IP Library Granted Patent US 11,748,511
Granted Patent B2
US 11,748,511 · App. 17/218,940 · Granted Sep 5, 2023

Protecting data based on context of data movement operation

Inventors: Paul Normand James Berube (Edmonton, CA); Victor Salamon (Edmonton, CA)
Assignee: EMC IP Holding Company LLC
G06F21/6245G06F21/44G06F21/54G06F21/6218G06F21/78G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,748,511
App. No.
17/218,940
Granted
Sep 5, 2023
Kind
B2
Abstract

Methods, apparatus, and processor-readable storage media for protecting data based on a context of data movement operations are provided herein. An example computer-implemented method includes identifying a context of a data movement operation based at least in part on a source and an indicated destination of data associated with the data movement operation; applying one or more data protection policies to the data movement operation based at least in part on the identified context, wherein a given data protection policy comprises one or more indications of one or more content scanners that are configured to detect data belonging to one or more regulated data classes; and in response to detecting data associated with the data movement operation that belongs to at least one of the regulated data classes, performing one or more automated remedial actions associated with the at least one regulated data class.

Claims (57)

1. A computer-implemented method comprising:

identifying a context of a data movement operation based at least in part on a source and an indicated destination of data associated with the data movement operation;

applying one or more data protection policies to the data movement operation based at least in part on the identified context, wherein a given data protection policy comprises one or more indications of one or more content scanners that are configured to detect data belonging to one or more regulated data classes;

selecting and executing at least a portion of the one or more content scanners based at least in part on a scrutiny level computed for the data movement operation; and

in response to detecting data associated with the data movement operation that belongs to at least one of the regulated data classes, performing one or more automated remedial actions associated with the at least one regulated data class;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The computer-implemented method of claim 1 , wherein identifying the context comprises determining one or more of the following attributes for at least one of the source and the indicated destination:

a physical location;

a virtual location;

a system name; and

a vendor.

3. The computer-implemented method of claim 1 , wherein identifying the context is further based on one or more characteristics of a process triggering the data movement operation.

4. The computer-implemented method of claim 3 , wherein the one or more characteristics comprise at least one of a user identifier and one or more group identifiers.

5. The computer-implemented method of claim 3 , wherein the scrutiny level is computed based on the one or more characteristics of said process.

6. The computer-implemented method of claim 1 , wherein:

the one or more content scanners are further configured to generate metadata in response to detecting that the data associated with the data movement operation belongs to at least one of the regulated data classes, and

the one or more automated remedial actions are performed based at least in part on the metadata.

7. The computer-implemented method of claim 6 , wherein the metadata comprises a location of the detected data.

8. The computer-implemented method of claim 1 , wherein the one or more automated remedial actions comprise one or more of:

redirecting at least a portion of the detected data to a different destination;

redacting at least a portion of the detected data;

preventing the data movement operation;

blocking one or more additional data movement operations one or more of from the source and to the indicated destination; and

generating one or more alerts.

9. The computer-implemented method of claim 1 , wherein the context of the data movement operation comprises a set of attributes corresponding to at least the source, the indicated destination, and a process triggering the data movement operation, and wherein the one or more automated remedial actions comprise:

providing feedback information to change a context of one or more subsequent data movement operations having at least one shared attribute with the set of attributes corresponding to the data movement operation.

10. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:

to identify a context of a data movement operation based at least in part on a source and an indicated destination of data associated with the data movement operation;

to apply one or more data protection policies to the data movement operation based at least in part on the identified context, wherein a given data protection policy comprises one or more indications of one or more content scanners that are configured to detect data belonging to one or more regulated data classes;

to select and execute at least a portion of the one or more content scanners based at least in part on a scrutiny level computed for the data movement operation; and

in response to detection of data associated with the data movement operation that belongs to at least one of the regulated data classes, to perform one or more automated remedial actions associated with the at least one regulated data class.

11. The non-transitory processor-readable storage medium of claim 10 , wherein identifying the context is further based on one or more characteristics of a process triggering the data movement operation.

12. The non-transitory processor-readable storage medium of claim 11 , wherein the scrutiny level is computed based on the one or more characteristics of said process.

13. The non-transitory processor-readable storage medium of claim 10 , wherein:

the one or more content scanners are further configured to generate metadata in response to detecting that the data associated with the data movement operation belongs to at least one of the regulated data classes, and

the one or more automated remedial actions are performed based at least in part on the metadata.

14. The non-transitory processor-readable storage medium of claim 13 , wherein the metadata comprises a location of the detected data.

15. The non-transitory processor-readable storage medium of claim 10 , wherein the one or more automated remedial actions comprise one or more of:

redirecting at least a portion of the detected data to a different destination;

redacting at least a portion of the detected data;

preventing the data movement operation;

blocking one or more additional data movement operations one or more of from the source and to the indicated destination; and

generating one or more alerts.

16. The non-transitory processor-readable storage medium of claim 10 , wherein the context of the data movement operation comprises a set of attributes corresponding to at least the source, the indicated destination, and a process triggering the data movement operation, and wherein the one or more automated remedial actions comprise:

providing feedback information to change a context of one or more subsequent data movement operations having at least one shared attribute with the set of attributes corresponding to the data movement operation.

17. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to identify a context of a data movement operation based at least in part on a source and an indicated destination of data associated with the data movement operation;

apply one or more data protection policies to the data movement operation based at least in part on the identified context, wherein a given data protection policy comprises one or more indications of one or more content scanners that are configured to detect data belonging to one or more regulated data classes;

to select and execute at least a portion of the one or more content scanners based at least in part on a scrutiny level computed for the data movement operation; and

in response to detection of data associated with the data movement operation belonging to at least one of the regulated data classes, to perform one or more automated remedial actions associated with the at least one regulated data class.

18. The apparatus of claim 17 , wherein identifying the context is further based on one or more characteristics of a process triggering the data movement operation.

19. The apparatus of claim 18 , wherein the scrutiny level is computed based on the one or more characteristics of said process.

20. The apparatus of claim 18 , wherein:

the one or more content scanners are further configured to generate metadata in response to detecting that the data associated with the data movement operation belongs to at least one of the regulated data classes, and

the one or more automated remedial actions are performed based at least in part on the metadata.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2021
From: BERUBE, PAUL NORMAND JAMES; SALAMON, VICTOR
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 055785/0054 →