GUI Sensitive Information Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting sensitive information in enterprise networks are inadequate, as they are difficult to manage, costly, and ineffective in monitoring encrypted network traffic, leading to potential data leakage and theft, which poses a significant security threat.

Innovation Solution

A graphical user interface (GUI) based system that monitors and manages sensitive information within an enterprise network by providing static and dynamic views of sensitive document locations, security policies, and information flow, allowing users to visualize and manage sensitive information, detect leaks, and identify involved parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional secure computer approach is used to store and manage sensitive information, then security protection is improved, but ease of operation deteriorates due to cumbersome procedures and difficulty in document access and modification

Engineering Contradiction:
Improvesecurity protectionVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a secure document server as an intermediary between users and sensitive documents. The server implements automated security policies, digital rights management, and access control mechanisms that protect sensitive information without requiring users to physically access secured computers. This mediator handles security enforcement transparently, allowing users to access and modify documents through standard network protocols while maintaining security protections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of physically securing documents in controlled-access computer rooms with an electronic/digital security system. Instead of requiring physical presence and manual authorization procedures, the system uses digital certificates, encrypted communications, and automated policy enforcement to protect sensitive documents. This substitution eliminates the need for users to visit secured locations while maintaining or enhancing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If network sniffer approach is used to monitor network traffic for sensitive information, then detection capability is improved, but network performance deteriorates due to traffic analysis overhead and encrypted traffic cannot be analyzed

Engineering Contradiction:
Improvedetection capabilityVSAvoidnetwork performance
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

The patent implements watermarks and digital signatures on sensitive documents before they are transmitted over the network. These preliminary markers are embedded in the document content or metadata, allowing the system to identify sensitive information without analyzing the actual document content during transmission. This approach enables detection of sensitive information flow while avoiding the need to decrypt or deeply inspect encrypted traffic, thus maintaining network performance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a document management server as an intermediary that monitors and tracks sensitive document transmissions. Instead of using network sniffers to analyze encrypted traffic, the server receives notifications from client applications about document access and transmission events. This mediator approach allows the system to detect sensitive information flow through application-layer events rather than network-layer packet analysis, avoiding performance degradation and working around encryption limitations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8140664B2Graphical user interface based sensitive information and internal information vulnerability management system
Publication Date: 2012.03.20 TREND MICRO INC
  • US8140664B2 patent drawing
  • US8140664B2 patent drawing
  • US8140664B2 patent drawing

AI summary

A system and method provides a graphical user interface (GUI) for users to monitor and manage sensitive information within an enterprise network. The GUI can provide users with information, such as the presence of input/output devices (I/O device), the location of documents containing sensitive information (sensitive documents), and the status of local security policy. The GUI can also provide users with real-time information, such as the occurrence of local security policy violations, the life-cycle of sensitive documents, and the sensitive information dynamic flow within the enterprise network.