Unified Security Report Interface for Quarantined Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face the challenge of managing multiple security layers, which results in IT administrators needing to review and release quarantined objects from multiple digests or reports, making it cumbersome to identify and release specific emails or data exchange transactions.
Innovation Solution
A unified reporting and interface system that integrates reports from multiple security layers into a single report and provides a unified interface for releasing objects from quarantine, allowing IT administrators and end users to view and manage quarantined objects and request releases through a single interface, regardless of the security layer that applied the preventive actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security layers are deployed to protect against malware and data leaks, then security coverage and reliability are improved, but the complexity of managing and monitoring security reports increases
Solution Approach 1:
The patent combines multiple security layer reports into a single unified report that consolidates quarantined objects from different security applications (Office 365, third-party security providers, etc.). This merging approach maintains comprehensive security coverage while eliminating the need for administrators to manually review multiple separate digests, thereby reducing report management complexity.
Solution Approach 2:
The unified report serves multiple functions simultaneously: it displays quarantined objects from various security layers, provides release capabilities for different security applications, and offers a single interface for both viewing and managing security objects. This multi-functionality resolves the contradiction by making one system perform the roles of multiple separate reporting systems.
2Reliability
If multiple security layers generate separate digests for each security application, then comprehensive security monitoring is achieved, but the time required for administrators to review and release quarantined objects increases
Solution Approach 1:
The system merges separate security digests into a single consolidated report that displays all quarantined objects from multiple security layers in one view. This eliminates the need for administrators to sequentially review multiple separate reports, significantly reducing the time required to monitor and manage security objects while maintaining complete visibility across all security layers.
Solution Approach 2:
The unified report pre-consolidates information from multiple security layers before presentation to the administrator. By performing the aggregation and organization of security data in advance, the system eliminates the time-consuming manual process of reviewing and cross-referencing multiple separate digests, allowing administrators to immediately see and act upon all quarantined objects.
3Measurement precision
If administrators must search through each security layer's digest to identify quarantined emails, then precise identification of specific security layers is achieved, but the ease of operation for releasing objects deteriorates
Solution Approach 1:
The unified report merges information from multiple security layer digests into a single structured view that clearly identifies which security layer quarantined each object. This consolidation maintains precise identification of security layers while eliminating the need for administrators to search through multiple separate reports, thereby dramatically improving ease of operation for releasing objects.
Data Source
AI summary
A data security system, including a security manager computer using network application programming interface (API) calls to services that perform data exchange transactions for end users of an enterprise, and to security layers that perform preventive actions on data exchange transactions that prevent incoming and/or outgoing data exchange transactions from reaching their respective destinations, the API calls remotely monitoring the security layers to identify preventive actions on data exchange transactions performed by the security layers, wherein the security layers are provided by respective different security applications, and a data reporter operative to provide to an administrator of the enterprise a unified report of data exchange transactions that are under preventive action by at least one of the security layers, and to provide a unified interface to an end user enabling the end user to request that a preventive action applied to a selected data exchange transaction be undone.


