IP Library Patent Application 15728137
Patent Application
App. No. 15/728,137

SYSTEMS AND METHODS FOR IDENTIFYING POTENTIAL MISUSE OR EXFILTRATION OF DATA

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/728,137
Abstract

Provided herein are systems and methods for preventing or controlling data movement. A learning engine may detect capabilities of a computing environment for allowing data access or transfer, and activities relating to data access or transfer from the computing environment. Data assets of the computing environment that are protected may be identified, according to metadata of the data assets. The learning engine may, according to the identified data assets and at least one of the detected capabilities or activities, determine a situation within the computing environment that represents potential or actual exfiltration of one of the identified data assets. A rule engine may perform an action to prevent or control the potential or actual data movement of the one of the identified data assets, responsive to applying one or more rules to the determined situation.

Claims (28)

1 . A system for preventing or controlling misuse of data, the system comprising:

a learning engine executing on one or more processors, the learning engine configured to:

detect capabilities of a computing environment for allowing data access or transfer, and activities relating to data access or transfer from, into or through the computing environment; and

determine, according to data assets of the computing environment that are identified to be protected, and at least one of the detected capabilities or activities, a situation within the computing environment that represents potential or actual misuse of one of the identified data assets, wherein the data assets that are to be protected are identified according to metadata of the data assets; and

a rule engine executing on the one or more processors, the rule engine configured to perform an action to prevent or control the potential or actual misuse of the one of the identified data assets, responsive to applying one or more rules to the determined situation.

2 . The system of claim 1 , further comprising training data for use by the learning engine to recognize application or user behavior indicative of potential or actual misuse of data.

3 . The system of claim 1 , wherein the learning engine is configured to detect the capabilities or the activities by monitoring or detecting one or more of: graphical user interface (GUI) controls available to a user control selection by the user, application programming interface (API) calls, files accessed, data communicated over a network, or activity using an input/output (I/O) device.

4 . The system of claim 1 , wherein the learning engine is configured to identify a first data asset that is protected, by monitoring or identifying at least one of: a residing location of the first data asset, an owner of the first data asset, a type of the first data asset, or whether part or all of the first data asset comprises classified or sensitive data.

5 . The system of claim 1 , wherein the computing environment comprises at least one of a web browser, an application, background system service, or an input/output (I/O) device.

6 . The system of claim 5 , wherein the application comprises a cloud-synchronization application, an electronic-mail application, a document processing or rendering application, a data transfer or copying application, or a facsimile or printing application.

7 . The system of claim 1 , wherein the learning engine is configured to detect the capabilities or the activities by detecting meta-data, words or phrases associated with application interfaces indicative of means of data egress from the computing environment.

8 . The system of claim 7 , wherein the learning engine is configured to determine the situation within the computing environment that represents potential or actual misuse of the one of the identified data assets, by relating the detected words or phrases in the application interfaces, to an user action via one or more corresponding application interfaces.

9 . The system of claim 1 , wherein the learning engine is configured to determine whether there is a situation within the computing environment that represents potential or actual exfiltration of one or more of the identified data assets, responsive to a triggering event.

10 . The system of claim 1 , wherein the action to prevent or control the potential or actual misuse of data comprises at least one of: warning or blocking a user against data movement of the one of the identified data assets, or blocking data movement of the one of the identified data assets by an application.

11 . A method for preventing or controlling misuse of data, the method comprising:

detecting, by a learning engine executing on one or more processors, capabilities of a computing environment for allowing data access or transfer, and activities relating to data access or transfer from the computing environment;

identifying data assets of the computing environment that are protected, according to metadata of the data assets;

determining, by the learning engine according to the identified data assets and at least one of the detected capabilities or activities, a situation within the computing environment that represents potential or actual misuse of one of the identified data assets; and

performing, by a rule engine executing on the one or more processors, an action to prevent or control the potential or actual misuse of the one of the identified data assets, responsive to applying one or more rules to the determined situation.

12 . The method of claim 11 , further comprising providing the training data, for use by the learning engine to recognize application or user behavior indicative of potential or actual misuse of data.

13 . The method of claim 11 , wherein detecting the capabilities or the activities comprises monitoring or detecting one or more of: graphical user interface (GUI) controls available to a user, control selection by the user, application programming interface (API) calls, files accessed, data communicated over a network, or activity using an input/output (I/O) device.

14 . The method of claim 11 , further comprising identifying a first data asset that is protected, by monitoring or identifying at least one of: a residing location of the first data asset, an owner of the first data asset, a type of the first data asset, or whether part or all of the first data asset comprises classified or sensitive data.

15 . The method of claim 11 , wherein the computing environment comprises at least one of a web browser, an application, background system service or an input/output (I/O) device.

16 . The method of claim 15 , wherein the application comprises a cloud-synchronization application, an electronic-mail application, a document processing or rendering application, a data transfer or copying application, or a facsimile or printing application.

17 . The method of claim 11 , wherein detecting the capabilities or the activities comprises detecting words or phrases in application interfaces indicative of means of data egress from the computing environment.

18 . The method of claim 17 , wherein determining the situation within the computing environment that represents potential or actual misuse of the one of the identified data assets, comprises relating the detected words or phrases in the application interfaces, to a user action via one or more corresponding application interfaces.

19 . The method of claim 11 , further comprising determining whether there is a situation within the computing environment that represents potential or actual exfiltration of one or more of the identified data assets, responsive to a triggering event.

20 . The method of claim 11 , wherein the action to prevent or control the potential or actual misuse of data comprises at least one of: warning or blocking a user against data movement of the one of the identified data assets, or blocking data movement of the one of the identified data assets by an application.

Assignments (11)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 29, 2019
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 050305/0418 →
CHANGE OF NAME Recorded May 21, 2019
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 049240/0514 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 23, 2018
From: DIGITAL GUARDIAN, INC.
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 046419/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2018
From: CARSON, DWAYNE A.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 045989/0511 →