Malware Detection Agent for Dynamic Data Loss Prevention Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data loss prevention (DLP) solutions lack the capability to automatically enable and disable policies based on threat assessments, relying on manual management by administrators.

Innovation Solution

A malware detection agent on a computing device detects potential data loss threats, enabling DLP policies to protect sensitive data until the threat is resolved, using a security agent that filters I/O operations and dynamically adjusts policy sensitivity based on threat levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual DLP policy management is used, then policy control precision is improved, but system automation capability deteriorates

Engineering Contradiction:
Improvepolicy control precisionVSAvoidsystem automation capability
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The DLP system automatically enables and disables policies based on threat assessments without requiring manual administrator intervention. The system monitors for malware indicators and autonomously adjusts policy states, allowing the system to serve itself rather than relying on continuous manual management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where threat detection results automatically trigger policy enablement or disablement. Malware detection agents provide real-time feedback about system security state, which the DLP system uses to dynamically adjust policy settings, creating a closed-loop automated control mechanism.

Inventive Principle:
Principle #23Feedback

2Extent of automation

If automatic DLP policy enablement is implemented, then system automation capability is improved, but policy response speed deteriorates

Engineering Contradiction:
Improvesystem automation capabilityVSAvoidpolicy response speed
Core Design Contradiction:
Extent of automationVSSpeed

Solution Approach 1:

DLP policies are pre-configured and ready to be automatically enabled when specific threat conditions are detected. The system maintains pre-established policy templates and activation rules, so when malware indicators are detected, the appropriate policies can be immediately enabled without delay for configuration or manual approval.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical policy management with automated software-based threat assessment and policy activation. Malware detection agents automatically analyze system states and trigger policy changes through software decision-making, eliminating the mechanical manual intervention process and enabling rapid automated response.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If continuous DLP policy monitoring is performed, then security coverage is improved, but system resource consumption deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of continuous intensive monitoring, the system performs periodic threat assessments triggered by specific events or time intervals. The malware detection agents monitor for indicators of compromise and periodically evaluate system states, enabling security coverage through scheduled checks rather than constant resource-intensive scanning.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies differentiated monitoring intensity to different system components and data types based on their security risk profiles. High-risk areas receive more intensive monitoring while lower-risk areas are monitored less frequently, optimizing the balance between security coverage and resource consumption by applying local quality control rather than uniform monitoring.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9064130B1Data loss prevention in the event of malware detection
Publication Date: 2015.06.23 CA TECH INC
  • US9064130B1 patent drawing
  • US9064130B1 patent drawing
  • US9064130B1 patent drawing

AI summary

A malware detection agent operating on a computing device detects one or more indicators of a potential data loss threat. Sensitive data is identified based on at least one of a logical location or a physical location of the sensitive data. One or more data loss prevention policies are enabled to protect the sensitive data until the potential data loss threat is resolved.