IP Library Granted Patent US 12,292,970
Granted Patent B2
US 12,292,970 · App. 17/907,212 · Granted May 6, 2025

System and method for automated sensitive information discovery, monitoring and remediation

Inventors: David Croteau (St-Romauld, CA); Nicolas Berthiaume (Lac-Beauport, CA); Jordan Bourgault (Quebec, CA); Michael Fortin (St-Aubert, CA)
Assignee: Groupe Elucidia Inc.
G06F21/554G06F21/6245H04L63/00H04L63/10H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,292,970
App. No.
17/907,212
Granted
May 6, 2025
Kind
B2
Abstract

A system for automated sensitive information discovery, monitoring, and remediation using an agent associated to a data source and including: a module detecting the occurrence of events indicative of access to data; an module identifying the events classified as potentially threatening; a module extracting data associated to each potentially threatening event; and a module performing data analysis of the extracted data and determining a sensitivity score for the data to file associated to the potentially threatening event. The system also comprises a central platform in data communication with the agent and including: a module analyzing data received from the agent and identifying a potential security risk relative to one of a user or group of users associated to the data source, the data source, a specific file or a specific data type stored on the data source; and a control module triggering remediation actions upon detection of a security risk.

Claims (39)

1. A system for automated sensitive information discovery, monitoring, and remediation, the system comprising:

at least one agent stored in a memory of a computing device operating as a data source or in data communication with the data source, the at least one agent being a software unit and defining instructions which, when executed by a processor, can perform tasks in a background, the at least one agent comprising:

a data source monitoring module monitoring activity of the data source and detecting an occurrence of events indicative of access to data using the data source or stored on the data source;

an event filtering module filtering the events detected by the data source monitoring module and identifying events classified as potentially threatening events regarding sensitive information stored on the data source or accessed using the data source;

a data extraction module performing data extraction of one of data and a file associated to each one of the events classified as potentially threatening events and generating extracted data therefrom; and

a file analysis module performing data analysis of the extracted data associated to each one of the events classified as potentially threatening events and determining a sensitivity score indicative of a level of sensitivity thereof;

a central platform in data communication with the at least one agent, the central platform being a software unit stored in a memory of a central computing device and defining instructions which, when executed by a processor of the central computing device, can perform computer-implemented tasks, the central platform comprising:

a trend recognition module receiving the sensitivity score associated to each one of the events classified as potentially threatening events from the file analysis module and quantifying a sensitivity level of overall data held on or accessed by a specific user or group of users using the data source, the trend recognition module analyzing the sensitivity score associated to each one of the events classified as potentially threatening events in combination with additional contextual and historical data relative to one of the specific user or group of users associated to the data source, the data source, a specific file type stored on the data source and a specific data type stored on the data source, to identify a potential security risk relative to the data source or to the specific user or group of users associated to the data source when an overall potential security risk is greater than a predetermined threshold for the data source or the specific user or group of users associated to the data source, the predetermined threshold being adapted to the specific user or group of users associated to the data source and being representative of a quantity of sensitive information the specific user or group of users associated to the data source is allowed to access; and

a control module triggering remediation actions relative to the one of the specific user or group of users associated to the data source, the data source, the specific file type stored on the data source and the specific data type stored on the data source, upon detection of a potential security risk.

2. The system of claim 1 , wherein the file analysis module is configured to generate metadata regarding the extracted data, the metadata being communicated to the trend recognition module and being used by the trend recognition module to identify the potential security risk relative to the data source or to the specific user or group of users associated to the data source.

3. The system of claim 1 , wherein the contextual and historical data includes at least one of events frequencies, a global sensitivity score for the specific user or group of users associated to the data source, a data location, behavioral patterns associated to the one of the specific user or group of users associated to the data source, the data source, the specific file type stored on the data source and the specific data type stored on the data source, a type of changes performed on a file associated to one of the events classified as potentially threatening events, a number of files associated to the specific user or group of users associated to the data source and a data type associated to the to one of the events classified as potentially threatening events.

4. The system of claim 1 , wherein the file analysis module is configured to determine the sensitivity score indicative of the level of sensitivity of the extracted data from the one of the data and the file associated to each one of events classified as potentially threatening events using at least one of a comparison of Term Frequency Inverse Document Frequency (TF-IDF) vectors generated for the corresponding data or the files and at least one reference file and a correlation analysis between sensitive information identified with Regular Expressions (REGEXs) and user identifiers.

5. The system of claim 1 , wherein the control module of the central platform is configured to determine remediation actions based on predetermined scenarios defining the remediation actions to be taken for specific situations.

6. The system of claim 1 , wherein the central platform comprises a display module displaying data relative to the events classified as potentially threatening events and corresponding sensitivity score on a display screen of the computing device.

7. The system of claim 1 , wherein the remediation actions include at least one of network access restriction, modification of file access rights, file encryption, user session termination, alert generation and user education recommendations.

8. The system of claim 1 , wherein the system includes a configuration module configured to receive parameters regarding one of security protocols, policies and sensitivity parameters of the system, the configuration module generating configuration data defining the parameters of the system as configured therein, the configuration data being transmitted to the at least one agent, the event filtering module being configured to perform filtering of the events detected by the data source monitoring module using a set of filtering parameters initially defined using the configuration module.

9. The system of claim 1 , wherein the central platform is configured to generate a hash value for each version of each file stored on the data source and wherein the data source monitoring module is configured to use the generated hash value to perform detection of changes in a file stored on the data source for detecting the occurrence of events indicative of access to data using the data source or stored on the data source.

10. The system of claim 1 , wherein the data source is one of an endpoint computing device and a cloud storage.

11. The system of claim 1 , wherein the at least one agent comprises a remediation action module configured to implement corresponding remediation actions on the data source.

12. A computer implemented method for automated sensitive information discovery, monitoring and remediation, the method comprising the steps of:

monitoring activity of a corresponding data source;

detecting an occurrence of events indicative of access to data using the data source or stored on the data source;

identifying events indicative of a potentially threatening access to sensitive information by a user;

identifying the events classified as potentially threatening events regarding sensitive information stored on the data source or accessed using the data source;

performing data extraction of one of data and a file associated to each one of the events classified as potentially threatening events and generating extracted data therefrom;

performing data analysis of the extracted data associated to each one of events classified as potentially threatening events and determining a sensitivity score indicative of a level of sensitivity thereof;

communicating the events classified as potentially threatening events and the sensitivity score of the one of the data and the file associated to each one of the events classified as potentially threatening events to a central platform storing information over time and

generating therefrom additional contextual and historical data relative to one of a specific user or group of users associated to the data source, the data source, a specific file type stored on the data source and a specific data type stored on the data source;

quantifying a sensitivity level of overall data held on or accessed by the specific user or group of users using the data source;

analyzing the sensitivity score associated to each one of the events classified as potentially threatening events in combination with the additional contextual and historical data relative to the one of the specific user or group of users associated to the data source, the data source, the specific file type stored on the data source and the specific data type stored on the data source, to identify a potential security risk relative to the data source or to the specific user or group of users associated to the data source when an overall potential security risk is greater than a predetermined threshold for the data source or the specific user or group of users associated to the data source, the predetermined threshold being adapted to the specific user or group of users associated to the data source and being representative of a quantity of sensitive information the specific user or group of users associated to the data source is allowed to access; and

triggering remediation actions relative to the one of the specific user or group of users associated to the data source, the data source, the specific file type stored on the data source and the specific data type stored on the data source, upon detection of the potential security risk.

13. The method of claim 12 , further comprising the steps of generating metadata regarding the extracted data and communicating the metadata associated to each one of the events classified as potentially threatening events to the central platform.

14. The method of claim 12 , wherein the contextual and historical data includes at least one of events frequencies, a global sensitivity score for the specific user or group of users associated to the data source, a data location, behavioral patterns associated to the one of the specific user or group of users associated to the data source, the data source, the specific file type stored on the data source and the specific data type stored on the data source, a type of changes performed on a file associated to one of the events classified as potentially threatening events, a number of files associated to the specific user or group of users associated to the data source and a data type associated to the to one of the events classified as potentially threatening events.

15. The method of claim 12 , wherein the step of determining the sensitivity score indicative of the level of sensitivity of the one of the data and the file associated to each one of the events classified as potentially threatening events is performed using at least one of a comparison of Term Frequency Inverse Document Frequency (TF-IDF) vectors generated for the corresponding one of the data and the file and at least one reference file and a correlation analysis between sensitive information identified with Regular Expressions (REGEXs) and user identifiers.

