IP Library › Granted Patent US 12,381,786
Granted Patent B2
US 12,381,786 · App. 17/671,438 · Granted Aug 5, 2025

System and method for monitoring data disclosures

Inventors: Taimur Aslam (Frederick, MD); Andrew J. Surwilo (Allendale, NJ)
Assignee: CYTEX, INC.
H04L41/145G06N7/01G06Q10/0635H04L43/028H04L61/4511H04L63/1416H04L63/20H04L41/147
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,786
App. No.
17/671,438
Granted
Aug 5, 2025
Kind
B2
Abstract

A method for data breach protection includes identifying data partners of an enterprise and determining data usage policies of the data partners. The data usage policies of the data partners may be monitored and a change in at least one data usage policy of at least one data partner may be detected. A similarity between an original version of the at least one data usage policy and the changed version of the at least one data usage policy may be determined. Results of the determined similarity may be displayed.

Claims (65)

1. A method, comprising:

identifying data assets of an enterprise;

scanning the data assets;

based upon scanned data assets of the enterprise to be monitored, identifying data partners of the enterprise to be analyzed;

determining data usage policies of the data partners;

monitoring the data usage policies of the data partners;

detecting a change in at least one data usage policy of at least one data partner;

determining a similarity between an original version of the at least one data usage policy and a changed version of the at least one data usage policy;

displaying results of the determined similarity.

2. The method of claim 1 , wherein determining data usage policies of the data partners comprises retrieving the data usage policies of the data partners using a data transfer method built upon HTTP, HTTPS, or Web Services.

3. The method of claim 1 , wherein detecting a change in at least one data usage policy of at least one data partner comprises automatically retrieving the at least one data usage policy of the at least one data partner using a data transfer method built upon HTTP, HTTPS, or Web Services.

4. The method of claim 1 , further comprising:

developing a domain specific taxonomy for a generic data usage policy based at least in part upon a plurality of publicly available data usage policies of a diverse group of organizations;

parsing data content of the changed version of the at least one data usage policy;

building a semantic relationship between the changed version of the at least one data usage policy of the at least one data partner and the generic data usage policy using a modified Latent Dirichlet Allocation.

5. The method of claim 4 , wherein the data usage policies of the data partners comprise a respective terms of use associated with each data partner.

6. The method of claim 4 , wherein the data usage policies of the data partners comprise a respective privacy policy associated with each data partner.

7. The method of claim 1 , wherein determining a similarity between the original version of the at least one data usage policy and the changed version of the at least one data usage policy comprises comparing the original version to the changed version using Euclidean, Jaccard or Cosine similarity metrics.

8. The method of claim 7 , wherein displaying the results of the determined similarity comprises displaying results of the determined similarity with reference links to the original version and the changed version of the at least one data usage policy.

9. The method of claim 1 , further comprising:

computing a pairwise similarity index between the changed version of the at least one data usage policy and a pre-selected set of publicly available data usage policies; and

displaying results of the computed pairwise similarity index.

10. The method of claim 1 , wherein identifying data partners of an enterprise comprises:

assign sensitivity labels to each of the data assets to be monitored.

11. A computer configured to access a storage device, the computer comprising:

a processor, and

a non-transitory, computer-readable storage medium storing computer-readable instructions that when executed by the processor cause the computer to perform:

identifying data assets of an enterprise;

scanning the data assets;

based upon scanned data assets of the enterprise to be monitored, identifying data partners of the enterprise to be analyzed;

determining data usage policies of the data partners;

monitoring the data usage policies of the data partners;

detecting a change in at least one data usage policy of at least one data partner;

determining a similarity between an original version of the at least one data usage policy and a changed version of the at least one data usage policy;

displaying results of the determined similarity.

12. The computer of claim 11 , wherein the instructions, when executed by the processor, further cause the computer to perform:

developing a domain specific taxonomy for a generic data usage policy based at least in part upon a plurality of publicly available data usage policies of a diverse group of organizations;

parsing data content of the changed version of the at least one data usage policy;

building a semantic relationship between the changed version of the at least one data usage policy of the at least one data partner and the generic data usage policy using a modified Latent Dirichlet Allocation.

13. The computer of claim 11 , wherein determining a similarity between the original version of the at least one data usage policy and the changed version of the at least one data usage policy comprises comparing the original version to the changed version using Euclidean, Jaccard or Cosine similarity metrics.

