Identity Correlation Data Store for DLP Incident Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention (DLP) technologies fail to efficiently correlate multiple user identities across different computing environments, making it difficult to identify users involved in data leaks and track their activities, especially when they use various external identifiers.
Innovation Solution
A method and apparatus dynamically populate an identity-correlation data store that maps external identifiers to unique internal identifiers assigned by an entity, allowing for the correlation of multiple identities to a single user, thereby updating incident records with internal identifiers to identify the responsible user and track their activities across different identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external identifiers are used to track user activities across different computing environments, then the ability to monitor user behavior increases, but the difficulty of identifying and correlating user identities increases
Solution Approach 1:
The patent introduces an identity correlation service as an intermediary component that receives external identifiers from various computing environments and correlates them with internal user identities. This service acts as a mediator between the external identifier system and the internal user management system, resolving the complexity of direct correlation while maintaining reliable user identification across different platforms and devices.
2Adaptability or versatility
If multiple external identifiers are monitored to track user activities, then the coverage of monitoring increases, but the difficulty of correlating identifiers to single users increases
Solution Approach 1:
The identity correlation service is designed as a universal system that can handle multiple types of external identifiers from various computing environments (mobile devices, desktop computers, different operating systems, various applications). It provides a single correlated user identity that works across all these different platforms and contexts, enabling comprehensive monitoring coverage while simplifying the correlation process through a unified approach.
3Measurement precision
If incident records are updated with internal identifiers, then the ability to identify responsible users improves, but the processing time increases
Solution Approach 1:
The system performs preliminary correlation of external identifiers with internal user identities in advance, building and maintaining an identity correlation database before incidents occur. When an incident is detected, the system can quickly query this pre-built correlation data to identify the responsible user, rather than performing complex correlation analysis in real-time during incident processing. This reduces the time loss while maintaining precise user identification.
Data Source
AI summary
A method and apparatus for detecting a violation of a data loss prevention (DLP) policy and correlating an external identifier of an incident record of the violation to a unique internal identifier using an identity-correlation data store are described.


