IP Library Granted Patent US 9,779,260
Granted Patent B1
US 9,779,260 · App. 13/906,241 · Granted Oct 3, 2017

Aggregation and classification of secure data

Inventors: Michel Brisebois (Renfrew, CA); Jason Aylesworth (Nepean, CA); Curtis Johnstone (Ottawa, CA); Andrew John Leach (Ottawa, CA); Elena Vinogradov (Kanata, CA); Joel Stacy Blaiberg (Teaneck, NJ); Stephen Pope (Ashton, CA); Shawn Donald Holmesdale (Ottawa, CA); Guangning Hu (Ottawa, CA)
Assignee: Dell Software Inc.
G06F21/6218G06F17/30563G06F17/30569G06F21/62G06F21/6227G06F2216/01G06F2216/03
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,779,260
App. No.
13/906,241
Filed
May 30, 2013
Granted
Oct 3, 2017
Kind
B1
Art Unit
2494
USPC
726/1
Abstract

In one embodiment, a method includes managing and controlling a plurality of data-access credentials. The method further includes accessing data from a plurality of sources in a plurality of data formats. The accessing includes using one or more data-access credentials of the plurality of data-access credentials. The one or more data-access credentials are associated with at least a portion of the plurality of data sources. The method also includes abstracting the data into a standardized format for further analysis. The abstracting includes selecting the standardized format based on a type of the data. In addition, the method includes applying a security policy to the data. The applying includes identifying at least a portion of the data for exclusion from storage based on the security policy. Additionally, the method includes filtering from storage any data identified for exclusion. Further, the method includes storing the data in the standardized format.

Claims (59)

1. A method comprising:

on a computer system comprising at least one server computer and a plurality of distinct data classification engines, managing and controlling a plurality of data-access credentials;

wherein the plurality of distinct data classification engines comprise an a priori classification engine, a posteriori classification engine, and a heuristics engine;

accessing, by the computer system, data from a plurality of sources in a plurality of data formats, the plurality of sources comprising sources that are internal to the computer system and sources that are external to the computer system;

wherein the accessing comprises using one or more data-access credentials of the plurality of data-access credentials, the one or more data-access credentials being associated with at least a portion of the plurality of data sources;

abstracting, by the computer system, the data into a standardized format for further analysis, the abstracting comprising selecting the standardized format based on a type of the data;

applying, by the computer system, a security policy to the data;

wherein the applying comprises identifying at least a portion of the data for exclusion from storage based on the security policy;

the computer system filtering from storage any data identified for exclusion;

storing, by the computer system, the filtered data in the standardized format;

prior to storing, classifying, using at least one of the plurality of distinct data classification engines, the data based on one or more characteristics of metadata associated with the data;

wherein the a posteriori classification engine is operable to perform an a posteriori classification, the a posteriori classification comprises utilization of one or more probabilistic algorithms, wherein the one or more probabilistic algorithms determine a probability that a set of data comprises a particular classification based on a combination of probabilistic determinations associated with subsets of the set of data, parameters, and metadata associated with the set of data; and

wherein the posteriori classification engine is configured to reclassify, at predefined time intervals, the previously classified data in response to user feedback, wherein the user feedback comprises indications by users of an accuracy of the previously classified data and update the one or more probabilistic algorithms based on the user feedback.

2. The method of claim 1 , wherein the using comprises using the one or more data-access credentials to access an account for each of the at least a portion of the plurality of data sources.

3. The method of claim 1 , wherein the accessing comprises accessing metadata associated with the data.

4. The method of claim 1 , wherein the abstracting comprises extracting metadata from the data.

5. The method of claim 1 , comprising, prior to the storing, formatting the data for storage.

6. The method of claim 1 , wherein the storing comprises dynamically expanding a database responsive to the data including a new type of data.

7. The method of claim 1 , wherein the plurality of sources are selected from the group consisting of: cloud services, social-media services, hosted applications, and email servers.

8. The method of claim 1 , wherein:

the data comprises messaging data; and

the standardized format comprises a standardized format for messages.

9. The method of claim 8 , wherein the accessing comprises accessing email from an email server to obtain metadata.

10. An information handling system comprising:

a processing unit, wherein the processing unit is operable to implement a method comprising:

managing and controlling a plurality of data-access credentials;

accessing data from a plurality of sources in a plurality of data formats, the plurality of sources comprising sources that are internal to the information handling system and sources that are external to the information handling system;

wherein the accessing comprises using one or more data-access credentials of the plurality of data-access credentials, the one or more data-access credentials being associated with at least a portion of the plurality of data sources;

abstracting the data into a standardized format for further analysis, the abstracting comprising selecting the standardized format based on a type of the data;

applying a security policy to the data;

wherein the applying comprises identifying at least a portion of the data for exclusion from storage based on the security policy;

filtering from storage any data identified for exclusion;

storing the filtered data in the standardized format;

prior to storing, classifying, using a plurality of distinct data classification engines, the data based on one or more characteristics of metadata associated with the data;

wherein the plurality of distinct data classification engines comprise an a priori classification engine, a posteriori classification engine, and a heuristics engine;

wherein the a posteriori classification engine is operable to perform an a posteriori classification, the a posteriori classification comprises utilization of one or more probabilistic algorithms, wherein the one or more probabilistic algorithms determine a probability that a set of data comprises a particular classification based on a combination of probabilistic determinations associated with subsets of the set of data, parameters, and metadata associated with the set of data; and

wherein the posteriori classification engine is configured to reclassify, at predefined time intervals, the previously classified data in response to user feedback, wherein the user feedback comprises indications by users of an accuracy of the previously classified data and update the one or more probabilistic algorithms based on the user feedback.

11. The information handling system of claim 10 , wherein the using comprises using the one or more data-access credentials to access an account for each of the at least a portion of the plurality of data sources.

12. The information handling system of claim 10 , wherein the accessing comprises accessing metadata associated with the data.

13. The information handling system of claim 10 , wherein the abstracting comprises extracting metadata from the data.

14. The information handling system of claim 10 , comprising, prior to the storing, formatting the data for storage.

15. The information handling system of claim 10 , wherein the storing comprises dynamically expanding a database responsive to the data including a new type of data.

16. The information handling system of claim 10 , wherein the plurality of sources are selected from the group consisting of: cloud services, social-media services, hosted applications, and email servers.

17. The information handling system of claim 10 , wherein:

the data comprises messaging data; and

the standardized format comprises a standardized format for messages.

18. A non-transitory computer-program product comprising a computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

on a computer system comprising at least one server computer and a plurality of distinct data classification engines, managing and controlling a plurality of data-access credentials;

wherein the plurality of distinct data classification engines comprise an a priori classification engine, an a posteriori classification engine, and a heuristics engine;

accessing, by the computer system, data from a plurality of sources in a plurality of data formats, the plurality of sources comprising sources that are internal to the computer system and sources that are external to the computer system;

wherein the accessing comprises using one or more data-access credentials of the plurality of data-access credentials, the one or more data-access credentials being associated with at least a portion of the plurality of data sources;

abstracting, by the computer system, the data into a standardized format for further analysis, the abstracting comprising selecting the standardized format based on a type of the data;

applying, by the computer system, a security policy to the data;

wherein the applying comprises identifying at least a portion of the data for exclusion from storage based on the security policy;

the computer system filtering from storage any data identified for exclusion;

storing, by the computer system, the filtered data in the standardized format;

prior to storing, classifying, using at least one of the plurality of distinct data classification engines, the data based on one or more characteristics of metadata associated with the data;

wherein the a posteriori classification engine is operable to perform an a posteriori classification, the a posteriori classification comprises utilization of one or more probabilistic algorithms, wherein the one or more probabilistic algorithms determine a probability that a set of data comprises a particular classification based on a combination of probabilistic determinations associated with subsets of the set of data, parameters, and metadata associated with the set of data; and

wherein the posteriori classification engine is configured to reclassify, at predefined time intervals, the previously classified data in response to user feedback, wherein the user feedback comprises indications by users of an accuracy of the previously classified data and update the one or more probabilistic algorithms based on the user feedback.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
CHANGE OF NAME Recorded Aug 19, 2013
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 031035/0914 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2013
From: BRISEBOIS, MICHEL; AYLESWORTH, JASON; JOHNSTONE, CURTIS; LEACH, ANDREW JOHN; VINOGRADOV, ELENA; BLAIBERG, JOEL STACY; POPE, STEPHEN; HOLMESDALE, SHAWN DONALD; HU, GUANGNING
To: QUEST SOFTWARE, INC.
Reel/Frame 030572/0912 →
Continuity (1)
Provisional Application 61658034 · Jun 11, 2012