Enterprise Sensitive Data Risk Scoring and Selective Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying and protecting sensitive data within computer networks is challenging due to the computational intensity of frequent scans, the complexity of risk assessment across multiple stakeholders, and the difficulty in applying protection policies to external databases, which can lead to missed critical risks and inefficient resource allocation.

Innovation Solution

A method that calculates a risk/impact score supporting multiple assessment types and policies, allowing for customizable weights and 'what if' analysis, and applies protection policies at the data element or full data set level, with a data management service identifying sensitive data and providing an interface for targeted protection policies across enterprise databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If frequent scans are used to identify sensitive data locations, then the accuracy of sensitive data knowledge is improved, but the computational resources and time required increase significantly

Engineering Contradiction:
Improveaccuracy of sensitive data knowledgeVSAvoidtime for scanning
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the database into multiple partitions and uses selective scanning based on risk scores. Instead of scanning the entire database frequently, the system divides it into manageable segments and scans only those partitions that contain sensitive data or have high risk scores, thereby reducing the time and computational resources required while maintaining accurate knowledge of sensitive data locations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial scanning by focusing computational efforts on specific database partitions that are more likely to contain sensitive data. By using risk scores to identify high-priority areas and scanning only those regions, the system achieves adequate coverage of sensitive data locations without the excessive time cost of scanning the entire database.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If comprehensive risk assessment across all databases is performed, then the identification of critical risks is improved, but the complexity of risk evaluation increases

Engineering Contradiction:
Improveidentification of critical risksVSAvoidcomplexity of risk evaluation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by customizing risk assessment parameters and weights according to specific database characteristics and stakeholder perspectives. Different databases are evaluated using tailored risk models that reflect their unique sensitivity, access patterns, and business importance, rather than applying a uniform complex assessment to all databases. This reduces overall evaluation complexity while maintaining reliable identification of critical risks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts risk assessment parameters such as weights for different risk factors based on stakeholder perspectives and database characteristics. By changing parameters like the importance weight of confidentiality versus integrity, or adjusting sensitivity thresholds, the system can simplify complex evaluations for less critical databases while maintaining comprehensive assessment for high-priority systems.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If protection policies are applied to all database copies containing sensitive data, then the security coverage is improved, but the difficulty of policy application increases when external databases are involved

Engineering Contradiction:
Improvesecurity coverageVSAvoidease of policy application
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a data management service as an intermediary that acts as a centralized policy enforcement point. This service maintains knowledge of all database copies containing sensitive data, including external databases, and coordinates policy application across the entire data ecosystem. The intermediary manages the complexity of multi-database policy enforcement by providing a unified interface and automated coordination, making it easier to apply protection policies comprehensively without manually managing each database connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2945091B1Assessment type-variable enterprise security impact analysis
Publication Date: 2019.10.02 INFORMATICA CORP
  • EP2945091B1 patent drawingFigure 1A
  • EP2945091B1 patent drawingFigure 1B
  • EP2945091B1 patent drawingFigure 2A~2B

AI summary

A data management service identifies sensitive data stored on enterprise databases according to record classification rules that classify a data record as having a sensitive data type if the data record includes fields matching at least one of the record classification rules. Methods and systems rely on a set of impact factors each having a set of set of value bands representing a range for the impact factor and a corresponding value (between 0 and 1). The factors, ranges, and values all are customizable for an organization. Impact scoring calculations take into account each of the impact factors, and each is weighted to represent a specific risk perception or assessment type. A similar impact scoring is applied to data quality using volume of data as a key attribute of the quality.