Systems and methods to prevent private data misuse by insider
Described embodiments provide systems and methods for protecting private data or confidential information. A device can receive a request from a client for a page from a server that includes confidential information to be verified with an owner of the confidential information. The device may be intermediary between the client and the server. Prior to providing the page to the client for rendering, the device may replace a first user interface (UI) element having the confidential information in the page, with a second UI element to obfuscate the confidential information. The device may receive an activation of the second UI element to request the owner to verify the confidential information from the client. The device may send to the client an update to the page to include an indication of whether the confidential information has been correctly verified with the owner.
1. A method comprising:
receiving, by a device intermediary between a client and a server, a request from the client for a page from the server that includes confidential information to be verified with an owner of the confidential information;
replacing, by the device prior to providing the page to the client for rendering, a first user interface (UI) element having the confidential information in the page, with a second UI element to obfuscate the confidential information;
receiving, by the device from the client, an activation of the second UI element to request the owner to verify the confidential information;
sending, by the device to the client, an update to the page to include an indication of whether the confidential information has been correctly verified with the owner; and
sending, by the device to the client, a message to update the second UI element or another element of the page to include the indication of whether the confidential information has been correctly verified with the owner.
2. The method of claim 1 , wherein the request is initiated by a user of the client in a communication session with the owner, the request initiated to verify the confidential information with the owner in the communication session.
3. The method of claim 1 , comprising:
determining, by the device, that the page from the server includes the confidential information, according to at least one of:
application of at least one rule,
identification of the first UI element, or
an output of a data loss prevention (DLP) system.
4. The method of claim 1 , comprising:
storing, by the device, the confidential information from the page; and
comparing, by the device, the stored confidential information with verification information obtained from the owner; and
determining, by the device according to the comparing, whether the confidential information has been correctly verified with the owner.
5. The method of claim 1 , comprising:
sending, by the device to the client, the page with the second UI element for display to a user of the client, wherein the second UI element comprises a button or widget that can be activated by the user of the client.
6. The method of claim 1 , comprising:
initiating, by the device responsive to receiving the activation of the second UI element:
a one-time verification message to the owner,
a push notification to the owner,
a representational state transfer (REST) call to a verification service, or
a prompt to the client or the owner to select a method to verify the confidential information.
7. The method of claim 1 , comprising:
replacing, by the device prior to providing the page to the client for display, a third UI element having additional confidential information in the page, with a fourth UI element to obfuscate the additional confidential information;
receiving, by the device from the client, an activation of the fourth UI element to request the owner to verify the additional confidential information; and
sending, by the device to the client, an update to the page to include an indication of whether the additional confidential information has been correctly verified with the owner.
8. The method of claim 1 , wherein at least one of: the confidential information, or a type of the confidential information, is prevented from being exposed or presented to a user of the client.
9. A device, comprising:
at least one processor located intermediate between a client and a server, the at least one processor configured to:
receive a request from the client for a page from the server that includes confidential information to be verified with an owner of the confidential information;
replace, prior to providing the page to the client for rendering, a first user interface (UI) element having the confidential information in the page, with a second UI element to obfuscate the confidential information;
receive from the client, an activation of the second UI element to request the owner to verify the confidential information;
send, to the client, an update to the page to include an indication of whether the confidential information has been correctly verified with the owner; and
send, to the client, a message to update the second UI element or another element of the page to include the indication of whether the confidential information has been correctly verified with the owner.
10. The device of claim 9 , wherein the request is initiated by a user of the client in a communication session with the owner, the request initiated to verify the confidential information with the owner in the communication session.
11. The device of claim 9 , wherein the at least one processor is configured to:
determine that the page from the server includes the confidential information, according to at least one of:
application of at least one rule,
identification of the first UI element, or
an output of a data loss prevention (DLP) system.
12. The device of claim 9 , wherein the at least one processor is configured to:
store the confidential information from the page; and
compare the stored confidential information with verification information obtained from the owner; and
determine, according to the comparing, whether the confidential information has been correctly verified with the owner.
13. The device of claim 9 , wherein the at least one processor is configured to:
send, to the client, the page with the second UI element for display to a user of the client, wherein the second UI element comprises a button or widget that can be activated by the user of the client.
14. The device of claim 9 , wherein the at least one processor is configured to:
initiate, responsive to receiving the activation of the second UI element:
a one-time verification message to the owner,
a push notification to the owner,
a representational state transfer (REST) call to a verification service, or
a prompt to the client or the owner to select a method to verify the confidential information.
15. The device of claim 9 , wherein the at least one processor is configured to:
replace, prior to providing the page to the client for rendering, a third UI element having additional confidential information in the page, with a fourth UI element to obfuscate the additional confidential information;
receive, from the client, an activation of the fourth UI element to request the owner to verify the additional confidential information; and
send, to the client, an update to the page to include an indication of whether the additional confidential information has been correctly verified with the owner.
16. The device of claim 9 , wherein at least one of: the confidential information, or a type of the confidential information, is prevented from being exposed or presented to a user of the client.
17. A non-transitory computer readable medium storing program instructions for causing at least one processor of a device intermediary between a client and a server, to:
receive a request from the client for a page from the server that includes confidential information to be verified with an owner of the confidential information;
replace, prior to providing the page to the client for rendering, a first user interface (UI) element having the confidential information in the page, with a second UI element to obfuscate the confidential information;
receive from the client, an activation of the second UI element to request the owner to verify the confidential information;
send, to the client, an update to the page to include an indication of whether the confidential information has been correctly verified with the owner; and
send, to the client, a message to update the second UI element or another element of the page to include the indication of whether the confidential information has been correctly verified with the owner.
18. The non-transitory computer readable medium of claim 17 , wherein the program instructions cause the at least one processor to:
initiate, responsive to receiving the activation of the second UI element:
a one-time verification message to the owner,
a push notification to the owner,
a representational state transfer (REST) call to a verification service, or
a prompt to the client or the owner to select a method to verify the confidential information.