IP Library Granted Patent US 8,447,722
Granted Patent B1
US 8,447,722 · App. 12/410,875 · Granted May 21, 2013

System and method for data mining and security policy management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,447,722
App. No.
12/410,875
Granted
May 21, 2013
Kind
B1
Abstract

A method is provided in one example and includes generating a query for a database for information stored in the database. The information relates to data discovered through a capture system. The method further includes generating an Online Analytical Processing (OLAP) element to represent information received from the query. A rule based on the OLAP element is generated and the rule affects data management for one or more documents that satisfy the rule. In more specific embodiments, the method further includes generating a capture rule that defines items the capture system should capture. The method also includes generating a discovery rule that defines objects the capture system should register. In still other embodiments, the method includes developing a policy based on the rule, where the policy identifies how one or more documents are permitted to traverse a network.

Claims (53)

1. A method, comprising:

filtering information contained in a plurality of tags stored in a database, the filtering based on one or more specified elements of a tag, wherein the information relates to objects discovered through a capture system, and wherein each object is associated with one of the tags, wherein each of the one or more specified elements includes one of a communication parameter, a content type, a concept, a word, and a signature;

generating an Online Analytical Processing (OLAP) element to represent the filtered information;

receiving as input one or more parameters based, at least in part, on the OLAP element, wherein each of the one or more parameters includes one of a communication parameter, a content type, a concept, a word, and a signature; and

generating a rule from the one or more parameters, wherein the rule includes an action to be performed on one or more objects identified by the one or more parameters, the one or more objects sought to be propagated through e-mail in a network environment.

2. The method of claim 1 , further comprising:

generating a capture rule that defines items the capture system should capture; and

generating a discovery rule that defines objects the capture system should register.

3. The method of claim 1 , further comprising:

developing a policy based on the rule, wherein the policy identifies how one or more documents are permitted to traverse a network.

4. The method of claim 3 , wherein the capture system applies and enforces the policy that is based on the rule, and wherein enforcement of the policy includes prohibiting at least one of the documents from being transmitted over the network.

5. The method of claim 1 , further comprising:

capturing a packet stream;

recreating a flow from the packet stream;

analyzing the flow to create at least one tag and at least one object from the flow; and

storing the at least one tag in a tag database and the at least one object in an object database.

6. The method of claim 1 , wherein the filtering is part of one or more data mining activities.

7. The method of claim 1 , further comprising:

updating one or more parameters for a rule or a policy; and

storing the updates in a database to be accessed by the capture system.

8. The method of claim 1 , further comprising:

applying one or more filters in conjunction with one or more data mining activities before the OLAP element is generated.

9. An apparatus, comprising:

a capture system that includes a processor and the memory, the apparatus being configured to:

filter information contained in a plurality of tags stored in a database, the filtering based on one or more specified elements of a tag, wherein the information relates to objects discovered through a capture system, and wherein each object is associated with one of the tags, wherein each of the one or more specified elements includes one of a communication parameter, a content type, a concept, a word, and a signature,

generate an Online Analytical Processing (OLAP) element to represent the filtered information, and

receive one or more parameters based, at least in part, on the OLAP element, wherein each of the one or more parameters includes one of a communication parameter, a content type, a concept, a word, and a signature, wherein a rule is generated from the one or more parameters, and wherein the rule includes an action to be performed on one or more objects identified by the one or more parameters, the one or more objects sought to be propagated through e-mail in a network environment.

10. The apparatus of claim 9 , wherein a policy is developed based on the rule, and wherein the policy identifies how one or more documents are permitted to traverse a network.

11. The apparatus of claim 10 , wherein the capture system applies and enforces the policy that is based on the rule, and wherein enforcement of the policy includes prohibiting at least one of the documents from being transmitted over the network.

12. The apparatus of claim 9 , wherein the capture system captures a packet stream, recreates a flow from the packet stream, analyzes the flow to create at least one tag and at least one object from the flow, and stores the at least one tag in a tag database and the at least one object in an object database.

13. The apparatus of claim 9 , wherein the filtering is part of one or more data mining activities.

14. Logic encoded in non-transitory media for execution and when executed by a processor operable to:

filter information contained in a plurality of tags stored in a database, the filtering based on one or more specified elements of a tag, wherein the information relates to objects discovered through a capture system, and wherein each object is associated with one of the tags, wherein each of the one or more specified elements includes one of a communication parameter, a content type, a concept, a word, and a signature;

generate an Online Analytical Processing (OLAP) element to represent the filtered information;

receiving as input one or more parameters based, at least in part, on the OLAP element, wherein each of the one or more parameters includes one of a communication parameter, a content type, a concept, a word, and a signature; and

generate a rule from the one or more parameters, wherein the rule includes an action to be performed on one or more objects identified by the one or more parameters, the one or more objects that satisfy the rule.

15. The logic of claim 14 , wherein the code is further operable to:

generate a capture rule that defines items the capture system should capture; and

generate a discovery rule that defines objects the capture system should register.

16. The logic of claim 14 , wherein the code is further operable to:

develop a policy based on the rule, wherein the policy identifies how one or more documents are permitted to traverse a network.

17. The logic of claim 16 , wherein the capture system applies and enforces the policy that is based on the rule, and wherein enforcement of the policy includes prohibiting at least one of the documents from being transmitted over the network.

18. The logic of claim 14 , wherein the code is further operable to:

capture a packet stream;

recreate a flow from the packet stream;

analyze the flow to create at least one tag and at least one object from the flow; and

store the at least one tag in a tag database and the at least one object in an object database.

19. The logic of claim 14 , wherein the filtering is part of one or more data mining activities.

20. The logic of claim 14 , wherein the code is further operable to:

update one or more parameters for a rule or a policy; and

store the updates in a database to be accessed by the capture system.

21. The logic of claim 14 , wherein the code is further operable to:

apply one or more filters in conjunction with one or more data mining activities before the OLAP element is generated.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →