IP Library Granted Patent US 8,533,579
Granted Patent B2
US 8,533,579 · App. 12/603,465 · Granted Sep 10, 2013

Data loss detection method for handling fuzziness in sensitive keywords

Inventor: Vikas Panwar (San Jose, CA)
Assignee: Symantec Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,533,579
App. No.
12/603,465
Granted
Sep 10, 2013
Kind
B2
Abstract

A method and apparatus for handling fuzziness in sensitive keywords from data loss prevention (DLP) policies. In one embodiment, the method includes identifying a keyword included in a DLP policy, generating multiple permutations of the keyword, and adding the multiple permutations to the DLP policy. The method further includes causing information content to be searched for the keyword permutations to detect a violation of the DLP policy in the information content.

Claims (46)

1. A computer-implemented method comprising:

identifying, by a computer system, a keyword included in a data loss prevention (DLP) policy, the keyword comprising a plurality of characters;

generating, by the computer system and in response to the identifying, a plurality of permutations of the characters of the keyword, wherein up to a specified maximum number of permutable characters in the keyword are permuted to generate the plurality of permutations;

adding, by the computer system, the plurality of permutations to the DLP policy; and

causing information content to be searched for the keyword and the plurality of permutations to detect a violation of the DLP policy in the information content.

2. The method of claim 1 further comprising:

creating a record of the DLP policy violation, the record identifying the information content, a detected permutation and a corresponding keyword.

3. The method of claim 1 , wherein each of the plurality of permutations is a distinct anagram of the keyword.

4. The method of claim 1 , further comprising:

receiving user input specifying the maximum number of permutable characters to be used to permute the keyword.

5. The method of claim 1 , wherein the maximum number of permutable characters comprises a maximum number of last characters of the keyword to be permuted.

6. The method of claim 1 , wherein generating, by the computer system and in response to the identifying, a plurality of permutations comprises:

receiving user input specifying the maximum number of permutable characters to be used to permute the keyword and user input specifying a number of last characters to be permuted; and

permuting the specified number of last characters of the keyword while limiting the number of characters to be permuted to the specified maximum number of permutable characters, when generating the plurality of permutations.

7. The method of claim 1 , wherein generating, by the computer system and in response to the identifying, a plurality of permutations comprises:

receiving user input specifying exceptions for keyword permutations; and

removing exceptions from the plurality of permutations prior to adding the plurality of permutations to the DLP policy.

8. The method of claim 1 further comprising:

providing a user interface allowing a user to specify one or more parameters for generating the plurality of permutations.

9. The method of claim 1 wherein the information content is any one of data in use, data in motion, and data at rest.

10. A computer system comprising:

a memory to store a data loss prevention (DLP) policy;

a processor, coupled to the memory; and

a policy management system, executed from the memory by the processor, to:

identify a keyword included in the DLP policy, the keyword comprising a plurality of characters;

generate, in response to identifying the keyword, a plurality of permutations of the characters of the keyword, wherein up to a specified maximum number of permutable characters in the keyword are permuted to generate the plurality of permutations;

add the plurality of permutations to the DLP policy; and

cause information content to be searched for the keywords and the plurality of permutations to detect a violation of the DLP policy in the information content.

11. The system of claim 10 further comprising:

a data management system, coupled to the policy management system, to detect the violation of the DLP policy, and to create a record of the DLP policy violation, the record identifying the information content, a detected permutation and a corresponding keyword.

12. The system of claim 10 , wherein each of the plurality of permutations is a distinct anagram of the keyword.

13. The system of claim 10 , wherein the policy management system comprises a user interface to receive user input specifying the maximum number of permutable characters to be used to permute the keyword.

14. The system of claim 10 , wherein the maximum number of permutable characters comprises a maximum number of last characters of the keyword to be permuted.

15. The system of claim 10 , wherein the policy management system comprises a user interface to receive user input specifying the maximum number of permutable characters to be used to permute the keyword and user input specifying a number of last characters to be permuted, wherein the policy management system is to permute the specified number of last characters of the keyword while limiting the number of characters to be permuted to the specified maximum number of permutable characters, when generating the plurality of permutations.

16. The system of claim 10 , wherein the policy management system comprises a user interface to receive user input specifying exceptions for keyword permutations, wherein the policy management system is to remove exceptions from the plurality of permutations prior to adding the plurality of permutations to the DLP policy.

17. A non-transitory computer readable storage medium that provides instructions, which when executed on a processing system cause the processing system to perform a method comprising:

identifying, by a computer system, a keyword included in a data loss prevention (DLP) policy, the keyword comprising a plurality of characters;

generating, by the computer system and in response to the identifying, a plurality of permutations of the characters of the keyword, wherein up to a specified maximum number of permutable characters in the keyword are permuted to generate the plurality of permutations;

adding, by the computer system, the plurality of permutations to the DLP policy; and

causing information content to be searched for the keyword and the plurality of permutations to detect a violation of the DLP policy in the information content.

18. The non-transitory computer readable storage medium of claim 17 , further comprising:

receiving user input specifying the maximum number of permutable characters to be used to permute the keyword.

19. The non-transitory computer readable storage medium of claim 17 , wherein the maximum number of permutable characters comprises a maximum number of last characters of the keyword to be permuted.

20. The non-transitory computer readable storage medium of claim 17 , wherein generating, by the computer system and in response to the identifying, a plurality of permutations comprises:

receiving user input specifying exceptions for keyword permutations; and

removing exceptions from the plurality of permutations prior to adding the plurality of permutations to the DLP policy.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2009
From: PANWAR, VIKAS
To: SYMANTEC CORPORATION
Reel/Frame 023405/0397 →
Continuity (1)
Related Publication 20110093768A1 · Apr 21, 2011