Sensitive Data File Detection Through Risk-Scored Database Searches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Entities often do not detect data breaches until after they experience negative consequences due to the difficulty in checking all publicly available databases for leaked sensitive information.
Innovation Solution
A risk assessment system generates search terms from entity-specific keywords, applies a risk scoring model to search results from online public databases, and identifies data files likely containing sensitive information from a breach.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If an entity manually checks all publicly available databases for leaked sensitive information, then they can identify data breaches, but the process is extremely time-consuming and difficult due to the vast amount of information to check
Solution Approach 1:
The patent introduces an automated risk assessment system as an intermediary between the entity and public databases. This system uses search term generation modules to create targeted search queries, automated search modules to query multiple databases simultaneously, and risk scoring modules to evaluate results. This intermediary automation resolves the contradiction by enabling comprehensive database checking without manual time investment.
Solution Approach 2:
The system performs preliminary actions by pre-generating search terms from entity information before conducting database searches. The search term generation module creates optimized queries in advance, and the system pre-identifies which databases to search based on the entity's data types. This preliminary preparation enables faster detection when breaches occur.
2Productivity
If an entity waits to check public databases until after experiencing negative consequences, then they avoid unnecessary checking effort, but they suffer harm before detecting the breach
Solution Approach 1:
The patent implements feedback mechanisms where the risk assessment system continuously monitors public databases and provides timely alerts to entities about potential breaches. The system generates risk scores for search results and notifies entities when sensitive information is detected, enabling proactive response before negative consequences occur. This feedback loop resolves the contradiction by making detection efficient and timely.
Solution Approach 2:
The system takes preliminary anti-action by proactively detecting and alerting entities to data breaches before they can cause significant harm. By continuously monitoring public databases and using risk scoring to identify leaked information early, the system enables entities to take corrective actions before experiencing negative consequences such as financial loss or reputational damage.
3Measurement precision
If the risk assessment system uses comprehensive search terms including all entity information, then it can identify all potential data leaks, but it risks exposing additional private information about the entity
Solution Approach 1:
The patent applies local quality by selectively including or excluding specific search terms based on their sensitivity and usefulness. The search term generation module evaluates each piece of entity information and determines whether to include it in search queries based on predefined criteria. This selective approach maintains detection accuracy while minimizing exposure of highly sensitive private information.
Solution Approach 2:
The system dynamically changes parameters of search terms based on risk assessment needs. The risk scoring module adjusts the sensitivity and scope of search terms depending on the context, entity type, and detected patterns. This parameter adjustment enables accurate leak identification while adapting the level of information exposure to minimize private data release.
Data Source
AI summary
A system and method are provided for assessing whether data files contain sensitive information associated with an entity. The system stores search keywords associated with the entity, generates search terms based on the search keywords, and searches one or more online public databases for data files associated with each search term. The system then generates risk scores for data files in the search results indicating a likelihood that the data files contain information from a data breach associated with the entity. The system identifies data files that contain information from the data breach from the generated risk scores, and transmits a notification to the entity describing the identified data files.


