Sensitivity Scanning Agent for Distributed Data Stores
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed computer networks face challenges in protecting sensitive information due to the risk of misclassification and exposure when using a single scanning tool across disparate data stores connected through non-private networks.
Innovation Solution
A method is provided to monitor file systems within distributed networks by detecting new data stores and determining their location. If a data store is in a foreign hosting environment, an agent of the native scanning tool is created within that environment to obtain sensitivity information without exposing the data to non-private networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single scanning tool is used to evaluate data sensitivity across disparate data stores, then comprehensive coverage of all data stores is improved, but the risk of data exposure to third parties increases
Solution Approach 1:
The scanning system is segmented into multiple distributed scanning tools, each deployed within specific hosting environments (cloud or on-premise). Each scanning tool independently scans data stores within its own environment, eliminating the need to send data through non-private networks while maintaining comprehensive coverage across all environments.
Solution Approach 2:
A central coordination system acts as an intermediary that manages the distributed scanning tools. This coordinator receives scan results from multiple scanning tools and aggregates the sensitivity information, enabling comprehensive data coverage without requiring data to traverse non-private networks.
2Device complexity
If data is sent through wide area networks to a single scanning tool, then centralized processing is simplified, but the risk of pilfering by third parties increases
Solution Approach 1:
The centralized scanning process is segmented into distributed scanning operations. Each scanning tool operates independently within its hosting environment, processing data locally without transmitting it through non-private networks. This maintains processing functionality while eliminating the exposure risk associated with network transmission.
Solution Approach 2:
Instead of sending actual data through networks for processing, the system creates copies of scanning tools in each hosting environment. These local copies perform the scanning function directly on the data, eliminating the need to transmit sensitive information across non-private networks while maintaining processing capability.
3Reliability
If access control measures are deployed to protect sensitive information, then authorized access is limited, but misclassification and location errors in data stores remain
Solution Approach 1:
The distributed scanning tools autonomously scan data stores within their respective hosting environments and automatically classify sensitivity levels. This self-service approach complements access control measures by providing independent verification of data sensitivity, helping to identify misclassified or improperly located sensitive information without requiring manual intervention.
Solution Approach 2:
The scanning system provides feedback about actual data sensitivity locations and classifications back to the organization. This feedback mechanism enables continuous improvement of access control policies by identifying gaps between intended and actual data protection, allowing for more precise sensitivity detection and classification over time.
Data Source
AI summary
A method for monitoring a file system within a distributed network is provided. From a local hosting environment having a native scanning tool, creation of a new data store within the network is detected. Responsive to detecting creation of the new data store, it is determined whether the new data store is physically located within a foreign hosting environment that is communicatively coupled to the local hosting environment through a non-private network. If the new data store is physically located within the foreign hosting environment, an agent of the native scanning tool is created within the foreign hosting environment and the agent is applied to the new data store within the foreign hosting environment to obtain sensitivity information for the new data store. The sensitivity information for the new data store is received and recorded in the local hosting environment.


