IP Library Granted Patent US 10,496,842
Granted Patent B1
US 10,496,842 · App. 16/035,764 · Granted Dec 3, 2019

Multi-pronged file anomaly detection based on violation counts

Inventor: Liwei Ren (San Jose, CA)
Assignee: DiDi Research America, LLC
G06F21/6218G06F16/122G06F16/285G06F21/604H04L63/102H04L63/20G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,496,842
App. No.
16/035,764
Granted
Dec 3, 2019
Kind
B1
Abstract

File classification information for a set of files are obtained. The file classification information defines (1) a number of classified files within the set of files, (2) a number of classification categories associated with the classified files, (3) a number of unauthorized classified files that do not match an access privilege of a user, and (4) a number of unauthorized classification categories associated with the unauthorized classified files. A violation of an access control policy is determined based on the file classification information.

Claims (40)

1. A system for protecting sensitive data, the system comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, cause the system to perform:

obtaining file classification information for a set of files, the file classification information defining (1) a number of classified files within the set of files, (2) a number of classification categories associated with the classified files, (3) a number of unauthorized classified files that do not match an access privilege of a user, and (4) a number of unauthorized classification categories associated with the unauthorized classified files; and

determining a violation of an access control policy based on the file classification information.

2. The system of claim 1 , wherein determining the violation of the access control policy based on the file classification information includes:

determining a risk parameter based on (1) the number of classified files within the set of files, (2) the number of classification categories associated with the classified files, (3) the number of unauthorized classified files that do not match the access privilege of the user, and (4) the number of unauthorized classification categories associated with the unauthorized classified files; and

determining the violation of the access control policy based on the risk parameter exceeding a risk parameter threshold.

3. The system of claim 1 , wherein determining the violation of the access control policy based on the file classification information includes:

determining the violation of the access control policy based on the number of unauthorized classified files that do not match the access privilege of the user exceeding an unauthorized classified files threshold.

4. The system of claim 1 , wherein determining the violation of the access control policy based on the file classification information includes:

determining the violation of the access control policy based on the number of unauthorized classification categories associated with the unauthorized classified files exceeding an unauthorized classification categories threshold.

5. The system of claim 1 , wherein the set of files is stored in an electronic storage of a computing device, and at least a portion of the file classification information for the set of files is determined by a discovery agent running on the computing device.

6. The system of claim 5 , wherein the discovery agent determines at least the portion of the file classification information based on (1) a determination of the classification categories associated with the classified files, and (2) the access privilege of the user.

7. The system of claim 1 , wherein a prevention analysis of the classified files is performed based on the determination of the violation of the access control policy.

8. The system of claim 7 , wherein a post-leak analysis of the classified files is performed based on the determination of the violation of the access control policy.

9. A method for protecting sensitive data, the method comprising:

obtaining file classification information for a set of files, the file classification information defining (1) a number of classified files within the set of files, (2) a number of classification categories associated with the classified files, (3) a number of unauthorized classified files that do not match an access privilege of a user, and (4) a number of unauthorized classification categories associated with the unauthorized classified files; and

determining a violation of an access control policy based on the file classification information.

10. The method of claim 9 , wherein determining the violation of the access control policy based on the file classification information includes:

determining a risk parameter based on (1) the number of classified files within the set of files, (2) the number of classification categories associated with the classified files, (3) the number of unauthorized classified files that do not match the access privilege of the user, and (4) the number of unauthorized classification categories associated with the unauthorized classified files; and

determining the violation of the access control policy based on the risk parameter exceeding a risk parameter threshold.

11. The method of claim 9 , wherein determining the violation of the access control policy based on the file classification information includes:

determining the violation of the access control policy based on the number of unauthorized classified files that do not match the access privilege of the user exceeding an unauthorized classified files threshold.

12. The method of claim 9 , wherein determining the violation of the access control policy based on the file classification information includes:

determining the violation of the access control policy based on the number of unauthorized classification categories associated with the unauthorized classified files exceeding an unauthorized classification categories threshold.

13. The method of claim 9 , wherein the set of files is stored in an electronic storage of a computing device, and at least a portion of the file classification information for the set of files is determined by a discovery agent running on the computing device.

14. The method of claim 13 , wherein the discovery agent determines at least the portion of the file classification information based on (1) a determination of the classification categories associated with the classified files, and (2) the access privilege of the user.

15. The method of claim 9 , wherein a prevention analysis of the classified files is performed based on the determination of the violation of the access control policy.

16. The method of claim 15 , wherein a post-leak analysis of the classified files is performed based on the determination of the violation of the access control policy.

17. A non-transitory computer-readable medium for protecting sensitive data, the non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform:

obtaining file classification information for a set of files, the file classification information defining (1) a number of classified files within the set of files, (2) a number of classification categories associated with the classified files, (3) a number of unauthorized classified files that do not match an access privilege of a user, and (4) a number of unauthorized classification categories associated with the unauthorized classified files; and

determining a violation of an access control policy based on the file classification information.

18. The non-transitory computer-readable medium of claim 17 , wherein determining the violation of the access control policy based on the file classification information includes:

determining a risk parameter based on (1) the number of classified files within the set of files, (2) the number of classification categories associated with the classified files, (3) the number of unauthorized classified files that do not match the access privilege of the user, and (4) the number of unauthorized classification categories associated with the unauthorized classified files; and

determining the violation of the access control policy based on the risk parameter exceeding a risk parameter threshold.

19. The non-transitory computer-readable medium of claim 17 , wherein determining the violation of the access control policy based on the file classification information includes:

determining the violation of the access control policy based on the number of unauthorized classified files that do not match the access privilege of the user exceeding an unauthorized classified files threshold.

20. The non-transitory computer-readable medium of claim 17 , wherein determining the violation of the access control policy based on the file classification information includes:

determining the violation of the access control policy based on the number of unauthorized classification categories associated with the unauthorized classified files exceeding an unauthorized classification categories threshold.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2020
From: DIDI (HK) SCIENCE AND TECHNOLOGY LIMITED
To: BEIJING DIDI INFINITY TECHNOLOGY AND DEVELOPMENT CO., LTD.
Reel/Frame 053180/0456 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2020
From: DIDI RESEARCH AMERICA, LLC
To: DIDI (HK) SCIENCE AND TECHNOLOGY LIMITED
Reel/Frame 053081/0934 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2018
From: REN, LIWEI
To: DIDI RESEARCH AMERICA, LLC
Reel/Frame 046355/0609 →
Cited By (2)
US 12,619,733 US 12,719,876