16. The method of claim 12 , wherein the step of triggering remediation actions includes determining remediation actions based on predetermined scenarios defining the remediation actions to be taken for specific situations.

17. The method of claim 12 , wherein the remediation actions include at least one of network access restriction, modification of file access rights, file encryption, user session termination, alert generation and user education recommendations.

18. The method of claim 12 , further comprising generating a hash value for each version of each file stored on the data source and wherein the step of detecting the occurrence of events includes using the generated hash value to perform detection of changes in a file stored on the data source.

19. The method of claim 12 , further comprising implementing corresponding remediation actions on the data source.

20. A computer-readable memory having recorded thereon statements and instructions for execution by a computer, said statements and instructions comprising code means for performing the steps of the method of claim 12 .

Assignments (2)
SECURITY INTEREST Recorded Sep 9, 2025
From: GROUPE ELUCIDIA INC. / ELUCIDIA GROUP INC.
To: BDC CAPITAL INC.
Reel/Frame 072864/0157 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CROTEAU, DAVID; BERTHIAUME, NICOLAS; BOURGAULT, JORDAN; FORTIN, MICHAËL
To: GROUPE ELUCIDIA INC.
Reel/Frame 064420/0986 →
Continuity (2)
Provisional Application 63000238 · Mar 26, 2020
Related Publication 20230153427A1 · May 18, 2023
References Cited (32)
US 7933989B1 · Barker et al. · 2011 [cited by applicant]
US 8307427B1 · Wisilosky et al. · 2012 [cited by applicant]
US 8677448B1 · Kauffman et al. · 2014 [cited by applicant]
US 9235562B1 · Hart · 2016 [cited by applicant]
US 9275065B1 · Ganesh et al. · 2016 [cited by applicant]
US 9276862B1 · Presta · 2016 [cited by examiner]
US 9349016B1 · Brisebois et al. · 2016 [cited by applicant]
US 9691027B1 · Sawant et al. · 2017 [cited by applicant]
US 9807094B1 · Liu et al. · 2017 [cited by applicant]
US 10257217B2 · Hamdi · 2019 [cited by applicant]
US 10320830B2 · Ahuja et al. · 2019 [cited by applicant]
US 10354187B2 · Kasravi et al. · 2019 [cited by applicant]
US 10375116B2 · Cheng et al. · 2019 [cited by applicant]
US 20070067853A1 · Ramsey · 2007 [cited by applicant]
US 20110225650A1 · Margolies et al. · 2011 [cited by applicant]
US 20120303558A1 · Jaiswal · 2012 [cited by applicant]
US 20130333040A1 · Diehl · 2013 [cited by examiner]
US 20140279641A1 · Sinngh et al. · 2014 [cited by applicant]
US 20150074756A1 · Deng · 2015 [cited by examiner]
US 20150154420A1 · Wu et al. · 2015 [cited by applicant]
US 20150326601A1 · Grondin · 2015 [cited by examiner]
US 20160292445A1 · Lindemann · 2016 [cited by applicant]
US 20170083517A1 · Mitkar et al. · 2017 [cited by applicant]
US 20170149737A1 · Betzler · 2017 [cited by examiner]
US 20170287028A1 · Barday · 2017 [cited by applicant]
US 20180191759A1 · Baijal et al. · 2018 [cited by applicant]
US 20180204021A1 · Long · 2018 [cited by applicant]
US 20190138727A1 · Dontov · 2019 [cited by examiner]
US 20190180049A1 · LeCour · 2019 [cited by applicant]
US 20210194888A1 · Bhaskar S · 2021 [cited by examiner]
Alzhrani, Khudran, Rudd, Ethan M., Boult, Terrance E., et al. Automated big text security classification. In : 2016 IEEE Conference on Intelligence and Security Informatics (ISI). IEEE, 2016. p. 103-108. [cited by applicant]
Park, Youngja, Teiken, Wilfried, Rao, Josyula R., et al. Data classification and sensitivity estimation for critical asset discovery. IBM Journal of Research and Development, 2016, vol. 60, No. 4, p. 2: 1-2: 12. [cited by applicant]