Sensitive Data Scanning Engine for Early Credential Leak Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security management systems lack comprehensive computing logic and infrastructure for efficient sensitive data leak-detection, especially in large-scale software development environments, leading to inefficient and computationally expensive detection of credential leaks in production systems.
Innovation Solution
A sensitive data leak-detection engine integrated into the software development environment, utilizing a logging framework, onboarding engine, and code scanning package to automate sensitive data scanning during the development stage, identifying potential credential leaks through a mock library and generating notifications for software developers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive data leak-detection is performed in production systems, then credential leaks can be detected, but computational costs increase significantly due to large log volume
Solution Approach 1:
The patent applies preliminary action by performing sensitive data leak detection during the software development process (unit testing stage) rather than in production systems. The detection engine integrates with the development environment to scan code and identify potential credential leaks early, preventing the need for expensive production-time analysis of large log volumes.
Solution Approach 2:
The patent uses a mock library that creates simulated logging data during development that mirrors production logging behavior. This allows the detection engine to test and scan sensitive data patterns using copies of log data generated during development, rather than processing actual production logs, thereby reducing computational costs while maintaining detection reliability.
2Productivity
If security management systems are integrated with software development processes, then development efficiency improves, but system complexity increases
Solution Approach 1:
The patent merges the sensitive data leak detection functionality with the software development environment by integrating the detection engine as part of the development infrastructure. The system combines code scanning, mock library generation, and sensitive data detection into a unified integrated environment that works seamlessly with existing development tools and processes.
Solution Approach 2:
The detection engine is designed with multi-functionality, serving multiple purposes: it scans code for sensitive data patterns, generates mock logging data, tests detection capabilities, and provides notifications. This universal approach consolidates multiple security functions into a single integrated system, reducing overall complexity compared to multiple separate security tools.
3Measurement precision
If comprehensive security management infrastructure is implemented, then detection accuracy improves, but infrastructure complexity and setup difficulty increase
Solution Approach 1:
The system implements self-service through automated onboarding where the detection engine automatically configures itself with the development environment, codebase, and testing infrastructure. The mock library is generated automatically based on the codebase structure, and the scanning process runs autonomously without requiring manual configuration or complex infrastructure setup, thereby maintaining high detection accuracy while reducing infrastructure complexity.
Data Source
AI summary
Methods, systems, and computer storage media for providing a sensitive data scanning in a sensitive data leak-detection engine of a security management system. Sensitive data scanning—for example confidential information scanning or credential scanning—provides sensitive data leak-detection via a software development environment during a software development process. In operation, a request—to execute a sensitive data scanning operation on an instance of in-development code—is accessed. The sensitive data scanning operation executable via a sensitive data leak-detection engine that provides code security management services in a software development environment. A code scanning package is accessed. The code scanning package comprises software development environment code scanning parameters. Based on the software development environment code scanning parameters, the in-development code is scanned for sensitive data. A notification comprising a sensitive data scan result associated with the in-development code is generated. The notification is communicated to cause the notification to be displayed.


