File Movement Detection via Intermediary Manager
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional file movement management techniques in network file systems lack the ability to control and monitor file movement at the file level, leading to potential unauthorized data egress and security breaches, as they only provide a binary approach to file management and do not account for file modifications or changes in location.
Innovation Solution
Implementing a system that creates and configures sensitive data sets, uses endpoint monitoring, and employs identification methods such as hashing, file name matching, and known text/data identification to track and manage file movements across various storage locations, allowing for granular control and reporting of file movements within a network file system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional binary file management approach is used, then system simplicity is maintained, but file-level movement control and security monitoring capability is insufficient
Solution Approach 1:
The patent segments file management into multiple levels: data set level, file level, and movement event level. By creating identifiable data sets with unique identifiers and tracking individual file movements within these sets, the system achieves granular control without requiring complete redesign of the entire file management infrastructure. This segmentation allows selective monitoring of sensitive files while maintaining standard operations for other files.
Solution Approach 2:
The patent introduces an intermediary file manager component that sits between the file system and users/applications. This file manager intercepts file movement operations, checks them against configured policies for identifiable data sets, and either allows or blocks movements accordingly. This intermediary layer provides security control without requiring changes to underlying file system operations or user applications.
2Reliability
If file-level movement control is implemented, then unauthorized data egress is prevented, but system complexity and implementation difficulty increases
Solution Approach 1:
The patent requires administrators to pre-configure identifiable data sets with unique identifiers, allowed destinations, and movement policies before file movements occur. This preliminary configuration establishes clear rules that the file manager can automatically enforce, eliminating the need for complex real-time analysis of each file movement decision. The system prepares security parameters in advance, making enforcement straightforward and automated.
Solution Approach 2:
The patent transforms file management from a binary allowed/denied approach to a parameter-based system where each identifiable data set has specific parameters: unique identifiers for recognition, allowed destination parameters, and movement control settings. By changing the management parameters from simple permissions to detailed data set configurations, the system achieves fine-grained control through configurable parameters rather than complex procedural logic.
3Ease of operation
If traditional access control lists are used, then server storage location management is simplified, but file movement tracking and modification detection capability is lost
Solution Approach 1:
The patent implements a feedback mechanism where the file manager continuously monitors file system operations, tracks file movements within identifiable data sets, and provides information about these movements to administrators. This feedback loop includes logging movement events, comparing file locations against allowed destinations, and reporting policy violations. The feedback provides visibility into file movements without interfering with normal operations, enabling both simple operation and comprehensive tracking.
Solution Approach 2:
The patent creates a virtual copy or representation of file movement information through the file manager's monitoring capabilities. Instead of modifying actual file operations or requiring changes to the file system itself, the system creates informational copies of movement events and compares these against configured policies. This copying approach enables tracking and analysis without adding complexity to the actual file management operations.
Data Source
AI summary
Systems and techniques for sensitive data movement detection are described herein. An attempt to relocate a file that is a member of a monitored data set may be identified. A user account associated with the attempt to relocate the file may be determined. A safe user group may be identified for the user account associated with the attempt to relocate the file. A destination may be obtained for the attempt to relocate the file. A safe zone may be determined for the monitored data set using the user account and the identification of the monitored data set. A notification may be provided based on the destination for the attempt to relocate the file and the safe user group and the safe zone.


