Invention Grant
- Patent Title: Controlling access to sensitive data based on changes in information classification
- Patent Title (中): 根据信息分类的变化控制对敏感数据的访问
-
Application No.: US13020589Application Date: 2011-02-03
-
Publication No.: US08800031B2Publication Date: 2014-08-05
- Inventor: David Scott Cecil , Peter Terence Cogill , Daniel McKenzie Taylor
- Applicant: David Scott Cecil , Peter Terence Cogill , Daniel McKenzie Taylor
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
A Data Loss Prevention (DLP) system includes an automated method for tracking changes to a security classification (e.g., content category) associated with an artifact to determine whether an attempt is being made to subvert a DLP policy. The method exploits the basic principle that, depending on context, the classification of a particular artifact, or a change to an existing classification, may indicate an attempt to subvert the policy. According to the method, an artifact classification state machine is implemented within a DLP system. For each policy-defined content category on each artifact, the machine identifies a content category change that may be of interest, as defined by policy. When a change in a classification has occurred, an artifact notification event (or, more generally, a notification of the change in classification) is issued.
Public/Granted literature
- US20120204260A1 Controlling access to sensitive data based on changes in information classification Public/Granted day:2012-08-09
Information query