14. The computer of claim 11 , wherein the instructions, when executed by the processor, further cause the computer to perform:

computing a pairwise similarity index between the changed version of the at least one data usage policy and a pre-selected set of publicly available data usage policies; and

displaying results of the computed pairwise similarity index.

15. The computer of claim 11 , wherein identifying data partners of an enterprise comprises:

assigning sensitivity labels to each of the data assets to be monitored.

16. A computer program product, comprising:

a non-transitory computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code comprising:

computer-readable program code configured to identify data assets of an enterprise;

computer-readable program code configured to scan the data assets;

computer-readable program code configured to, based upon scanned data assets of the enterprise to be monitored, identifying data partners of the enterprise to be analyzed;

computer-readable program code configured to determine data usage policies of the data partners;

computer-readable program code configured to monitor the data usage policies of the data partners;

computer-readable program code configured to detect a change in at least one data usage policy of at least one data partner;

computer-readable program code configured to determine a similarity between an original version of the at least one data usage policy and a changed version of the at least one data usage policy;

computer-readable program code configured to display results of the determined similarity.

17. The computer program product of claim 16 , the computer-readable program code further comprising:

computer-readable program code configured to develop a domain specific taxonomy for a generic data usage policy based at least in part upon a plurality of publicly available data usage policies of a diverse group of organizations;

computer-readable program code configured to parse data content of the changed version of the at least one data usage policy;

computer-readable program code configured to build a semantic relationship between the changed version of the at least one data usage policy of the at least one data partner and the generic data usage policy using a modified Latent Dirichlet Allocation.

18. The computer program product of claim 16 , wherein determining a similarity between the original version of the at least one data usage policy and the changed version of the at least one data usage policy comprises comparing the original version to the changed version using Euclidean, Jaccard or Cosine similarity metrics.

19. The computer program product of claim 16 , the computer-readable program code further comprising:

computer-readable program code configured to compute a pairwise similarity index between the changed version of the at least one data usage policy and a pre-selected set of publicly available data usage policies; and

computer-readable program code configured to display results of the computed pairwise similarity index.

20. The computer program product of claim 16 , wherein identifying data partners of an enterprise comprises

assigning sensitivity labels to each of the data assets to be monitored.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2025
From: BROADSTONE TECHNOLOGIES, LLC
To: CYTEX, INC.
Reel/Frame 071603/0542 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2023
From: ASLAM, TAIMUR; SURWILO, ANDREW
To: BROADSTONE TECHNOLOGIES, LLC
Reel/Frame 062736/0235 →
Continuity (5)
Provisional Application 63200108 · Feb 14, 2021
Provisional Application 63200104 · Feb 14, 2021
Provisional Application 63200103 · Feb 14, 2021
Provisional Application 63200105 · Feb 14, 2021
Related Publication 20220394061A1 · Dec 8, 2022
References Cited (18)
US 11087014B2 · Levy · 2021 [cited by examiner]
US 11416700B1 · Bhatt · 2022 [cited by examiner]
US 11461785B2 · Redlich · 2022 [cited by examiner]
US 20100010968A1 · Redlich · 2010 [cited by examiner]
US 20100222037A1 · Dragt · 2010 [cited by examiner]
US 20130139215A1 · Hu · 2013 [cited by examiner]
US 20160164915A1 · Cook · 2016 [cited by examiner]
US 20180300351A1 · Glover · 2018 [cited by examiner]
US 20190319961A1 · Levy · 2019 [cited by examiner]
US 20190319971A1 · Levy · 2019 [cited by examiner]
US 20190319980A1 · Levy · 2019 [cited by examiner]
US 20190384812A1 · Turek · 2019 [cited by examiner]
US 20200394455A1 · Lee · 2020 [cited by examiner]
US 20210192651A1 · Groth · 2021 [cited by examiner]
US 20210326467A1 · Levy · 2021 [cited by examiner]
US 20210342454A1 · Brannon · 2021 [cited by examiner]
US 20210342467A1 · Levy · 2021 [cited by examiner]
Y. Park, W. Teiken, J. R. Rao and S. N. Chari, “Data classification and sensitivity estimation for critical asset discovery,” in IBM Journal of Research and Development, vol. 60, No. 4, pp. 2:1-2:12, Jul.-Aug. 2016, doi… [cited by examiner]