IP Library Granted Patent US 12,632,591
Granted Patent B2
US 12,632,591 · App. 18/318,967 · Granted May 19, 2026

Sensitive data reclassification engine in a security management system

Inventors: Shimon Ezra (Petach Tikva, IL); Andrey Karpovsky (Kiryat Motzkin, IL)
Assignee: Microsoft Technology Licensing, LLC
G06F21/6245G06F16/285
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,591
App. No.
18/318,967
Granted
May 19, 2026
Kind
B2
Abstract

Methods, systems, and computer storage media for providing data security posture management using a sensitive data reclassification engine in a security management system. Data security posture management provides security operations—including identifying and remediating risk exposure—to securely manage data, resources, and workloads. In operation, sensitive data scan results are accessed. A scanned data item having a first data sensitivity confidence score—and a first data classification that indicates that the scanned data item is a potentially sensitive data item—is identified in the sensitive data scan results. Based on the scanned data item having the first data classification, scanned metadata comprising a sensitive data attribute is accessed. Based on a second data sensitivity confidence score associated with the sensitive data attribute and the scanned data item, the first data classification is replaced with a second data classification that indicates that the scanned data item is a sensitive data item.

Claims (58)

1 . A computerized system comprising:

one or more computer processors;

computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising:

accessing sensitive data scan results associated with a computing device in a computing environment;

based on the sensitive data scan results, identifying a scanned data item having a first data sensitivity confidence score and a first data classification that indicates that the scanned data item is a potentially sensitive data item, wherein the scanned data item is further evaluated using a scanned metadata record of the scanned data item when the first data classification indicates that the scanned data item is the potentially sensitive data item;

based on the scanned data item having the first data classification, accessing the scanned metadata record of the scanned data item;

determining that the scanned metadata record comprises a sensitive data attribute;

using the sensitive data attribute, generating a second data sensitivity confidence score for the scanned data item, wherein generating the second data sensitivity confidence score comprises applying a sensitive data confidence rescoring model that is trained on one or more metadata types to generate a subsequent probability of data sensitivity based on one or more sensitive data attributes associated with scanned metadata;

based on the second data sensitivity confidence score, replacing the first data classification with a second data classification that indicates that the scanned data item is a sensitive data item; and

communicating a security posture visualization to cause display of the security posture visualization comprising an identifier of the scanned data item associated with the second data classification.

2 . The system of claim 1 , wherein the sensitive data scan results are associated with a sensitive data scanning engine that supports scanning data items for sensitive information, the sensitive data scanning engine simultaneously scans data items for sensitive data and metadata associated with a plurality of metadata types, wherein the plurality of metadata types are associated with generating updated data sensitivity confidence scores for scanned data items having metadata that includes sensitive data attributes.

3 . The system of claim 1 , further comprising a first confidence threshold and a second confidence threshold, wherein scanned data items with confidence scores above the first confidence threshold are identified as sensitive data items, and scanned data items with data sensitivity confidence scores below the second confidence threshold are identified as non-sensitive data items.

4 . The system of claim 1 , further comprising a sensitive data reclassification engine including scanned metadata records that include sensitive data attributes of metadata that are mapped to scanned data items with the first data classification that indicates that the scanned data items are potentially sensitive data items.

5 . The system of claim 1 , further comprising:

a first plurality of scanned data items with data sensitivity confidence scores above a first confidence threshold, the first plurality of scanned data items are identified as sensitive data items;

a second plurality of scanned data items with data sensitivity confidence scores below a second confidence threshold, the second plurality of scanned data items are identified as non-sensitive data items; and

a third plurality of scanned items with data sensitivity confidence scores between the first confidence threshold and the second confidence threshold, the third plurality of scanned data items are identified as potentially sensitive data items, the third plurality of scanned data items comprising the scanned data item.

6 . The system of claim 1 , wherein the one or more metadata types includes explicit tags, actual names, access and data flow patterns; and similarity to other resources.

7 . The system of claim 1 , wherein the sensitive data confidence rescoring model is trained on the one or more metadata types to generate the subsequent probability of data sensitivity based on sensitive data attributes associated with the scanned metadata.

8 . The system of claim 1 , wherein the security posture visualization comprises an alert associated with the scanned data item, wherein the alert is associated with a prioritization identifier and a remediation action, wherein the prioritization identifier is based on the second data classification and the remediation action is executable to address a security threat associated with the alert.

9 . The system of claim 1 , the operations further comprising:

communicating a request for a security posture of the computing environment;

based on the request, receiving a security posture visualization associated with the computing environment, wherein the security posture visualization comprises the scanned data item; and

causing display of the security posture visualization comprising the identifier of the scanned data item associated with the second data classification.

10 . The system of claim 1 , the operations further comprising:

receiving an indication to execute a remediation action associated with the scanned data item, wherein the remediation action is associated with the security posture visualization; and

communicating the indication to execute the remediation action to cause execution of the remediation action.

