RESOURCE SENSITIVITY LABELLING BASED ON SCANNING BY A WEB BROWSER
A web browser determines whether resources (e.g., files) of an enterprise are labelled in alignment with their contents. The web browser identifies a resource of the enterprise that comprises a sensitivity label, where the sensitivity label indicates sensitivity of the first resource. The web browser validates the sensitivity label of the first resource based on content of the first resource. If the sensitivity label does not align with the content of the first resource, the web browser enforces a policy for the first resource. The web browser then labels the first resource based on its sensitivity, which include scanning the first resource for sensitive features.
1 . A method comprising:
identifying, by a web browser, a first resource of an enterprise comprising a sensitivity label, wherein the sensitivity label indicates sensitivity of the first resource;
validating, by the web browser, the sensitivity label of the first resource based on content of the first resource;
based on determining that the sensitivity label of the first resource does not align with the content of the first resource, enforcing a policy for the first resource by the web browser; and
labeling the first resource based on sensitivity of the first resource, wherein labeling the first resource comprises, by the web browser,
scanning the first resource for sensitive features,
generating a signature of the first resource based on metadata of the first resource, wherein the metadata of the first resource comprises one or more of a timestamp, a location of each of one or more sensitive features in the first resource identified from scanning, and a class of data with which the first resource is associated; and
labelling the first resource with the signature.
2 . The method of claim 1 , wherein labelling the first resource with the signature comprises attaching the signature to the first resource or embedding the signature in the first resource.
3 . The method of claim 1 , wherein scanning the first resource for sensitive features comprises scanning one or more other resources accessible via hyperlinks within the first resource for sensitive features.
4 . (canceled)
5 . The method of claim 1 , wherein the signature is encrypted.
6 . (canceled)
7 . (canceled)
8 . (canceled)
9 . (canceled)
10 . The method of claim 1 , further comprising scanning the first resource for risky material, wherein labeling the first resource is based on determining that the first resource does not include risky material.
11 . The method of claim 10 , further comprising:
based on determining that the first resource includes risky material, attempting to remove the risky material from the first resource;
based on successfully removing the risky material from the first resource, proceeding with labeling the first resource; and
based on unsuccessful removal of the risky material from the first resource, disallowing use of the first resource.
12 . The method of claim 5 , further comprising decrypting the signature based on detecting interaction by a user with the first resource.
13 . The method of claim 1 , wherein enforcing the policy for the first resource is based on detecting interaction by a user with the first resource.
14 . The method of claim 1 , wherein enforcing the policy for the first resource comprises the web browser blocking at least one of upload, download, and opening of the first resource.
15 . One or more non-transitory computer-readable media having program code stored thereon, the program code comprising instructions to:
identify, by a web browser, a first resource of an enterprise comprising a sensitivity label, wherein the sensitivity label indicates sensitivity of the first resource;
validate, by the web browser, the sensitivity label of the first resource based on content of the first resource;
based on a determination that the sensitivity label of the first resource does not align with the content of the first resource, enforce a policy for the first resource by the web browser; and
label the first resource based on sensitivity of the first resource, wherein the instructions to label the first resource comprise instructions to, by the web browser, scan the first resource for sensitive features,
generate a signature of the first resource based on metadata of the first resource, wherein the metadata of the first resource comprises one or more of a timestamp, a location of each of one or more sensitive features in the first resource identified from scanning, and a class of data with which the first resource is associated; and
label the first resource with the signature.
16 . The non-transitory computer-readable media of claim 15 , wherein the instructions to label the first resource with the signature comprise instructions to attach the signature to the first resource or embed the signature in the first resource.
17 . The non-transitory computer-readable media of claim 15 , wherein the instructions to scan the first resource for sensitive features comprise instructions to scan one or more other resources accessible via hyperlinks within the first resource for sensitive features.
18 . The non-transitory computer-readable media of claim 15 , wherein the signature is encrypted, wherein the program code further comprises instructions to decrypt the signature based on detecting interaction by a user with the first resource.
19 . The non-transitory computer-readable media of claim 15 , wherein the program code further comprises instructions to scan the first resource for risky material, wherein the instructions to label the first resource comprise instructions to label the first resource based on a determination that the first resource does not include risky material.
20 . The non-transitory computer-readable media of claim 15 , wherein the instructions to enforce the policy for the first resource comprise instructions to enforce the policy for the first resource based on detection of interaction by a user with the first resource.
21 . The non-transitory computer-readable media of claim 15 , wherein the instructions to enforce the policy for the first resource comprise instructions to, by the web browser, block at least one of upload, download, and opening of the first resource.
22 . A user equipment comprising:
a processor; and
a machine-readable medium having instructions stored thereon that are executable by the processor to cause the user equipment to,
identify, by a web browser installed on the user equipment, a first resource of an enterprise comprising a sensitivity label, wherein the sensitivity label indicates sensitivity of the first resource;
validate, by the web browser, the sensitivity label of the first resource based on content of the first resource;
based on a determination that the sensitivity label of the first resource does not align with the content of the first resource, enforce a policy for the first resource by the web browser; and
label the first resource based on sensitivity of the first resource, wherein the instructions executable by the processor to cause the user equipment to label the first resource comprise instructions executable by the processor to cause the user equipment to, by the web browser,
scan the first resource for sensitive features,
generate a signature of the first resource based on metadata of the first resource, wherein the metadata of the first resource comprises one or more of a timestamp, a location of each of one or more sensitive features in the first resource identified from scanning, and a class of data with which the first resource is associated; and
label the first resource with the signature.
23 . The user equipment of claim 22 , wherein the instructions executable by the processor to cause the user equipment to enforce the policy for the first resource comprise instructions executable by the processor to cause the user equipment to enforce the policy for the first resource based on detection of interaction by a user with the first resource.
24 . The user equipment of claim 22 , wherein the instructions executable by the processor to cause the user equipment to enforce the policy for the first resource comprise instructions executable by the processor to cause the user equipment to, by the web browser, block at least one of upload, download, and opening of the first resource.
25 . The user equipment of claim 22 , wherein the instructions executable by the processor to cause the user equipment to scan the first resource for sensitive features comprise instructions executable by the processor to cause the user equipment to scan one or more other resources accessible via hyperlinks within the first resource for sensitive features.