IP Library Granted Patent US 12,316,675
Granted Patent B2
US 12,316,675 · App. 17/447,813 · Granted May 27, 2025

Content based security requirements

Inventors: Fang Lu (Billerica, MA); Jeremy R. Fox (Georgetown, TX); Martin G. Keen (Cary, NC); Uri Kartoun (Cambridge, MA)
Assignee: International Business Machines Corporation
H04L63/20G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,675
App. No.
17/447,813
Granted
May 27, 2025
Kind
B2
Abstract

Taking security actions according to calculated sensitivity levels of objects. Sensitivity levels are determined according to learned security measures taken on objects having certain content. Security actions are taken upon determining that an object in view of recently added content has an actionable sensitivity level. Additional considerations apply to baseline aspects of the object as well as ongoing changes to the baseline considerations.

Claims (71)

1. A computer-implemented method comprising:

determining characteristics of a set of objects having a first sensitivity score, the characteristics including at least one of memory size, total number of words in an object, access frequency, and storage time;

associating, from the determined characteristics, a set of characteristics of the set of objects with the first sensitivity score;

creating a rules database establishing links between object characteristics and security requirements, the rules database:

linking the set of characteristics with the first sensitivity score; and

linking the first sensitivity score with a set of security requirements;

monitoring use of a computing system for an object modification, the object modification includes adding content to the object;

responsive to detecting the object modification, identifying an object being modified by the object modification and a storage location of the object, the object having a pre-defined sensitivity score, the storage location having a pre-defined security score, and the storage location being secured according to a first security protocol based on the pre-defined security score of the storage location being below a threshold value for maintaining the first security protocol;

computing a revised sensitivity score for the object during modification of characteristics of the object;

revising the pre-defined security score of the identified storage location based on the revised sensitivity score of the object stored therein to generate a revised security score of the storage location; and

responsive to the revised security score of the storage location exceeding the threshold value, taking a security action to modify the first security protocol.

2. The method of claim 1 , further comprising:

collecting user-specific preferences including the set of objects having pre-assigned sensitivity scores and user profile data; and

establishing a training dataset with the collected user-specific preferences;

wherein:

computing the revised sensitivity score is performed by a machine learning model trained on the training dataset.

3. The method of claim 1 , wherein:

the set of objects is a set of text documents;

the storage location is a file system directory; and

the object modification includes adding words and phrases a text document.

4. The method of claim 3 , wherein computing the revised sensitivity score includes:

determining a specified number of characters are added to the text document;

identifying text characteristics of the set of characteristics in the text document including the added words and phrases; and

determining an assigned sensitivity score corresponding to the identified text characteristics.

5. The method of claim 1 , wherein the set of characteristics includes sets of words and sets of phrases.

6. The method of claim 1 , further comprising:

receiving the first threshold value for maintaining the first security protocol from an administrator of the storage location.

7. The method of claim 1 , wherein computing the revised sensitivity score is performed a specified duration of time after detecting the object modification.

8. The method of claim 1 , wherein:

the set of objects is a set of text documents;

the target storage location is a file system directory; and

the modification of characteristics includes adding words and phrases a text document.

9. A computer system comprising:

a processor set; and

a computer readable storage medium;

wherein:

the processor set is structured, located, connected, and/or programmed to run program instructions stored on the computer readable storage medium; and

the program instructions which, when executed by the processor set, cause the processor set to perform a method including:

determining characteristics of a set of objects having a first sensitivity score, the characteristics including at least one of memory size, total number of words in an object, access frequency, and storage time;

associating, from the determined characteristics, a set of characteristics of the set of objects with the first sensitivity score;

creating a rules database establishing links between object characteristics and security requirements, the rules database:

linking the set of characteristics with the first sensitivity score; and

linking the first sensitivity score with a set of security requirements;

monitoring use of a computing system for an object modification, the object modification includes adding content to the object;

responsive to detecting the object modification, identifying an object being modified by the object modification and a storage location of the object, the object having a pre-defined sensitivity score, the storage location having a pre-defined security score, and the storage location being secured according to a first security protocol based on the pre-defined security score of the storage location being below a threshold value for maintaining the first security protocol;

computing a revised sensitivity score for the object during modification of characteristics of the object;

revising the pre-defined security score of the identified storage location based on the revised sensitivity score of the object stored therein to generate a revised security score of the storage location; and

responsive to the revised security score of the storage location exceeding the threshold value, taking a security action to modify the first security protocol.

