File Movement Detection via Intermediary Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional file movement management techniques in network file systems lack the ability to control and monitor file movement at the file level, leading to potential unauthorized data egress and security breaches, as they only provide a binary approach to file management and do not account for file modifications or changes in location.

Innovation Solution

Implementing a system that creates and configures sensitive data sets, uses endpoint monitoring, and employs identification methods such as hashing, file name matching, and known text/data identification to track and manage file movements across various storage locations, allowing for granular control and reporting of file movements within a network file system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional binary file management approach is used, then system simplicity is maintained, but file-level movement control and security monitoring capability is insufficient

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments file management into multiple levels: data set level, file level, and movement event level. By creating identifiable data sets with unique identifiers and tracking individual file movements within these sets, the system achieves granular control without requiring complete redesign of the entire file management infrastructure. This segmentation allows selective monitoring of sensitive files while maintaining standard operations for other files.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary file manager component that sits between the file system and users/applications. This file manager intercepts file movement operations, checks them against configured policies for identifiable data sets, and either allows or blocks movements accordingly. This intermediary layer provides security control without requiring changes to underlying file system operations or user applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If file-level movement control is implemented, then unauthorized data egress is prevented, but system complexity and implementation difficulty increases

Engineering Contradiction:
Improvedata securityVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent requires administrators to pre-configure identifiable data sets with unique identifiers, allowed destinations, and movement policies before file movements occur. This preliminary configuration establishes clear rules that the file manager can automatically enforce, eliminating the need for complex real-time analysis of each file movement decision. The system prepares security parameters in advance, making enforcement straightforward and automated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms file management from a binary allowed/denied approach to a parameter-based system where each identifiable data set has specific parameters: unique identifiers for recognition, allowed destination parameters, and movement control settings. By changing the management parameters from simple permissions to detailed data set configurations, the system achieves fine-grained control through configurable parameters rather than complex procedural logic.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If traditional access control lists are used, then server storage location management is simplified, but file movement tracking and modification detection capability is lost

Engineering Contradiction:
Improveoperation simplicityVSAvoidfile movement information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the file manager continuously monitors file system operations, tracks file movements within identifiable data sets, and provides information about these movements to administrators. This feedback loop includes logging movement events, comparing file locations against allowed destinations, and reporting policy violations. The feedback provides visibility into file movements without interfering with normal operations, enabling both simple operation and comprehensive tracking.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a virtual copy or representation of file movement information through the file manager's monitoring capabilities. Instead of modifying actual file operations or requiring changes to the file system itself, the system creates informational copies of movement events and compares these against configured policies. This copying approach enables tracking and analysis without adding complexity to the actual file management operations.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11270022B2Sensitive data movement detection
Publication Date: 2022.03.08 MIMECAST NORTH AMERICA INC
  • US11270022B2 patent drawing
  • US11270022B2 patent drawing
  • US11270022B2 patent drawing

AI summary

Systems and techniques for sensitive data movement detection are described herein. An attempt to relocate a file that is a member of a monitored data set may be identified. A user account associated with the attempt to relocate the file may be determined. A safe user group may be identified for the user account associated with the attempt to relocate the file. A destination may be obtained for the attempt to relocate the file. A safe zone may be determined for the monitored data set using the user account and the identification of the monitored data set. A notification may be provided based on the destination for the attempt to relocate the file and the safe user group and the safe zone.