Selective Data Removal in Web Requests for DLP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Data Loss Prevention (DLP) systems are ineffective in handling web requests to highly-interactive websites (e.g., Web 2.0 websites) as they often lead to unstable user experiences and application crashes, and require arduous customization to manage sensitive data transmission.
Innovation Solution
A method and apparatus for selectively removing data elements that trigger policy violations from web requests to interactive websites, using a data monitoring system (DMS) that evaluates web requests, determines data boundaries, and modifies them to allow seamless processing without blocking, thereby preventing data loss.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional DLP systems block web requests containing sensitive data, then data loss prevention is improved, but user experience and system stability deteriorate
Solution Approach 1:
The patent extracts only the sensitive data elements from the web request while preserving the rest of the request structure. The DLP system identifies and removes only the specific portions containing sensitive information (such as SSN, credit card numbers) rather than blocking the entire request, thereby maintaining user experience while preventing data loss.
Solution Approach 2:
The patent segments the web request into distinct data elements and boundaries. By analyzing the request structure and identifying specific segments containing sensitive data, the system can selectively remove only those segments rather than blocking the entire request, thus maintaining system stability and user interaction.
2Reliability
If conventional DLP systems block web requests containing sensitive data, then data loss prevention is improved, but system stability deteriorates
Solution Approach 1:
The patent extracts only the sensitive data elements from the web request while preserving the rest of the request structure. The DLP system identifies and removes only the specific portions containing sensitive information (such as SSN, credit card numbers) rather than blocking the entire request, thereby maintaining user experience while preventing data loss.
Solution Approach 2:
The patent segments the web request into distinct data elements and boundaries. By analyzing the request structure and identifying specific segments containing sensitive data, the system can selectively remove only those segments rather than blocking the entire request, thus maintaining system stability and user interaction.
3Reliability
If customized responses are created for each Web 2.0 website, then data loss prevention accuracy is improved, but device complexity and maintenance burden increase
Solution Approach 1:
The patent implements a universal DLP system that can handle multiple website types and technologies through a single unified approach. The system uses general-purpose data element identification and boundary detection mechanisms that work across different web applications without requiring website-specific customization, thereby reducing complexity while maintaining high accuracy.
Solution Approach 2:
The system employs automated detection and analysis of web request structures to identify data boundaries and sensitive elements. Rather than requiring manual configuration for each website, the system self-adjusts to different web technologies and formats, reducing the need for complex customizations and ongoing maintenance.
Data Source
AI summary
A method and apparatus for selectively removing a data element that triggers a policy violation from a web request to an interactive website. In one embodiment, a computer-implemented method identifies a policy for protecting source data, having a plurality of data elements. The method further evaluates a web request sent to an interactive website as part of a web-based application, and determines that the web request includes at least one of the plurality of data elements triggering a violation of the policy. The method determines the data boundaries of the web request, and selectively removes data content within the data boundaries containing the at least one data element that triggered the violation to allow the web request to be processed by the interactive website as if it were the original web request containing the at least one data element.