10. The computer system of claim 9 , further causing the processor to perform a method including:

collecting user-specific preferences including the set of objects having pre-assigned sensitivity scores and user profile data; and

establishing a training dataset with the collected user-specific preferences;

wherein:

computing the revised sensitivity score is performed by a machine learning model trained on the training dataset.

11. The computer system of claim 9 , wherein:

the set of objects is a set of text documents;

the storage location is a file system directory; and

the object modification includes adding words and phrases a text document.

12. The computer system of claim 11 , wherein computing the revised sensitivity score includes:

determining a specified number of characters are added to the text document;

identifying text characteristics of the set of characteristics in the text document including the added words and phrases; and

determining an assigned sensitivity score corresponding to the identified text characteristics.

13. The computer system of claim 9 , wherein the set of characteristics includes sets of words and sets of phrases.

14. The computer system of claim 9 , further comprising:

receiving the first threshold value for maintaining the first security protocol from an administrator of the storage location.

15. A computer-implemented method comprising:

determining characteristics of a set of objects having a first sensitivity score, the characteristics including a memory size and an access frequency;

associating, from the determined characteristics, a set of characteristics of the set of objects with the first sensitivity score;

creating a rules database establishing links between object characteristics and security requirements, the rules database linking the set of characteristics with a set of security requirements;

computing a revised sensitivity score for an object during modification of characteristics of the object;

generating a current security score of a target storage location based on the revised sensitivity score of the object, wherein the object is stored in the target storage location according to a first security protocol; and

responsive to the current security score of the target storage location exceeding a threshold value for the first security protocol, taking a security action to modify the first security protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2021
From: LU, FANG; FOX, JEREMY R.; KEEN, MARTIN G.; KARTOUN, URI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057496/0428 →
Continuity (1)
Related Publication 20230080992A1 · Mar 16, 2023
References Cited (23)
US 9413771B2 · Lim · 2016 [cited by applicant]
US 9734169B2 · Redlich · 2017 [cited by applicant]
US 10979461B1 · Cervantez · 2021 [cited by applicant]
US 20120303558A1 · Jaiswal · 2012 [cited by applicant]
US 20160057115A1 · Abuelsaad · 2016 [cited by applicant]
US 20170093910A1 · Gukal · 2017 [cited by applicant]
US 20180197087A1 · Luo · 2018 [cited by applicant]
US 20180329733A1 · Aronov · 2018 [cited by examiner]
US 20190057210A1 · Aelkatwad · 2019 [cited by examiner]
US 20190081982A1 · Breton · 2019 [cited by examiner]
US 20190171846A1 · Conikee · 2019 [cited by examiner]
US 20210075815A1 · dos Santos Silva · 2021 [cited by examiner]
US 20230007023A1 · Andrabi · 2023 [cited by examiner]
CN 108337571A · 2018 [cited by examiner]
RO 132807A · 2018 [cited by applicant]
“An Introduction to Microsoft Azure Information Protection—YouTube”, Jun. 22, 2016, 2 pages, <https://www.youtube.com/watch?v=N9lp0m6d3G0>. [cited by applicant]
“Apply a sensitivity label to content automatically”, Microsoft 365 licensing guidance for security and compliance, Mar. 17, 2021, 21 pages, <https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-sensitivity-l… [cited by applicant]
“Quick Guide: Using Azure Information Protection to Keep Your Content Secure”, Why choose Azure Information Protection | Proventeq, Mar. 20, 2019, 5 pages, <https://www.proventeq.com/blog/quick-guide-using-azure-informa… [cited by applicant]
Araujo et al. “From Patches to Honey-Patches: Lightweight Attacker Misdirection, Deception, and Disinformation”, CCS'14, Nov. 3-7, 2014, Scottsdale, Arizona, USA, Copyright 2014 ACM, 12 pages. [cited by applicant]
Ayoade et al.. “Automating Cyberdeception Evaluation with Deep Learning”, HICSS, Jan. 2020, 10 pages. [cited by applicant]
Boggs et al., “Synthetic Data Generation and Defense in Depth Measurement of Web Applications*”, International Workshop on Recent Advances in Intrusion Detection, Springer, Cham, 2014, 21 pages. [cited by applicant]
Brueckner et al., “Automated computer forensics training in a virtualized environment” Digital investigation 5 (2008): S105-S111, 7 pages. [cited by applicant]
Deshotels et al., “iOracle: Automated Evaluation of Access Control Policies in iOS”, ASIACCS'18, Jun. 4-8, 2018, Incheon, Republic of Korea, 15 pages. [cited by applicant]