Trusted File Awareness Using Endpoint–Cloud Event Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to accurately detect data exfiltration via network-based services, such as cloud storage, due to the generation of massive amounts of non-indicative alerts, making it difficult to prevent unauthorized data transfers from authorized computing devices to unauthorized accounts or vice versa.

Innovation Solution

A system that monitors both endpoint and authorized accounts on network-based service providers for file system element events, matching events from both sources to identify unauthorized transfers by correlating file system element events on client computing devices with those on network-based services, thereby reducing false alarms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional monitoring methods are used to detect data exfiltration, then coverage of detection is improved, but false alarm rate increases significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse alarms
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the detection process into two independent monitoring components: one monitoring the client computing device and another monitoring the network-based service account. By dividing the detection into separate event streams that are later correlated, the system can identify true exfiltration events while filtering out false alarms that occur in only one stream.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary correlation mechanism that matches events between the client device stream and the service account stream. This intermediary layer compares file system element events from both sources and identifies mismatches that indicate true exfiltration, while filtering out matched events that represent legitimate operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If monitoring is performed on both endpoint and network service, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveexfiltration detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into two independent but coordinated components: endpoint monitoring on the client device and service monitoring on the network-based service. Each component independently collects events from its respective source, reducing the complexity of any single monitoring module while achieving high detection accuracy through their coordination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each monitoring component operates autonomously, collecting and processing events from its own source independently. The endpoint monitor collects file system events locally, while the service monitor collects account events independently. They then self-correlate through event matching without requiring complex centralized coordination, reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250260700A1Determining trusted file awareness via loosely connected events and file attributes
Publication Date: 2025.08.14 MIMECAST NORTH AMERICA INC
  • US20250260700A1 patent drawing
  • US20250260700A1 patent drawing
  • US20250260700A1 patent drawing

AI summary

Disclosed in some examples are methods, systems, devices, and machine-readable mediums which monitor for file system element transfers to and from both the endpoint and authorized accounts on network-based service providers (e.g., cloud-based storage). The system uses the capabilities of monitoring both the network-based service and the client computing device to filter out legitimate uploads to authorized network-based services and legitimate downloads to authorized computing devices. By matching events, it filters out events that are likely legitimate, the system may provide more accurate information, notifications, awareness, and unmatched event indications.