Systems and methods for managing data security
Exemplary embodiments for data security include a data access proxy coupled with a database, further coupled with a server configured to operate the data access proxy to: identify a user and request to access a data item; validate the user and request, including inspecting the user's identity, evaluating the user's history, and evaluating permissions and restrictions associated with the user and the data item; access the database to retrieve the data item; inspect security attributes related to the data item; and transform the data item based on one or more privacy rules, including redacting the at least one data item, deleting information from the at least one data item, substituting information from the at least one private data item with other information, adding information to the at least one data item, providing synthetic data as a private data item, or providing proxy data for the data item.
1 . A data security system comprising:
at least one artificial intelligence resource comprising at least one named-entity recognition model, at least one large language model, and at least one artificial intelligence application supported by a neural network; and
at least one server communicatively coupled to the artificial intelligence resource and further communicatively coupled to at least one private database, the server configured to operate the artificial intelligence resource to:
identify a user and a request from the user to access at least one data item stored in the private database;
validate the user and the request, the validation including inspecting the user's identity, evaluating permissions and restrictions associated with the user and the data item, and evaluating the user's activity history by directing information associated with the user, including user history and behavior, to the artificial intelligence application supported by the neural network for detecting anomalous or outlier activity of the user, the neural network being trained on query history data to recognize routine and conventional activity associated with a user category for the user;
analyze user activity associated with the user for suspicious activity via a neural network application;
access the private database to retrieve the data item;
inspect one or more security attributes related to the data item via the named-entity recognition model;
transform the data item based on one or more privacy rules via the large language model using results from both the neural network application analysis and the named-entity recognition model inspection, the transformation comprising:
at least one of: redacting information from the data item, deleting information from the data item, substituting information from the data item with other information, and adding information to the data item; and
at least one of: substituting synthetic data for the data item, providing the synthetic data as a private data item, and providing proxy data for the data item, the synthetic data or the proxy data being used by the server and the artificial intelligence resource as a tracker to trace data traffic associated with the user;
reconstitute the data item in a response to the request; and
transmit the response with a transformed version of the data item to the user or a designated recipient.
2 . The data security system of claim 1 , wherein the transformed version of the data item includes the synthetic data resembling sensitive information in the data item.
3 . The data security system of claim 1 , wherein the named-entity recognition model is trained to identify at least one of: personally identifiable information (PII), financial data, medical information, and trade secrets within the data item, and wherein the named-entity recognition model outputs confidence scores for identified sensitive information types.
4 . The data security system of claim 1 , wherein the named-entity recognition model is configured to detect patterns within database columns and associate identified patterns with known classes of personally identifiable information.
5 . The data security system of claim 1 , the large language model being configured to generate and validate code for a security measure, including comments within the code that can be used to track a user's subsequent activity.
6 . The data security system of claim 5 , the code having comments within the code, the comments being used to track the user's subsequent activity.
7 . The data security system of claim 1 , the artificial intelligence resource further including functionality for optical character recognition.
8 . The data security system of claim 1 , the artificial intelligence resource further including functionality for text classification.
9 . The data security system of claim 1 , the artificial intelligence resource further including functionality for image classification.
10 . The data security system of claim 1 , the large language model further supporting a chatbot and further being trained on organizational legacy resources and access-control lists.
11 . A method for data security comprising:
identifying a user and a request from the user to access at least one data item stored in at least one private database, the identifying being performed by an artificial intelligence resource comprising at least one named-entity recognition model, at least one large language model, and at least one artificial intelligence application supported by a neural network, the artificial intelligence resource further being coupled with at least one server configured to operate the artificial intelligence resource;
validating the user and the request, by the artificial intelligence resource, the validating including inspecting the user's identity, evaluating permissions and restrictions associated with the user and the data item, and evaluating the user's activity history by directing information associated with the user, including user history and behavior, to the artificial intelligence application supported by the neural network, the neural network being trained on query history data to recognize routine and conventional activity associated with a user category for the user;
analyzing user activity associated with the user for suspicious activity via the neural network application;
accessing the private database to retrieve the data item by the artificial intelligence resource;
inspecting one or more security attributes related to the data item via the named-entity recognition model;
transforming the data item based on one or more privacy rules via the large language model using results from both the neural network application analysis and the named-entity recognition model inspection, the transforming comprising:
at least one of: redacting information from the data item, deleting information from the data item, substituting information from the private data item with other information, and adding information to the data item; and
at least one of: substituting synthetic data for the data item, providing synthetic data as a private data item, and providing proxy data for the data item, the synthetic data or the proxy data being used by the server and the artificial intelligence resource as a tracker to trace data traffic associated with the user;
reconstituting, by the artificial intelligence resource, the data item in a response to the request; and
transmitting the response with a transformed version of the data item to the user or a designated recipient.
12 . The method of claim 11 , wherein the transformed version of the data item includes the synthetic data resembling sensitive information in the data item.
13 . The method of claim 11 , wherein the named-entity recognition model is trained to identify personally identifiable information (PII), financial data, medical information, and trade secrets within the data item, and wherein the named-entity recognition model outputs confidence scores for identified sensitive information types.
14 . The method of claim 11 , wherein the named-entity recognition model is configured to detect patterns within database columns and associate identified patterns with known classes of personally identifiable information.
15 . The method of claim 11 , further comprising generating and validating, by the large language model, code for a security measure, including comments within the code that can be used to track a user's subsequent activity.
16 . The method of claim 15 , the code having comments within the code, the comments being used to track the user's subsequent activity.
17 . The method of claim 11 , the artificial intelligence resource further including functionality for optical character recognition.
18 . The method of claim 11 , the artificial intelligence resource further including functionality for text classification.
19 . The method of claim 11 , the artificial intelligence resource further including functionality for image classification.
20 . The method of claim 11 , the large language model further supporting a chatbot and further being trained on organizational legacy resources and access-control lists.