Intelligent Term Grouping for Scalable Sensitive Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face challenges in scalable document registration and manual processes for synthesizing sensitive information, making it time-intensive and complex to identify and protect valuable data, especially in non-fixed formats.

Innovation Solution

A system and method for intelligent term grouping using concept builders that select key terms and regular expressions from text mining, automating the process of identifying related terms and forming concepts for data classification, enabling efficient protection of sensitive information across networks without prior knowledge of what needs to be protected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used for synthesizing sensitive information, then security professionals can identify and protect valuable data, but the process becomes time-intensive and complex

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime-intensive process
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by automatically synthesizing sensitive information through text mining and concept building. The network appliance autonomously identifies sensitive data, extracts key terms, and creates protection rules without requiring continuous manual intervention from security professionals, thus resolving the time-intensive nature of manual processes while maintaining security reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes with automated computational systems. Text mining algorithms, concept builders, and pattern recognition systems substitute for manual security analysis, automatically processing large volumes of data to identify sensitive information and generate protection rules, thereby eliminating the time-consuming aspects of manual synthesis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual registration of documents is used, then sensitive information can be identified, but scalability is limited

Engineering Contradiction:
Improvesensitive information identificationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network appliance performs multiple functions including text mining, concept building, rule generation, and data protection within a single system. This universal approach allows the same automated system to handle diverse document types and sensitive information formats across the enterprise network, enabling scalable deployment without requiring separate manual registration processes for different data types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Manual document registration is replaced with automated text mining and pattern recognition systems that can process unlimited volumes of documents across the network. The system automatically synthesizes sensitive information from various sources and formats, making the process scalable to enterprise-wide deployments without proportionally increasing manual effort

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive data protection is implemented across all information assets, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential elements needed for protection by using text mining to identify key terms and concepts from sensitive documents. The concept builder extracts meaningful patterns and synthesizes them into focused protection rules, rather than attempting to manually configure comprehensive security policies for every possible data element, thus reducing system complexity while maintaining broad security coverage

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The automated system self-generates protection rules by analyzing document content and identifying sensitive information patterns. This self-service capability eliminates the need for complex manual configuration and ongoing management of security policies, allowing comprehensive coverage across all information assets while keeping the system manageable through automation rather than increasing complexity through manual processes

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8706709B2System and method for intelligent term grouping
Publication Date: 2014.04.22 MCAFEE LLC
  • US8706709B2 patent drawing
  • US8706709B2 patent drawing
  • US8706709B2 patent drawing

AI summary

A method is provided in one example embodiment and it includes identifying a root word for a tree to be used in managing data and creating a word stem to be included in the tree. A query is initiated to determine whether a stem node exists at one or more branch points of the word, and if the stem node does not exist, then the stem node is added to a branch point of the tree. In more specific embodiments, if the stem node does exist, then node statistics are updated. In other embodiments, the method includes updating a branch point list after creating the word stem. In yet other embodiments, the branch point is a word or a combination of words. The tree can be used to identify locations and frequencies within a document set where one or more words are present.