11 . One or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations, the operations comprising:

communicating a request for a security posture of a computing environment;

based on the request, receiving a security posture visualization associated with the computing environment, wherein the security posture visualization comprises a scanned data item having a second data classification that replaced a first data classification that indicated that the scanned data item was a potentially sensitive data item, the second data classification indicates that the scanned data item is a sensitive data item,

the second data classification is generated based on a generating a second data sensitivity confidence score of the scanned data item,

wherein generating the second data sensitivity confidence score comprises applying a sensitive data confidence rescoring model that is trained on one or more metadata types to generate a subsequent probability of data sensitivity based on one or more sensitive data attributes associated with scanned metadata; and

causing display of the security posture visualization comprising the scanned data item associated with the second data classification.

12 . The media of claim 11 , wherein the security posture visualization comprises an alert associated with the scanned data item, wherein the alert is associated with a prioritization identifier and a remediation action, wherein the prioritization identifier is based on the second data classification and the remediation action is executable to address a security threat associated with the alert.

13 . The media of claim 11 , the operations further comprising:

accessing a scanned metadata record of the scanned data item having a first data sensitivity confidence score and the first data classification;

determining that the scanned metadata record comprises a sensitive data attribute;

using the sensitive data confidence rescoring model and the sensitive data attribute, generating the second data sensitivity confidence score for the scanned data item based on rescoring the scanned data item having the first data sensitivity confidence score; and

based on the second data sensitivity confidence score, replacing the first data classification with the second data classification.

14 . The media of claim 13 , wherein the sensitive data confidence rescoring model is trained on the one or more metadata types to generate the subsequent probability of data sensitivity based on sensitive data attributes associated with the scanned metadata.

15 . The media of claim 11 , the operations further comprising:

receiving an indication to execute a remediation action associated with the scanned data item, wherein the remediation action is associated with the security posture visualization; and

communicating the indication to execute the remediation action to cause execution of the remediation action.

16 . A computer-implemented method, the method comprising:

accessing scanned metadata of a scanned data item having a first data classification that indicates that the scanned data item is a potentially sensitive data item;

determining that the scanned metadata comprises a sensitive data attribute;

using a sensitive data confidence rescoring model and the sensitive data attribute, generating a second data sensitivity confidence score for the scanned data item based on rescoring the scanned data item having a first data sensitivity confidence score, wherein generating the second data sensitivity confidence score comprises applying the sensitive data confidence rescoring model that is trained on one or more metadata types to generate a subsequent probability of data sensitivity based on one or more sensitive data attributes associated with scanned metadata; and

based on the second data sensitivity confidence score, replacing the first data classification with a second data classification that indicates that the scanned data item is a sensitive data item.

17 . The method of claim 16 , further comprising:

a first plurality of scanned data items with data sensitivity confidence scores above a first confidence threshold, the first plurality of scanned data items are identified as sensitive data items;

a second plurality of scanned data items with data sensitivity confidence scores below a second confidence threshold, the second plurality of scanned data items are identified as non-sensitive data items; and

a third plurality of scanned items with data sensitivity confidence scores between the first confidence threshold and the second confidence threshold, the third plurality of scanned data items are identified as potentially sensitive data items, the third plurality of scanned data items comprising the scanned data item.

18 . The method of claim 16 , wherein the sensitive data confidence rescoring model is trained on the one or more metadata types to generate the subsequent probability of data sensitivity based on sensitive data attributes associated with the scanned metadata.

19 . The method of claim 16 , the method further comprising:

accessing the scanned data item associated with the second data classification that identifies classification;

based on the scanned data item and the second data classification, generating a security posture visualization; and

communicating the security posture visualization comprising the scanned data item.

20 . The method of claim 19 , wherein the second data sensitivity confidence score is above a first confidence score threshold, wherein data items with data sensitivity confidences scores above the first confidence score threshold are assigned the second data classification that indicates that the data items are sensitive data items.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2023
From: KARPOVSKY, ANDREY; EZRA, SHIMON
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 063720/0800 →
Continuity (1)
Related Publication 20240386132A1 · Nov 21, 2024
References Cited (16)
US 11704431B2 · Kraus · 2023 [cited by examiner]
US 12153693B2 · Williamson · 2024 [cited by examiner]
US 20150326601A1 · Grondin · 2015 [cited by applicant]
US 20180352005A1 · Gaddam · 2018 [cited by examiner]
US 20200125746A1 · Joshi · 2020 [cited by examiner]
US 20210004471A1 · Brannon · 2021 [cited by applicant]
US 20210026872A1 · Saillet · 2021 [cited by examiner]
US 20220207163A1 · Gentleman · 2022 [cited by examiner]
US 20230087093A1 · Ithal · 2023 [cited by applicant]
US 20230195755A1 · Raghavan · 2023 [cited by examiner]
US 20240005032A1 · Phokela · 2024 [cited by examiner]
US 20240143831A1 · Bryan · 2024 [cited by examiner]
US 20240323216A1 · Gershanov · 2024 [cited by examiner]
CN 117195297B · 2024 [cited by examiner]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/028098, Sep. 10, 2024, 17 pages. [cited by applicant]
International Preliminary Report on Patentability (Chapter I) received for PCT Application No. PCT/US2024/028098, Mailed on Nov. 27, 2025, 11 Pages. [cited by applicant]