Systems, methods, and computer-readable media for data security
Systems and methods are provided for data security. A server system provides data security using one or more processor devices, one or more communication interfaces, and one or more memory devices including computer-executable instructions. Those instructions cause the one or more processor devices to: monitor one or more requests or activities of a computing device; compare the monitored one or more requests or activities with a database of predetermined characteristics to determine whether the monitored one or more requests or activities indicates that the computing device downloaded or attempted to download more than a threshold number of data files or objects; and determine that the one or more requests or activities is suspicious when the comparing determines that the one or more requests or activities indicates that the computing device downloaded or attempted to download more than the threshold number of data files or objects, which causes a response to hinder the monitored one or more requests or activities.
1 . A method performed at a data computing system that includes one or more data processors, one or more communication devices, and one or more memories storing one or more programs, the method comprising the following steps:
detecting, by the data computing system, one or more commands or actions from a computing device in communication with the data computing system, where the one or more commands or actions correspond to one or more data objects;
applying one or more markers to the one or more data objects, where the one or more markers include metadata embedded within the one or more markers hidden from the computing device;
executing, by the data computing system, the one or more programs to analyze the one or more commands or actions and corresponding one or more markers, and generating an output;
determining, by the data computing system, the one or more commands or actions is atypical based on the output;
determining, by the data computing system, that the one or more commands or actions determined to be atypical is suspicious; and
initiating, by the data computing system, a response to prevent the commands or actions that are determined to be suspicious.
2 . The method of claim 1 , wherein one or more data objects include: documents, images, video, presentations, emails, posts, databases, logs of data, meta data, contact information, user credentials, financial data, location information, medical records, executable software, or software applications.
3 . The method of claim 1 , wherein the data computing system analyzes the one or more markers to improve tracking and security of marked data objects.
4 . The method of claim 1 , wherein the one or more markers include classification data and wherein the data computing system uses the classification data to determine a type of response actions and timing of when the response actions are implemented to prevent the commands or actions that are determined to be suspicious.
5 . The method of claim 1 , wherein the computing device is part of a server network, and wherein the data computing system uses the one or more markers to prevent the one or more data objects from leaving the server network.
6 . The method of claim 5 , wherein the data computing system detects that one of the data objects has been downloaded by the computing device and determines whether a signal is received from a marker corresponding to one data object within a predetermined time period, and if not, the data computing system determines that the download by the computing device is suspicious.
7 . The method of claim 5 , wherein the data computing system detects that one of the data objects has been downloaded by the computing device and determines whether a signal is received from a marker corresponding to one data object indicates that the computing device is within a trusted environment.
8 . The method of claim 7 , wherein the data computing system sends a signal to the marker to destroy the data object downloaded.
9 . The method of claim 1 , wherein the response includes deleting the one or more commands or actions from a first server and storing a copy of the one or more commands or actions in a secondary server.
10 . The method of claim 1 , further comprising:
determining, by the data computing system, a baseline of actions or commands and comparing of the one or more commands or actions to the baseline of commands or actions,
wherein the baseline of actions or commands is a baseline of actions or commands of a particular user or a baseline of actions or commands of general actions of the data computing system.
11 . The method of claim 1 , wherein the one or more commands or actions determined to be suspicious is based on one or more of the following conditions:
a query being executed which is recursive;
a command being initiated that has not been used before;
an action or command being executed at a time of day or a time of week that is not usual for that action or command;
an action or command relating to high value data files or data objects; and
an action or command that calls or initiates other actions or commands.
12 . The method of claim 1 , wherein the one or more commands or actions determined to be suspicious is based on one or more of the following conditions:
a frequency of a command or an action;
a sequence of inputted commands or actions taken;
whether the one or more commands or the one or more actions are atypical of a certain user profile;
whether the one or more commands or the one or more actions are atypical of a certain employee type; and
whether an atypical group of different users or IP addresses or both, exceeds an atypical grouping threshold, and the atypical group of different users or IP addresses or both is conducting similar or the same actions.
