IP Library Granted Patent US 12682108
Granted Patent B2
US 12682108 · App. 18/632,168 · Granted Jul 14, 2026

Efficient statistical techniques for detecting sensitive data

Inventors: Aurelian Tutuianu (Iasi, RO); Daniel Voinea (Iasi, RO); Petru-Serban Cehan (Iasi, RO); Silviu Catalin Poede (Iasi, RO); Adrian Cadar (Iasi, RO); Marian-Razvan Udrea (Iasi, RO); Brent Gregory (Iasi, RO)
Assignee: Amazon Technologies, Inc.
G06F21/6245G06F16/2462G06F16/29G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12682108
App. No.
18/632,168
Granted
Jul 14, 2026
Kind
B2
Abstract

A candidate attribute combination of a first data set is identified, such that the candidate attribute combination meets a data type similarity criterion with respect to a collection of data types of sensitive information for which the first data set is to be analyzed. A collection of input features is generated for a machine learning model from the candidate attribute combination, including at least one feature indicative of a statistical relationship between the values of the candidate attribute combination and a second data set. An indication of a predicted probability of a presence of sensitive information in the first data set is obtained using the machine learning model.

Claims (47)

1 . A computer-implemented method, comprising:

receiving, from a client of a cloud computing environment via one or more programmatic interfaces, (a) an indication of a database comprising a plurality of tables of the client, wherein individual ones of the tables comprise a respective plurality of columns and (b) a descriptor of a category of sensitive data which is to be detected within the database;

determining, at the cloud computing environment, that a particular column of a particular table comprises data of the category; and

presenting, via the one or more programmatic interfaces to the client, at least the name of the particular column and the name of the particular table.

2 . The computer-implemented method of claim 1 , wherein said determining that the particular column of the particular table comprises data of the category comprises:

executing one or more machine learning models.

3 . The computer-implemented method as recited in claim 1 , further comprising:

performing, at the cloud computing environment, one or more additional actions in response to determining that the particular column of the particular table comprises data of the category, wherein the one or more additional actions comprise one or more of: (a) a submission of a request to the client to approve an administrative action, (b) isolation of at least a portion of the particular table, (c) encryption of at least a portion of the particular table, or (d) deletion of at least a portion of the particular table.

4 . The computer-implemented method as recited in claim 1 , wherein the category of sensitive data comprises one or more of: (a) geographical location data, (b) an identifier of a customer account, an individual, a device or an order, (c) an Internet Protocol (IP) address, (d) an email address, (e) a phone number, (f) financial data, (g) a birth date, or (h) data indicating one or more contacts of an individual.

5 . The computer-implemented method as recited in claim 1 , further comprising:

obtaining, at the cloud computing environment via the one or more programmatic interfaces, an indication of a filtering rule to be applied to select one or more columns of the plurality of columns of the particular table which are to be analyzed to predict a probability of presence of the category of sensitive data, wherein said determining that the particular column comprises data of the category is based at least in part on analysis of the one or more columns selected using the filtering rule.

6 . The computer-implemented method as recited in claim 1 , further comprising:

obtaining, at the cloud computing environment via the one or more programmatic interfaces, an indication of a schedule for analyzing the database to determine whether the database comprises data of the category, wherein said determining that the particular column comprises data of the category is performed in accordance with the schedule.

7 . The computer-implemented method as recited in claim 6 , further comprising:

obtaining, at the cloud computing environment via the one or more programmatic interfaces, a labeled training data set for training a machine learning model to detect presence of data of the category; and

training, at the cloud computing environment, the machine learning model using the labeled training data set, wherein said determining that the particular column comprises data of the category comprises utilizing the machine learning model.

8 . A system, comprising:

one or more computing devices;

wherein the one or more computing devices include instructions that upon execution on or across the one or more computing devices:

receive, from a client of a cloud computing environment via one or more programmatic interfaces, (a) an indication of a database comprising a plurality of tables of the client, wherein individual ones of the tables comprise a respective plurality of columns and (b) a descriptor of a category of sensitive data which is to be detected within the database;

determine, at the cloud computing environment, that a particular column of a particular table comprises data of the category; and

present, via the one or more programmatic interfaces to the client, at least the name of the particular column and the name of the particular table.

