System and method for identifying a data type associated with an application server
Computing platforms, methods, and storage media for identifying a data type associated with an application server are disclosed. Exemplary implementations may: determine, based on scanning real-time traffic associated with the application server, whether the application server is internet-facing; examine an application log associated with the application server with respect to presence of masking characters associated with masking personally identifiable information (PII); and in response to detecting masking characters in the application log: perform a real-time determination that the application server processes PII data; and generate a recommendation with respect to additional protection or encryption for the PII data. Exemplary implementations may automatically determine whether PII is being collected by a server based on access to an application log, and without having direct access to application data associated with the server.
1 . An apparatus configured for identification of a data type associated with an application server, the apparatus comprising:
a non-transient computer-readable storage medium having executable instructions embodied thereon; and
one or more hardware processors configured to execute the instructions to:
determine, based on scanning real-time traffic associated with the application server, a digital certificate type associated with the application server and whether the application server is internet-facing;
examine an application log associated with the application server with respect to presence of masking characters associated with masking personally identifiable information (PII); and
in response to detecting masking characters in the application log:
perform a real-time determination that the application server processes PII data; and
generate a recommendation with respect to additional protection or encryption for the PII data;
generate, based on the determination of whether the application server is internet-facing and based on the digital certificate type associated with the application server, a certificate management assessment result; and
initiate a certificate change if the digital certificate type is determined to be unsuitable with respect to security requirements associated with the application server.
2 . The apparatus of claim 1 wherein the one or more hardware processors are further configured to execute the instructions to:
perform the real-time determination that the application server processes PII data independent of direct access to application data associated with the application server.
3 . The apparatus of claim 1 wherein the one or more hardware processors are further configured to execute the instructions to:
examine the application log with respect to presence of a data field name associated with processing PII data; and
perform the real-time determination that the application server processes PII data in response to one or more of detecting masking characters in the application log and detecting presence of a data field name associated with processing PII data.
4 . The apparatus of claim 1 wherein the one or more hardware processors are further configured to execute the instructions to:
examine a code repository associated with the application server; and
identify class-level or application-level information associated with processing PII data.
5 . The apparatus of claim 1 wherein the one or more hardware processors are further configured to execute the instructions to:
examine a code repository associated with the application server; and
identify presence or absence of a variable name associated with processing PII data.
6 . The apparatus of claim 1 wherein the one or more hardware processors are further configured to execute the instructions to:
generate a security recommendation based on determining that an application programming interface (API) associated with the application server requires additional protection or encryption.
7 . The apparatus of claim 1 wherein the one or more hardware processors are further configured to execute the instructions to:
receive a feed from a monitoring system, the feed comprising the real-time traffic associated with the application server.
8 . A processor-implemented method of identifying a data type associated with an application server, the method comprising:
determining, based on scanning real-time traffic associated with the application server, a digital certificate type associated with the application server and whether the application server is internet-facing;
examining an application log associated with the application server with respect to presence of masking characters associated with masking personally identifiable information (PII); and
in response to detecting masking characters in the application log:
performing a real-time determination that the application server processes PII data; and
generating a recommendation with respect to additional protection or encryption for the PII data;
generating, based on the determination of whether the application server is internet-facing and based on the digital certificate type associated with the application server, a certificate management assessment result; and
initiating a certificate change if the digital certificate type is determined to be unsuitable with respect to security requirements associated with the application server.
9 . The method of claim 8 further comprising:
performing the real-time determination that the application server processes PII data independent of direct access to application data associated with the application server.
10 . The method of claim 8 further comprising:
examining the application log with respect to presence of a data field name associated with processing PII data; and
performing the real-time determination that the application server processes PII data in response to one or more of detecting marking characters in the application log and detecting presence of a data field name associated with processing PII data.
11 . The method of claim 8 further comprising:
examining a code repository associated with the application server; and
identifying class-level or application-level information associated with processing PII data.
12 . The method of claim 8 further comprising:
examining a code repository associated with the application server; and
identifying presence or absence of a variable name associated with processing PII data.
13 . The method of claim 8 further comprising:
generating a security recommendation based on determining that an application programming interface (API) associated with the application server requires additional protection or encryption.
14 . The method of claim 8 further comprising:
receiving a feed from a monitoring system, the feed comprising the real-time traffic associated with the application server.
15 . A non-transient computer-readable storage medium having instructions embodied thereon, the instructions being executable by one or more processors to perform a method of identifying a data type associated with an application server, the method comprising:
determining, based on scanning real-time traffic associated with the application server, a digital certificate type associated with the application server and whether the application server is internet-facing;
examining an application log associated with the application server with respect to presence of masking characters associated with masking personally identifiable information (PII); and
in response to detecting masking characters in the application log:
performing a real-time determination that the application server processes PII data; and
generating a recommendation with respect to additional protection or encryption for the PII data;
generating, based on the determination of whether the application server is internet-facing and based on the digital certificate type associated with the application server, a certificate management assessment result; and
initiating a certificate change if the digital certificate type is determined to be unsuitable with respect to security requirements associated with the application server.
16 . The non-transient computer-readable storage medium of claim 15 wherein the method further comprises:
performing the real-time determination that the application server processes PII data independent of direct access to application data associated with the application server.
17 . The non-transient computer-readable storage medium of claim 15 wherein the method further comprises:
performing the real-time determination that the application server processes PII data independent of direct access to application data associated with the application server.
18 . The non-transient computer-readable storage medium of claim 15 wherein the method further comprises:
examining the application log with respect to presence of a data field name associated with processing PII data; and
performing the real-time determination that the application server processes PII data in response to one or more of detecting marking characters in the application log and detecting presence of a data field name associated with processing PII data.
19 . The non-transient computer-readable storage medium of claim 15 wherein the method further comprises:
examining a code repository associated with the application server; and
identifying class-level or application-level information associated with processing PII data.
20 . The non-transient computer-readable storage medium of claim 19 wherein the method further comprises:
examining a code repository associated with the application server, and
identifying presence or absence of a variable name associated with processing PII data.