Detection and prevention of sensitive information leaks

US9779254B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9779254-B2
Application numberUS-201414190569-A
CountryUS
Kind codeB2
Filing dateFeb 26, 2014
Priority dateFeb 26, 2014
Publication dateOct 3, 2017
Grant dateOct 3, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Examples of techniques for detecting and preventing sensitive information leaks are described herein. In one example, a method for detection of sensitive information leaks comprises computing, via a processor, a set of rules that identify sensitive information, and sending, via the processor, the set of rules to a dispatcher application using a protocol. The method can also include detecting, via the processor, that at least one data block of the transmitted data matches the set of rules, and executing, via the processor, a corrective action in response to detecting that at least one of the transmitted data blocks matches the set of rules.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for detection and prevention of sensitive information leaks comprising: a memory device comprising processor executable instructions; and a processor to: identify an event of one or more data blocks in a predetermined secure portion of a database being accessed by a device; compute a set of rules that identify sensitive information in the one or more data blocks accessed by the device, wherein the set of rules identify a pattern of the sensitive information and is computed by a first data leaks application, wherein the first data leaks application executes according to a first algorithm, and wherein the sensitive information includes transaction data from a point of sale device; send, to a dispatcher application, using a protocol, the set of rules and event-specific parameters associated with the event of accessing the one or more data blocks, the event-specific parameters including an identifier of the point of sale device, an identifier of a transport protocol being used for transmitting the one or more data blocks by the device, an identifier of a process that is transmitting the one or more data blocks, an identifier of a user that is transmitting the one or more data blocks, and a timestamp associated with the access of the one or more data blocks; monitor the one or more data blocks in a data transmission from the device in real-time; execute a corrective action in response to detecting that at least one of the data blocks from the event that is being transmitted by the device matches the set of rules that are associated with the event-specific parameters; and in response to detecting that the first data leaks application, using the set of rules, cannot identify sensitive information from the data blocks from the predetermined secure portion of the database being transmitted by the device, generating a second data leaks application by populating a predefined template with the event-specific parameters, and sending the template to the second data leaks application, wherein the second data leaks application computes a second set of rules based on the event-specific parameters and executes according to a second algorithm, distinct from the first data leaks application. 2. The system of claim 1 , wherein the processor is further configured to execute a corrective action in response to detecting that at least one of the data blocks matches the second set of rules of the second data leaks application, wherein the corrective action comprises preventing the transmitted data from being sent to an external computing device. 3. The system of claim 1 , wherein the protocol comprises the event-specific parameters that, along with the set of rules, identifies sensitive information based on metadata and attributes. 4. The system of claim 3 , wherein the second data leaks application includes a second filter, distinct from a first filter of the first data leaks application, wherein a filter determines a portion of the transmitted data to monitor for sensitive information based on the event-specific parameters. 5. The system of claim 4 , wherein the processor is further configured to execute the second data leaks application to identify transmitted data that includes sensitive information. 6. The system of claim 1 , wherein the processor is configured to: detect a filter for the sensitive information; detect that the first data leaks application is to be updated based on the filter; and update the first data leaks application to identify the sensitive information with the filter. 7. The system of claim 3 , wherein the protocol enables the transmission of the event-specific parameters between at least two computing devices. 8. The system of claim 1 , wherein the protocol includes an origin system identifier that identifies a source that provided the set of rules, wherein the dispatcher application receives sets of rules from multiple sources and distinguishes among the sets of rules using corresponding origin system identifiers. 9. The system of claim 1 , wherein the event-specific parameters further includes an identifier of a transaction associated with the sensitive information.

Assignees

Inventors

Classifications

  • G06F21/552Primary

    involving long-term monitoring or reporting · CPC title

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

  • G06F21/60Primary

    Protecting data · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9779254B2 cover?
Examples of techniques for detecting and preventing sensitive information leaks are described herein. In one example, a method for detection of sensitive information leaks comprises computing, via a processor, a set of rules that identify sensitive information, and sending, via the processor, the set of rules to a dispatcher application using a protocol. The method can also include detecting, v…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F21/552. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 03 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).