Heuristic Data Movement Detection Engine for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in ensuring the security and efficient management of enterprise data movement while allowing authorized access, as existing systems often struggle to balance data security with convenient access and scalability.

Innovation Solution

A heuristic data movement detection engine is employed to monitor, track, and manage enterprise data movements by analyzing patterns and generating alerts or halting unauthorized data transfers, using predefined or learned patterns to ensure compliance with defined security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict data security measures are implemented to prevent unauthorized data movement, then data security is improved, but ease of operation deteriorates as authorized users face more restrictions

Engineering Contradiction:
Improvedata securityVSAvoidauthorized access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements continuous monitoring of data movement operations and provides feedback to users about detected patterns. When unauthorized movement is detected, the system generates alerts and notifications to inform users of security violations while maintaining normal operations for authorized users, thus balancing security with operational convenience

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary data loss prevention system that acts as a mediator between security requirements and user operations. This intermediary layer analyzes data movements, applies security policies, and enables authorized access while blocking unauthorized movements, resolving the contradiction between strict security and operational ease

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive monitoring of all data movements is implemented, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvedata movement detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into multiple independent components including data movement agents, pattern analysis engines, and policy management modules. Each component handles specific aspects of monitoring, reducing overall system complexity while maintaining comprehensive detection precision through coordinated operation of these modular elements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies monitoring at appropriate levels of detail based on data sensitivity and user roles. Rather than uniformly monitoring every byte movement with maximum precision, the system applies partial monitoring to low-risk operations and excessive (detailed) monitoring only to high-risk operations, reducing overall complexity while maintaining necessary detection accuracy

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9934475B2Managing enterprise data movement using a heuristic data movement detection engine
Publication Date: 2018.04.03 BANK OF AMERICA CORP
  • US9934475B2 patent drawing
  • US9934475B2 patent drawing
  • US9934475B2 patent drawing

AI summary

Methods, systems, and computer-readable media for managing enterprise data movement using a heuristic data movement detection engine are presented. In some embodiments, a computer system may receive one or more data packets associated with a movement of enterprise data intercepted by a filtering engine. Subsequently, the computer system may evaluate the one or more data packets associated with the movement of enterprise data intercepted by the filtering engine based on at least one predefined data movement pattern. Then, the computer system may detect at least one variation from the at least one predefined data movement pattern based on the evaluating of the one or more data packets associated with the movement of enterprise data intercepted by the filtering engine. Thereafter, the computer system may send at least one alert message based on the detecting of the at least one variation from the at least one predefined data movement pattern.