Network Sensitive Information Leak Prevention via Link Strength Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for managing sensitive information in corporate and social networks face challenges such as accidental leaks due to incorrect email predictions, lack of systematic classification, high false alarm rates, and require significant human intervention for determining sensitivity levels and authorized recipients.
Innovation Solution
A system that extracts terms from documents associated with user profiles, generates categorical terms based on usage frequencies, determines link strength between users, and analyzes sensitivity levels to prevent unauthorized sharing by assessing the distribution of terms and link strength values, providing alerts or prohibiting transactions that may leak sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional systems implement document similarity tests to prevent leaks, then information security is improved, but false alarm rate increases and system complexity increases
Solution Approach 1:
The system continuously monitors and learns from actual information sharing behavior patterns. By analyzing feedback from user interactions and communication histories, the system refines its sensitivity detection algorithms to reduce false alarms while maintaining security. The feedback mechanism allows the system to adapt to evolving communication patterns and distinguish between legitimate information sharing and actual leaks.
Solution Approach 2:
The system automatically classifies information sensitivity and identifies authorized recipients without requiring manual intervention. Through automated analysis of document content, user profiles, and communication patterns, the system serves itself in determining security parameters, reducing false alarms caused by manual classification errors while maintaining high security standards.
2Measurement precision
If manual classification of documents is performed, then classification accuracy is improved, but time consumption and human resource requirements increase
Solution Approach 1:
The system performs automated classification of documents based on content analysis, user profiles, and communication patterns. This self-service approach eliminates the need for manual classification by network administrators, significantly reducing time consumption while maintaining classification accuracy through sophisticated automated algorithms that analyze document metadata, content keywords, and contextual information.
Solution Approach 2:
The system pre-classifies documents and establishes user authorization levels before information sharing occurs. By performing classification actions in advance and maintaining updated user profiles with authorized recipient lists, the system eliminates the need for real-time manual review, reducing time consumption while ensuring accurate classification through pre-established criteria and continuous learning.
3Difficulty of detecting and measuring
If the system monitors all communications to prevent leaks, then detection capability is improved, but system complexity and processing overhead increase
Solution Approach 1:
The system applies differentiated monitoring and analysis based on local characteristics of each communication. Instead of uniform monitoring of all communications, the system adjusts its detection parameters and complexity based on the specific context, recipient authorization status, and sensitivity level of each document, reducing overall system complexity while maintaining high detection capability where needed.
Solution Approach 2:
The system performs comprehensive monitoring only when necessary based on risk assessment. By analyzing communication patterns and identifying high-risk scenarios in advance, the system applies full monitoring intensity only to critical communications rather than all communications uniformly, reducing processing overhead and system complexity while maintaining effective detection capability for actual leaks.
Data Source
AI summary
Determining sensitive information and preventing the unauthorized or unintended dissemination of such information are disclosed. Terms are determined from documents associated with users in a network. Distributions among users and relative frequencies with which the terms are used are determined. Link strengths between users are calculated. Based on the distribution of the terms, the relative frequencies of use among the user profiles and link strengths between users conducting information transactions that include the terms, a sensitivity level for each term can be determined. To determine whether a particular information transaction with particular terms may be conducted between two users in the network, a combination of link strength between the users and sensitivity level of the terms with respect to the users or users' profiles are considered. If the information transaction includes terms that are unknown to one of the users, then a warning or alarm can be raised.