9 . The system of claim 8 , wherein to determine that the particular column of the particular table comprises data of the category, the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:

execute one or more machine learning models.

10 . The system of claim 8 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:

perform, at the cloud computing environment, one or more additional actions in response to determining that the particular column of the particular table comprises data of the category, wherein the one or more additional actions comprise one or more of: (a) a submission of a request to the client to approve an administrative action, (b) isolation of at least a portion of the particular table, (c) encryption of at least a portion of the particular table, or (d) deletion of at least a portion of the particular table.

11 . The system of claim 8 , wherein the category of sensitive data comprises one or more of: (a) geographical location data, (b) an identifier of a customer account, an individual, a device or an order, (c) an Internet Protocol (IP) address, (d) an email address, (e) a phone number, (f) financial data, (g) a birth date, or (h) data indicating one or more contacts of an individual.

12 . The system of claim 8 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:

obtain, at the cloud computing environment via the one or more programmatic interfaces, an indication of a filtering rule to be applied to select one or more columns of the plurality of columns of the particular table which are to be analyzed to predict a probability of presence of the category of sensitive data, wherein the determination that the particular column comprises data of the category is based at least in part on analysis of the one or more columns selected using the filtering rule.

13 . The system of claim 8 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:

obtain, at the cloud computing environment via the one or more programmatic interfaces, an indication of a schedule for analyzing the database to determine whether the database comprises data of the category, wherein the determination that the particular column comprises data of the category is made in accordance with the schedule.

14 . The system of claim 8 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:

obtain, at the cloud computing environment via the one or more programmatic interfaces, a labeled training data set for training a machine learning model to detect presence of data of the category; and

train, at the cloud computing environment, the machine learning model using the labeled training data set, wherein the determination that the particular column comprises data of the category comprises utilizing the machine learning model.

15 . One or more non-transitory computer-accessible storage media storing program instructions that when executed on or across one or more processors:

receive, from a client of a cloud computing environment via one or more programmatic interfaces, (a) an indication of a database comprising a plurality of tables of the client, wherein individual ones of the tables comprise a respective plurality of columns and (b) a descriptor of a category of sensitive data which is to be detected within the database;

determine, at the cloud computing environment, that a particular column of a particular table comprises data of the category; and

present, via the one or more programmatic interfaces to the client, at least the name of the particular column and the name of the particular table.

16 . The one or more non-transitory computer-accessible storage media of claim 15 , wherein to determine that the particular column of the particular table comprises data of the category, the one or more non-transitory computer-accessible storage media store additional program instructions that when executed on or across the one or more processors:

execute one or more machine learning models.

17 . The one or more non-transitory computer-accessible storage media of claim 15 , storing additional program instructions that when executed on or across the one or more processors:

perform, at the cloud computing environment, one or more additional actions in response to determining that the particular column of the particular table comprises data of the category, wherein the one or more additional actions comprise one or more of: (a) a submission of a request to the client to approve an administrative action, (b) isolation of at least a portion of the particular table, (c) encryption of at least a portion of the particular table, or (d) deletion of at least a portion of the particular table.

18 . The one or more non-transitory computer-accessible storage media of claim 15 , wherein the category of sensitive data comprises one or more of: (a) geographical location data, (b) an identifier of a customer account, an individual, a device or an order, (c) an Internet Protocol (IP) address, (d) an email address, (e) a phone number, (f) financial data, (g) a birth date, or (h) data indicating one or more contacts of an individual.

19 . The one or more non-transitory computer-accessible storage media of claim 15 , storing additional program instructions that when executed on or across the one or more processors:

obtain, at the cloud computing environment via the one or more programmatic interfaces, an indication of a filtering rule to be applied to select one or more columns of the plurality of columns of the particular table which are to be analyzed to predict a probability of presence of the category of sensitive data, wherein the determination that the particular column comprises data of the category is based at least in part on analysis of the one or more columns selected using the filtering rule.

20 . The one or more non-transitory computer-accessible storage media of claim 15 , storing additional program instructions that when executed on or across the one or more processors:

obtain, at the cloud computing environment via the one or more programmatic interfaces, an indication of a schedule for analyzing the database to determine whether the database comprises data of the category, wherein the determination that the particular column comprises data of the category is made in accordance with the schedule.