead of static uniform policies, the system continuously adapts policy application to match current conditions, resolving the contradiction between maintaining security and providing flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies different security policies to different users, devices, and communication events based on their specific contexts. High-risk scenarios receive stricter policies while low-risk scenarios receive more permissive policies, allowing the system to maintain overall security while providing local flexibility where appropriate.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If comprehensive monitoring of all communication events is implemented, then data breach detection capability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improverisk detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements selective monitoring that focuses computational resources on high-risk communication events and users rather than uniformly monitoring all events. By identifying and prioritizing critical events based on context and risk assessment, the system achieves high detection accuracy while reducing overall system complexity and processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The monitoring system uses feedback loops where communication events are analyzed, risk assessments are updated, and policy applications are adjusted in real-time. This continuous feedback mechanism allows the system to maintain high detection accuracy by focusing on emerging risks while avoiding unnecessary monitoring of low-risk patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9349016B1System and method for user-context-based data loss prevention
Publication Date: 2016.05.24 QUEST SOFTWARE INC
  • US9349016B1 patent drawing
  • US9349016B1 patent drawing
  • US9349016B1 patent drawing

AI summary

In one embodiment, a method includes determining a user context of at least one user device currently accessing an enterprise communication platform. The method further includes selecting a dynamic data loss prevention (DLP) policy applicable to the at least one user device based, at least in part, on the user context. The dynamic DLP policy specifies one or more communication events of interest. In addition, the method includes monitoring communication events initiated by the at least one user device for the one or more communication events of interest. Moreover, the method includes, responsive to each communication event of interest: assessing the communication event of interest based, at least in part, on a content-based classification of a communication associated with the communication event of interest; and responsive to a risk assessment meeting certain criteria, taking at least one action specified by the dynamic DLP policy.