Dynamic Entity Classification for Network Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional tools fail to utilize data classification information for assigning classifications to entities transmitting data and adjusting the criticality of data transmission events based on the classification of the data being transmitted, limiting their ability to enforce security and organizational classification rules effectively.
Innovation Solution
A system and method for monitoring network traffic, classifying source and destination computers based on the classification of the data transmitted, using a monitoring tool and classification tool to enforce organizational classification rules, assign classifications, and manage data transmission by determining if the source and destination systems are classified under these rules, with the ability to alert or authorize data transmission based on classification differences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional monitoring tools are used to recognize or categorize data content, then data classification is achieved, but the ability to assign classifications to entities transmitting data and adjust criticality of transmission events is lost
Solution Approach 1:
The system implements feedback by using the classified data information to dynamically assign classifications to entities (source and destination systems) and adjust the criticality of transmission events. The monitoring tool continuously observes data transmissions, classifies the data, and feeds this classification information back to update entity classifications and criticality levels, creating a closed-loop system that adapts based on observed data patterns
Solution Approach 2:
The system applies dynamics by making entity classifications and criticality levels changeable and adaptive rather than static. Entity classifications are dynamically updated based on the types of data they transmit or receive, and criticality of transmission events is adjusted in real-time based on the classification of data being transmitted, allowing the system to respond flexibly to changing security requirements and data patterns
2Measurement precision
If tools monitor data traversing the network and recognize content, then data classification is achieved, but enforcement of security and organizational classification rules is limited
Solution Approach 1:
The system applies preliminary action by pre-establishing organizational classification rules and security policies before data transmissions occur. These rules define classification categories, entity classification criteria, and criticality levels in advance, enabling the monitoring tool to automatically enforce security rules by comparing actual transmissions against pre-defined policies and taking appropriate actions such as blocking or alerting on non-compliant transmissions
3Productivity
If conventional tools categorize data content, then basic classification is achieved, but dynamic classification of transmitting entities based on data classification is not possible
Solution Approach 1:
The system applies universality by designing a multi-functional classification framework where the same classification mechanism serves multiple purposes: classifying data content, classifying source and destination entities, determining criticality of transmission events, and enforcing security policies. This universal classification approach allows a single system to perform diverse classification-related functions, increasing both productivity and adaptability
Data Source
AI summary
A system, method and computer program product are provided for monitoring data traffic on one or more networks, determining the classification of the data based on an organization's classification rules, and assigning a classification to one or more entities involved in the transmission of the data, the classification being based at least in part on the classification of the data being transmitted. The classification rules may be based on an organization's classification categories of confidentiality, integrity and availability (CIA). The system, method and computer program product are also provided for implementing controls based on the classifications of the various entities, such as issuing an alert and/or preventing transmission of data if the data is transmitted between two entities that have different classifications.


