IP Library Granted Patent US 10,482,280
Granted Patent B2
US 10,482,280 · App. 15/419,756 · Granted Nov 19, 2019

Structured text and pattern matching for data loss prevention in object-specific image domain

Inventors: Ramzi Abi Antoun (San Francisco, CA); Jinyu Zuo (San Francisco, CA)
Assignee: Symantec Corporation
G06F21/6245G06F21/34G06K9/00228G06K9/00456G06K9/4604G06T7/11G06K2209/01G06T2207/10004
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,482,280
App. No.
15/419,756
Filed
Jan 30, 2017
Granted
Nov 19, 2019
Kind
B2
Art Unit
2431
USPC
726/27
Abstract

Structured text and pattern matching may be performed for data loss prevention in object-specific image domain. According to some embodiments, a method may include receiving an image, identifying one or more objects in the image based on attributes of the one or more objects, and determining an object type of a first object of the one or more objects by a computing device. The method may include identifying, by the computing device, one or more specific regions of the first object for recognition based on the object type of the first object and recognizing text in the one or more specific regions of the first object. In some embodiments, the method may then include providing, by the computing device, the text recognized in the one or more specific regions of the first object to a security engine, wherein the security engine may be configured to evaluate whether the text comprises sensitive information.

Claims (49)

1. A computer-implemented method comprising:

receiving, by a computing device, an image;

identifying, by the computing device, multiple physical objects represented in the image based on attributes of the multiple physical objects;

determining, by the computing device, an object type of a first object of the multiple physical objects;

determining, by the computing device, an object type of a second object of the multiple physical objects;

identifying, by the computing device, one or more specific regions of the first object for recognition based on the object type of the first object;

identifying, by the computing device, one or more specific regions of the second object for recognition based on the object type of the second object;

responsive to identifying the one or more specific regions, recognizing, by the computing device, text in the one or more specific regions of the first object;

recognizing, by the computing device, text in the one or more specific regions of the second object;

providing, by the computing device, the text recognized in the one or more specific regions of the first object to a security engine, the security engine configured to evaluate whether the text comprises sensitive information; and

providing, by the computing device, the text in the one or more specific regions of the second object to the security engine.

2. The computer-implemented method of claim 1 , further comprising:

in response to the security engine determining that the text in the one or more specific regions of the first object does not comprise sensitive information, classifying, by the computing device, the first object as not including sensitive information.

3. The computer-implemented method of claim 1 , further comprising:

determining, by the computing device, whether text is present in the one or more specific regions of the first object; and

in response to determining that no text is present in the one or more specific regions, classifying the object as not including sensitive information.

4. The computer-implemented method of claim 1 , wherein a location of each specific region of the one or more specific regions is determined based on a known layout of the object type.

5. The computer-implemented method of claim 1 , wherein the security engine is further configured to determine whether the text comprises sensitive information based on the metadata tagged on the text.

6. The computer-implemented method of claim 1 , further comprising:

determining that the image contains sensitive information based on the object type of the first object and the object type of the second object.

7. The computer-implemented method of claim 6 , wherein it is determined that the image contains sensitive information responsive to the object type of the first object being a first particular type and the object type of the second object being a second, different particular object type.

8. The computer-implemented method of claim 1 , wherein the security engine evaluates whether the text comprises sensitive information by matching the text in the one or more specific regions of the first object against a database of defined sensitive information.

9. The computer-implemented method of claim 1 , further comprising:

automatically blocking the image from being electronically transferred in response to the text recognized in the one or more specific regions of the first object being evaluated as including sensitive information.

10. The computer-implemented method of claim 1 , further comprising:

automatically transmitting an electronic message to an administrator in response to the text recognized in the one or more specific regions of the first object being evaluated as including sensitive information.

11. The computer-implemented method of claim 1 comprising:

adjusting a rotation or a perspective of the one or more specific regions using a determined rotation or perspective of the first object in order to facilitate text recognition within the one or more specific regions of the first object.

12. The computer-implemented method of claim 1 , wherein the attributes comprise dimensions of the first object.

13. The computer-implemented method of claim 1 , wherein the object type of the first object comprises a check.

14. The computer-implemented method of claim 13 , wherein the check is identified based on attributes comprising MICR (Magnetic Ink Character Recognition) characters.

15. The computer-implemented method of claim 1 , wherein the object type of the first object comprises a photo identification card.

16. The computer-implemented method of claim 15 , wherein the photo identification card is identified based on attributes comprising an image of a face at a given location.

17. A non-transitory computer readable medium storing instructions that, when executed by a computing device having one or more processors, causes the one or more processors to perform operations comprising:

receiving, by a computing device, an image;

identifying, by the computing device, multiple physical objects represented in the image based on attributes of the multiple physical objects;

determining, by the computing device, an object type of a first object of the multiple physical objects;

determining, by the computing device, an object type of a second object of the multiple physical objects;

identifying, by the computing device, one or more specific regions of the first object for recognition based on the object type of the first object;

identifying, by the computing device, one or more specific regions of the second object for recognition based on the object type of the second object;

responsive to identifying the one or more specific regions, recognizing, by the computing device, text in the one or more specific regions of the first object;

recognizing, by the computing device, text in the one or more specific regions of the second object;

providing, by the computing device, the text recognized in the one or more specific regions of the first object to a security engine, the security engine configured to evaluate whether the text comprises sensitive information; and

providing, by the computing device, the text in the one or more specific regions of the second object to the security engine.

18. A computer system comprising:

a receiving module programmed to receive an image, at least one processor configured to execute the receiving module;

an object identification module programmed to identify multiple physical objects represented in the image based on attributes of the multiple physical objects, the at least one processor configured to execute the object identification module, the object identification module communicatively coupled to the receiving module;

an object analysis module programmed to determine an object type of a first object of the multiple physical objects, determine an object type of a second object of the multiple physical objects, identify one or more specific regions of the first object for recognition based on the object type of the first object, and identify one or more specific regions of the second object for recognition based on the object type of the second object, the at least one processor configured to execute the object analysis module, the object analysis module communicatively coupled to the object identification module; and

a text recognition module programmed to, responsive to identifying the one or more specific regions, recognize text in the one or more specific regions of the first object, recognize text in the one or more specific regions of the second object, tag the text recognized in each specific region of the one or more specific regions of the first object with metadata based on a location of the specific region on the first object, provide the text recognized in the one or more specific regions of the first object to a security engine, and provide the text in the one or more specific regions of the second object to the security engine, the metadata indicating a data type expected to be found at the location of the specific region on an object having the object type of the first object, the security engine configured to evaluate whether the text of the first object or the second object comprises sensitive information, the at least one processor configured to execute the text recognition module, the text recognition module communicatively coupled to the object analysis module.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2017
From: ABI ANTOUN, RAMZI; ZUO, JINYU
To: SYMANTEC CORPORATION
Reel/Frame 041585/0466 →
Continuity (1)
Related Publication 20180218170A1 · Aug 2, 2018
Cited By (1)
US 12,613,996