IP Library Granted Patent US 8,793,802
Granted Patent B2
US 8,793,802 · App. 11/752,208 · Granted Jul 29, 2014

System, method, and computer program product for preventing data leakage utilizing a map of data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,793,802
App. No.
11/752,208
Granted
Jul 29, 2014
Kind
B2
Abstract

A system, method, and computer program product are provided for preventing data leakage utilizing a map of data. In use, information describing data stored on at least one system is received. To this end, a map of the data is generated, utilizing the information. Further, data leakage is prevented, utilizing the map.

Claims (60)

1. A method, comprising:

receiving information describing data stored on at least one system;

generating a baseline map of the data, utilizing the information;

generating a current map that reflects a network map, wherein generating the baseline map and the current map includes mapping a location of the data to a categorization of the data, and wherein the location of the data includes an internet protocol address associated with the at least one system;

comparing the baseline map to the current map prior to receiving a request to transmit at least some of the data, wherein the comparing includes:

identifying differences in categorizations for documents between the baseline map and the current map with respect to their respective locations on a plurality of different file servers; and

preventing a transfer of the documents over a network based on the differences in the categorizations for the documents between the baseline map and the current map.

2. The method of claim 1 , wherein the data includes at least one file.

3. The method of claim 1 , wherein the data includes at least one electronic mail message.

4. The method of claim 1 , wherein the information includes a categorization of the data.

5. The method of claim 4 , wherein the categorization is associated with criteria.

6. The method of claim 5 , wherein the criteria is predetermined.

7. The method of claim 6 , wherein the criteria is based on a selected document.

8. The method of claim 4 , wherein the categorization is associated with a group within an organization.

9. The method of claim 1 , wherein the information includes a statistical analysis of the data.

10. The method of claim 9 , wherein the statistical analysis indicates a number of occurrences of at least one predetermined keyword within the data.

11. The method of claim 1 , wherein the data is stored on a single system.

12. The method of claim 1 , wherein the data is stored on a group of systems.

13. The method of claim 1 , wherein the location of the data further includes at least one of a pathname associated with the data, a user name, and a machine name.

14. The method of claim 1 , wherein the information describing the data is identified by parsing the data.

15. The method of claim 1 , further comprising accessing a policy, which indicates an allowable threshold number of differences between the baseline map and the current map, for permitting a transmission of at least some of the data.

16. The method of claim 15 , wherein data leakage is conditionally prevented based on the policy.

17. The method of claim 1 , wherein data leakage is prevented by securing the data.

18. Logic embodied on a tangible non-transitory computer readable medium for performing operations, comprising:

receiving information describing data stored on at least one system;

generating a baseline map of the data, utilizing the information;

generating a current map that reflects a network map, wherein generating the baseline map and the current map includes mapping a location of the data to a categorization of the data, and wherein the location of the data includes an internet protocol address associated with the at least one system;

comparing the baseline map to the current map prior to receiving a request to transmit at least some of the data, wherein the comparing includes:

identifying differences in categorizations for documents between the baseline map and the current map with respect to their respective locations on a plurality of different file servers; and

preventing a transfer of the documents over a network based on the differences in the categorizations for the documents between the baseline map and the current map.

19. The tangible non-transitory computer readable medium of claim 18 , wherein the data includes at least one file.

20. The tangible non-transitory computer readable medium of claim 18 , wherein the data includes at least one electronic mail message.

21. The tangible non-transitory computer readable medium of claim 18 , wherein the information includes a categorization of the data.

22. The tangible non-transitory computer readable medium of claim 21 , wherein the categorization is associated with criteria and the criteria is predetermined.

23. The tangible non-transitory computer readable medium of claim 18 , wherein the information includes a statistical analysis of the data.

24. The tangible non-transitory computer readable medium of claim 23 , wherein the statistical analysis indicates a number of occurrences of at least one predetermined keyword within the data.

25. The tangible non-transitory computer readable medium of claim 18 , wherein generating the baseline map includes mapping a location of the data to a categorization of the data.

26. The tangible non-transitory computer readable medium of claim 18 , wherein the location of the data includes at least one of a pathname associated with the data, a user name, and a machine name.

27. The tangible non-transitory computer readable medium of claim 18 , the operations further comprising accessing a policy, which indicates an allowable threshold number of differences between the baseline map and the current map, for permitting a transmission of at least some of the data.

28. A central server, comprising:

a baseline map of data stored in a memory;

a current map of data stored in the memory;

a processor communicatively coupled to the memory;

logic communicatively coupled to the processor to:

receive information describing data stored on at least one system,

generate a baseline map of the data, utilizing the information, and

generate a current map that reflects a network map, wherein generating the baseline map and the current map includes mapping a location of the data to a categorization of the data, and wherein the location of the data includes an internet protocol address associated with the at least one system,

compare the baseline map to the current map prior to receiving a request to transmit at least some of the data,

wherein the compare includes:

identifying differences in categorizations for documents between the baseline map and the current map with respect to their respective locations on a plurality of different file servers; and

prevent a transfer of the documents over a network based on the differences in the categorizations for the documents between the baseline map and the current map.

29. The central server of claim 28 , wherein the data includes at least one file.

30. The central server of claim 28 , wherein the data includes at least one electronic mail message.

31. The central server of claim 28 , wherein the information includes a categorization of the data.

32. The central server of claim 31 , wherein the categorization is associated with criteria and the criteria is predetermined.

33. The central server of claim 28 , wherein the information includes a statistical analysis of the data.

34. The central server of claim 33 , wherein the statistical analysis indicates a number of occurrences of at least one predetermined keyword within the data.

35. The central server of claim 28 , wherein generating the baseline map includes mapping a location of the data to a categorization of the data.

36. The central server of claim 28 , wherein the location of the data includes at least one of a pathname associated with the data, a user name, and a machine name.

37. The central server of claim 28 , the logic being communicatively coupled to the processor to access a policy, which indicates an allowable threshold number of differences between the baseline map and the current map, for permitting a transmission of at least some of the data.

Assignments (19)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 061032/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2007
From: BISHOP, MICHAEL G.
To: MCAFEE, INC.
Reel/Frame 019333/0451 →