13 . A data computing system, comprising:
one or more data processors;
one or more communication interfaces connected to the one or more data processors; and
one or more memories devices including computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to:
detect one or more commands or actions from a computing device in communication with the data computing system, where the one or more commands or actions correspond to one or more data objects;
apply one or more markers to the one or more data objects, where the one or more markers include metadata embedded within the one or more markers hidden from the computing device;
analyze the one or more commands or actions and corresponding one or more markers, and generate an output;
determine the one or more commands or actions is atypical based on the output;
determine that the one or more commands or actions determined to be atypical is suspicious; and
initiate a response to prevent the commands or actions that are determined to be suspicious.
14 . The data computing system of claim 13 , wherein one or more data objects include: documents, images, video, presentations, emails, posts, databases, logs of data, meta data, contact information, user credentials, financial data, location information, medical records, executable software, or software applications.
15 . The data computing system of claim 13 , further comprising computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to analyze the one or more markers to improve tracking and security of marked data objects.
16 . The data computing system of claim 13 , wherein the one or more markers include classification data and further comprising computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to:
use the classification data to determine a type of response actions and timing of when the response actions are implemented to prevent commands or actions that are determined to be suspicious.
17 . The data computing system of claim 13 , further comprising computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to use the one or more markers to prevent the one or more data objects from leaving the data computing system.
18 . The data computing system of claim 17 , further comprising computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to detect that one of the data objects has been downloaded by the computing device and determines whether a signal is received from a marker corresponding to one data object within a predetermined time period, and if not, determine that the download by the computing device is suspicious.
19 . The data computing system of claim 17 , further comprising computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to detect that one of the data objects has been downloaded by the computing device and determines whether a signal is received from a marker corresponding to one data object indicates that the computing device is within a trusted environment.
20 . The data computing system of claim 19 , further comprising computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to send a signal to the marker to destroy the data object downloaded.
21 . The data computing system of claim 13 , wherein the response includes deleting the one or more commands or actions from a first server and storing a copy of the one or more commands or actions in a secondary server.
22 . The data computing system of claim 13 , further comprising computer-executable instructions, which when executed by the one or more data processors, cause the one or more data processors to determine a baseline of actions or commands and compare of the one or more commands or actions to the baseline of commands or actions,
wherein the baseline of actions or commands is a baseline of actions or commands of a particular user or a baseline of actions or commands of general actions of the data computing system.
23 . The data computing system of claim 13 , wherein the one or more commands or actions determined to be suspicious is based on one or more of the following conditions:
a query being executed which is recursive;
a command being initiated that has not been used before;
an action or command being executed at a time of day or a time of week that is not usual for that action or command;
an action or command relating to high value data files or data objects; and
an action or command that calls or initiates other actions or commands.
24 . The data computing system of claim 13 , wherein the one or more commands or actions determined to be suspicious is based on one or more of the following conditions:
a frequency of a command or an action;
a sequence of inputted commands or actions taken;
whether the one or more commands or the one or more actions are atypical of a certain user profile;
whether the one or more commands or the one or more actions are atypical of a certain employee type; and
whether an atypical group of different users or IP addresses or both, exceeds an atypical grouping threshold, and the atypical group of different users or IP addresses or both is conducting similar or the same actions.
25 . A non-transitory, computer-readable medium having instructions stored thereon which, when executed at a data computing system that includes one or more data processors, one or more communication devices, and one or more memories storing one or more programs, cause the data computing system to perform operations that include:
detecting, by the data computing system, one or more commands or actions from a computing device in communication with the data computing system, where the one or more commands or actions correspond to one or more data objects;
applying one or more markers to the one or more data objects, where the one or more markers include metadata embedded within the one or more markers hidden from the computing device;
executing, by the data computing system, the one or more programs to analyze the one or more commands or actions and corresponding one or more markers, and generating an output;
determining, by the data computing system, the one or more commands or actions is atypical based on the output;
determining, by the data computing system, that the one or more commands or actions determined to be atypical is suspicious; and
initiating, by the data computing system, a response to prevent the commands or actions that are determined to be suspicious.