Selective Data Removal in Web Requests for DLP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Data Loss Prevention (DLP) systems are ineffective in handling web requests to highly-interactive websites (e.g., Web 2.0 websites) as they often lead to unstable user experiences and application crashes, and require arduous customization to manage sensitive data transmission.

Innovation Solution

A method and apparatus for selectively removing data elements that trigger policy violations from web requests to interactive websites, using a data monitoring system (DMS) that evaluates web requests, determines data boundaries, and modifies them to allow seamless processing without blocking, thereby preventing data loss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional DLP systems block web requests containing sensitive data, then data loss prevention is improved, but user experience and system stability deteriorate

Engineering Contradiction:
Improvedata loss preventionVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts only the sensitive data elements from the web request while preserving the rest of the request structure. The DLP system identifies and removes only the specific portions containing sensitive information (such as SSN, credit card numbers) rather than blocking the entire request, thereby maintaining user experience while preventing data loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the web request into distinct data elements and boundaries. By analyzing the request structure and identifying specific segments containing sensitive data, the system can selectively remove only those segments rather than blocking the entire request, thus maintaining system stability and user interaction.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional DLP systems block web requests containing sensitive data, then data loss prevention is improved, but system stability deteriorates

Engineering Contradiction:
Improvedata loss preventionVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent extracts only the sensitive data elements from the web request while preserving the rest of the request structure. The DLP system identifies and removes only the specific portions containing sensitive information (such as SSN, credit card numbers) rather than blocking the entire request, thereby maintaining user experience while preventing data loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the web request into distinct data elements and boundaries. By analyzing the request structure and identifying specific segments containing sensitive data, the system can selectively remove only those segments rather than blocking the entire request, thus maintaining system stability and user interaction.

Inventive Principle:
Principle #1Segmentation

3Reliability

If customized responses are created for each Web 2.0 website, then data loss prevention accuracy is improved, but device complexity and maintenance burden increase

Engineering Contradiction:
Improvedata loss prevention accuracyVSAvoidcustomization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal DLP system that can handle multiple website types and technologies through a single unified approach. The system uses general-purpose data element identification and boundary detection mechanisms that work across different web applications without requiring website-specific customization, thereby reducing complexity while maintaining high accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs automated detection and analysis of web request structures to identify data boundaries and sensitive elements. Rather than requiring manual configuration for each website, the system self-adjusts to different web technologies and formats, reducing the need for complex customizations and ongoing maintenance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8826443B1Selective removal of protected content from web requests sent to an interactive website
Publication Date: 2014.09.02 CA TECH INC
  • US8826443B1 patent drawing
  • US8826443B1 patent drawing
  • US8826443B1 patent drawing

AI summary

A method and apparatus for selectively removing a data element that triggers a policy violation from a web request to an interactive website. In one embodiment, a computer-implemented method identifies a policy for protecting source data, having a plurality of data elements. The method further evaluates a web request sent to an interactive website as part of a web-based application, and determines that the web request includes at least one of the plurality of data elements triggering a violation of the policy. The method determines the data boundaries of the web request, and selectively removes data content within the data boundaries containing the at least one data element that triggered the violation to allow the web request to be processed by the interactive website as if it were the original web request containing the at least one data element.