Network Security Compliance Service for Data Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network computing environments, ensuring that data objects are stored in appropriate data storage containers based on their security and compliance concerns is challenging due to the sheer volume of data, leading to potential exposure of sensitive information and unnecessary resource expenditure.

Innovation Solution

A network system implements a security and compliance service that analyzes data storage containers and their contents to determine if they match their context classification, performing remediation actions when mismatches are found, using a Security Compliance Analysis component to scan data objects and a Remediation component to mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If every data object is checked to ensure proper classification, then data security is improved, but time consumption and resource expenditure increase prohibitively

Engineering Contradiction:
Improvedata securityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the data container verification process by focusing only on specific high-risk data types (credentials, PII, financial data) rather than checking every data object. The security service divides the verification task into targeted scans for sensitive information patterns, allowing efficient enforcement of security policies without prohibitively expensive full-coverage scanning of all data containers.

Inventive Principle:
Principle #1Segmentation

2Reliability

If data objects are over-classified as highly sensitive, then data security is improved, but resource expenditure increases due to unnecessary protection measures

Engineering Contradiction:
Improvedata securityVSAvoidresource expenditure
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent replaces manual or rule-based classification mechanisms with an automated security service that uses pattern recognition and machine learning models to accurately classify data objects. This substitution enables precise identification of truly sensitive data, preventing over-classification while maintaining security, as the system learns to distinguish between actual sensitive information and ordinary data that may appear similar.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive security checks are performed on all data containers, then data exposure prevention is improved, but productivity decreases due to extensive verification requirements

Engineering Contradiction:
Improvedata exposure preventionVSAvoiddata management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by performing security verification only on data containers that contain or are suspected of containing sensitive information types. Rather than requiring comprehensive verification of all data containers, the security service selectively applies checks based on data type, container classification, and risk assessment, maintaining adequate security while preserving data management productivity.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If strict classification rules are enforced on all data, then compliance is improved, but ease of operation deteriorates due to complex management requirements

Engineering Contradiction:
ImprovecomplianceVSAvoiddata management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the security service to automatically perform classification, verification, and remediation actions without requiring manual intervention from data managers. The system autonomously identifies misclassified data, determines appropriate corrective actions, and executes remediation, thereby enforcing strict compliance rules while maintaining ease of operation through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240256701A1Programmatic data security and compliance remediation for network computing environment
Publication Date: 2024.08.01 UBER TECHNOLOGIES INC
  • US20240256701A1 patent drawing
  • US20240256701A1 patent drawing
  • US20240256701A1 patent drawing

AI summary

The network system implements a security and compliance service to ensure that a context classification of a data storage container is appropriate for individual data objects contained within it. If the data storage container is inappropriate for the data object, the network system performs remedial actions to avoid risk or harm from misclassification or potential exposure of the data object.