IP Library Granted Patent US 9,349,016
Granted Patent B1
US 9,349,016 · App. 14/298,095 · Granted May 24, 2016

System and method for user-context-based data loss prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,349,016
App. No.
14/298,095
Granted
May 24, 2016
Kind
B1
Abstract

In one embodiment, a method includes determining a user context of at least one user device currently accessing an enterprise communication platform. The method further includes selecting a dynamic data loss prevention (DLP) policy applicable to the at least one user device based, at least in part, on the user context. The dynamic DLP policy specifies one or more communication events of interest. In addition, the method includes monitoring communication events initiated by the at least one user device for the one or more communication events of interest. Moreover, the method includes, responsive to each communication event of interest: assessing the communication event of interest based, at least in part, on a content-based classification of a communication associated with the communication event of interest; and responsive to a risk assessment meeting certain criteria, taking at least one action specified by the dynamic DLP policy.

Claims (51)

1. A method comprising, by at least one computer system comprising computer hardware:

determining a user context of at least one user device currently accessing an enterprise communication platform;

selecting a dynamic data loss prevention (DLP) policy applicable to the at least one user device based, at least in part, on the user context;

wherein the dynamic DLP policy specifies one or more pre-transmission communication events of interest;

wherein the one or more pre-transmission communication events of interest comprise creation of an unsent draft communication via the at least one user device;

monitoring communication events initiated by the at least one user device for the one or more pre-transmission communication events of interest;

responsive to the monitoring, determining that a pre-transmission communication event of interest has occurred, the determining comprising detecting a new unsent draft communication, initiated by the at least one user device, in a designated storage location for unsent draft communications;

assessing the pre-transmission communication event of interest based, at least in part, on a content-based classification of the new unsent draft communication; and

responsive to a risk assessment meeting certain criteria, taking at least one action specified by the dynamic DLP policy.

2. The method of claim 1 , comprising publishing each risk assessment to a real-time risk-evaluation dashboard on the at least one user device.

3. The method of claim 2 , comprising:

receiving an attestation input from the at least one user device;

adjusting at least one of the user context and the dynamic DLP policy responsive to the attestation input; and

logging the attestation input.

4. The method of claim 3 , wherein:

the attestation input comprises a user certification related to a riskiness of at least one communication event of interest; and

the adjusting comprises modifying a trigger threshold of the dynamic DLP policy for the at least one communication event of interest.

5. The method of claim 1 , wherein the taking comprises publishing a warning to the at least one user device.

6. The method of claim 1 , wherein the user context comprises user-location information and user-device identification information.

7. The method of claim 1 , wherein the taking comprises preventing further access to the new unsent draft communication.

8. The method of claim 1 , wherein the taking comprises preventing further access to the enterprise communication platform.

9. The method of claim 1 , wherein the taking comprises preventing transmission of the new unsent draft communication.

10. An information handling system comprising:

a processor comprising computer hardware, wherein the processor is configured to implement a method, the method comprising:

determining a user context of at least one user device currently accessing an enterprise communication platform;

selecting a dynamic data loss prevention (DLP) policy applicable to the at least one user device based, at least in part, on the user context;

wherein the dynamic DLP policy specifies one or more pre-transmission communication events of interest;

wherein the one or more pre-transmission communication events of interest comprise creation of an unsent draft communication via the at least one user device;

monitoring communication events initiated by the at least one user device for the one or more pre-transmission communication events of interest;

responsive to the monitoring, determining that a pre-transmission communication event of interest has occurred, the determining comprising detecting a new unsent draft communication, initiated by the at least one user device, in a designated storage location for unsent draft communications;

assessing the pre-transmission communication event of interest based, at least in part, on a content-based classification of the new unsent draft communication; and

responsive to a risk assessment meeting certain criteria, taking at least one action specified by the dynamic DLP policy.

11. The information handling system of claim 10 , the method comprising publishing each risk assessment to a real-time risk-evaluation dashboard on the at least one user device.

12. The information handling system of claim 11 , the method comprising:

receiving an attestation input from the at least one user device;

adjusting at least one of the user context and the dynamic DLP policy responsive to the attestation input; and

logging the attestation input.

13. The information handling system of claim 12 , wherein:

the attestation input comprises a user certification related to a safety of at least one communication event of interest; and

the adjusting comprises modifying a trigger threshold of the dynamic DLP policy for the at least one communication event of interest.

14. The information handling system of claim 10 , wherein the taking comprises publishing a warning to the at least one user device.

15. The information handling system of claim 10 , wherein the user context comprises user-location information and user-device identification information.

16. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

determining a user context of at least one user device currently accessing an enterprise communication platform;

selecting a dynamic data loss prevention (DLP) policy applicable to the at least one user device based, at least in part, on the user context;

wherein the dynamic DLP policy specifies one or more pre-transmission communication events of interest;

wherein the one or more pre-transmission communication events of interest comprise creation of an unsent draft communication via the at least one user device;

monitoring communication events initiated by the at least one user device for the one or more pre-transmission communication events of interest;

responsive to the monitoring, determining that a pre-transmission communication event of interest has occurred, the determining comprising detecting a new unsent draft communication, initiated by the at least one user device, in a designated storage location for unsent draft communications;

assessing the pre-transmission communication event of interest based, at least in part, on a content-based classification of the new unsent draft communication; and

responsive to a risk assessment meeting certain criteria, taking at least one action specified by the dynamic DLP policy.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 033625 FRAME 0748 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0050 →
RELEASE OF REEL 033625 FRAME 0688 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0757 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 033625 FRAME 0711 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040016/0903 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 033625/0748 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033625/0711 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 033625/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2014
From: BRISEBOIS, MICHEL ALBERT; JOHNSTONE, CURTIS T.
To: DELL SOFTWARE INC.
Reel/Frame 033085/0104 →