IP Library Granted Patent US 11,874,853
Granted Patent B2
US 11,874,853 · App. 17/015,111 · Granted Jan 16, 2024

Data classification by on-the-fly inspection of data transactions

Inventors: Eldad Chai (Kfar Saba, IL); Yoav Cohen (Nes-Ziona, IL); Ben Herzberg (Modiin, IL)
Assignee: SATORI CYBER LTD.
G06F16/285G06F16/2379
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,874,853
App. No.
17/015,111
Granted
Jan 16, 2024
Kind
B2
Abstract

A data classification system includes a proxy and a processor. The proxy is configured to intercept transactions that are conducted over a network between clients and a data store. The processor is configured to construct, based on the intercepted transactions, a classification map including a classification of at least some of the data that is stored in the data store into predefined classes.

Claims (27)

1. A data classification system for classifying data of a data store based on inspecting data transactions between clients and the data store, comprising:

a proxy, configured to intercept transactions that are conducted over a network between clients and the data store, wherein the transactions include queries and responses, and wherein the queries or responses carry data; and

a processor, configured to construct, based on the intercepted transactions, a classification map comprising a classification of at least some of the data that is stored in the data store into predefined classes, wherein the classification map lists memory locations of data in the data store along with a corresponding classification of the sensitivity of the data,

wherein the processor comprises:

a knowledge store including the classification map; and

a classifier which classifies the data as to whether it is sensitive and updates the classification map based on the results of the classification, wherein the classifier is configured to check for intercepted transactions whether their data already appears in the classification map, and to refrain from classifying data of transactions for which the data is already in the classification map.

2. The system according to claim 1 , wherein the processor is configured to construct the classification map without directly accessing the data store.

3. The system according to claim 1 , wherein the processor is configured to output a report that reports the classification map.

4. The system according to claim 1 , wherein the processor is configured to formulate a policy on subsequent transactions based on the classification map.

5. The system according to claim 1 , wherein the proxy is configured to suspend a given transaction until the processor has completed classifying the data pertaining to the given transaction.

6. A data classification method for classifying data of a data store based on inspecting data transactions between clients and the data store, comprising:

intercepting transactions that are conducted over a network between clients and the data store, wherein the transactions include queries and responses, and wherein the queries or responses carry data;

constructing, based on the intercepted transactions, a classification map comprising a classification of at least some of the data that is stored in the data store into predefined classes, wherein the classification map lists memory locations of data in the data store along with a corresponding classification of the sensitivity of the data,

wherein constructing the classification map comprises:

checking for intercepted transactions whether their data already appears in the classification map,

classifying the data that does not already appear in the classification map as to whether it is sensitive, while refraining from classifying data of transactions for which the data is already in the classification map.

7. The method according to claim 6 , wherein constructing the classification map is performed without directly accessing the data store.

8. The method according to claim 6 , further comprising outputting a report that reports the classification map.

9. The method according to claim 6 , further comprising enforcing a policy on subsequent transactions based on the classification map.

10. The method according to claim 6 , further comprising suspending a given transaction until classification of the data pertaining to the given transaction is completed.

11. The method according to claim 6 , wherein the intercepted transactions are allowed to proceed regardless of their classification.

12. The system according to claim 1 , wherein the proxy is configured to allow intercepted transactions to proceed regardless of their classification.

13. The system according to claim 1 , wherein the processor further includes an analyzer which parses the intercepted transactions and models the parsed intercepted transactions to recognize which data is accessed by the intercepted transactions and determine a type of filtering that the intercepted transactions perform.

14. The system according to claim 1 , wherein the classifier performs string analysis on the queries to identify strings indicative of sensitive data.

15. The system according to claim 1 , wherein the classifier performs string analysis on the data to identify strings indicative of sensitive data.

16. The system according to claim 1 , wherein the classifier performs string analysis on the labels of the data to identify strings indicative of sensitive data.

17. The system according to claim 1 , wherein the classifier applies a statistical machine learning model to the queries and responses.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2025
From: SATORI CYBER LTD.
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 072275/0917 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: SILICON VALLEY BANK
To: SATORI CYBER LTD.
Reel/Frame 069589/0527 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 17, 2020
From: SATORI CYBER LTD
To: SILICON VALLEY BANK
Reel/Frame 054794/0588 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: CHAI, ELDAD; COHEN, YOAV; HERZBERG, BEN
To: SATORI CYBER LTD.
Reel/Frame 053729/0707 →
Continuity (1)
Related Publication 20220075801A1 · Mar 10, 2022