IP Library Granted Patent US 11,748,306
Granted Patent B1
US 11,748,306 · App. 15/826,814 · Granted Sep 5, 2023

Distributed data classification

Inventors: Abhishek Sureshchandra Chaudhary (Kalyan, IN); Muthukannan Murugappan (Trichy, IN); Parag V. Thakur (Pune, IN)
Assignee: Veritas Technologies LLC
G06F16/1734G06F16/13G06F16/183
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,748,306
App. No.
15/826,814
Granted
Sep 5, 2023
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes for source side classification of five and active data. Operating system calls associated with files being accessed or files recently accessed by an endpoint computing device are intercepted. A list including the files is generated and sent to a server computing device. A confirmation is received that a request to classify the files has been received from the server computing device.

Claims (82)

1 . A computer-implemented method comprising:

intercepting a plurality of operating system calls at an endpoint computing device, wherein

the plurality of operating system calls are associated with a plurality of files edited by the endpoint computing device;

generating a file list at the endpoint computing device, wherein

the file list comprises information that identifies the plurality of files associated with the intercepted operating system calls;

communicating the file list from the endpoint computing device to an approval computing device;

determining, at the approval computing device, whether the plurality of files in the file list are to be classified by the endpoint computing device as files with restricted access or unrestricted access;

in response to the approval computing device determining that the plurality of files in the file list are to be classified at the endpoint computing device, communicating a file classification request from the approval computing device to the endpoint computing device, wherein the file classification request includes user benchmark data relating to file classification performance of a user of the endpoint computing device;

determining, at the endpoint computing device, whether the endpoint computing device is idle and whether execution of a classification operation by the endpoint computing device would increase a processing load imposed on the endpoint computing device beyond a threshold, wherein the classification operation is configured to allow classification of the one or more files; and

in response to a determination that the endpoint computing device is idle and the classification operation will not increase the processing load imposed on the endpoint computing device beyond the threshold,

classifying each of the plurality of files as confidential with restricted access or not confidential with unrestricted access by the endpoint computing device.

2 . The computer-implemented method of claim 1 , further comprising:

in response to determining that the classification operation will cause deterioration in performance of the endpoint computing device, and that the endpoint computing device is not idle

inhibiting or delaying performance of the classification operation on the endpoint computing device.

3 . The computer-implemented method of claim 1 wherein the determining whether the endpoint computing device is idle is based, at least in part, on a user history or a geolocation of the endpoint computing device.

4 . The computer-implemented method of claim 1 , wherein

intercepting the one or more operating system calls comprises

accessing a kernel of the operating system,

monitoring a file system associated with the operating system,

identifying one or more network events associated with the endpoint computing device, and

identifying the one or more files.

5 . The computer-implemented method of claim 1 , wherein

the benchmark data is associated with an employee level of the user of the endpoint computing device in an active directory, a peer of the user of the endpoint computing device in the active directory, a business unit of the user of the endpoint computing device, or a peer organization of the user of the endpoint computing device.

6 . The computer-implemented method of claim 1 , wherein

the file classification request is generated by a file classification manager executing on a server computing device,

the file list comprising the one or more files is generated by a file classification engine executed by the endpoint computing device, and

the one or more files are temporarily stored on a local storage device or a memory associated with the endpoint computing device and permanently stored on a remote storage device.

7 . A non-transitory computer readable storage medium comprising program instructions executable to perform a method comprising:

intercepting a plurality of operating system calls at an endpoint computing device, wherein

the plurality of operating system calls are associated with a plurality of files edited by the endpoint computing device;

generating a file list at the endpoint computing device, wherein

the file list comprises information that identifies the plurality of files associated with the intercepted operating system calls;

communicating the file list from the endpoint computing device to an approval computing device;

determining, at the approval computing device, whether the plurality of files in the file list are to be classified by the endpoint computing device as files with restricted access or unrestricted access;

in response to the approval computing device determining that the plurality of files in the file list are to be classified at the endpoint computing device, communicating a file classification request from the approval computing device to the endpoint computing device, wherein the file classification request includes user benchmark data relating to file classification performance of a user of the endpoint computing device;

determining, at the endpoint computing device, whether the endpoint computing device is idle and whether execution of a classification operation by the endpoint computing device would increase a processing load imposed on the endpoint computing device beyond a threshold, wherein the classification operation is configured to allow classification of the one or more files; and

in response to a determination that the endpoint computing device is idle and the classification operation will not increase the processing load imposed on the endpoint computing device beyond the threshold,

classifying each of the plurality of files as confidential with restricted access or not confidential with unrestricted access by the endpoint computing device.

8 . The non-transitory computer readable storage medium of claim 7 , wherein the method further comprises:

in response to determining that the classification operation will cause deterioration in performance of the endpoint computing device, and that the endpoint computing device is not idle

inhibiting or delaying performance of the classification operation on the endpoint computing device.

9 . The non-transitory computer readable storage medium of claim 7 wherein the determining whether the endpoint computing device is idle is based, at least in part, on a user history or a geolocation of the endpoint computing device.

10 . The non-transitory computer readable storage medium of claim 7 , wherein the intercepting the one or more operating system calls comprises:

accessing a kernel of the operating system,

monitoring a file system associated with the operating system,

identifying one or more network events associated with the endpoint computing device, and

identifying the one or more files.

11 . The non-transitory computer readable storage medium of claim 7 , wherein

the benchmark data is associated with an employee level of the user of the endpoint computing device in an active directory, a peer of the user of the endpoint computing device in the active directory, a business unit of the user of the endpoint computing device, or a peer organization of the user of the endpoint computing device,

the request to classify the one or more files is generated by a file classification manager executing on a server computing device,

the file list comprising the one or more files is generated by a file classification engine executed by the endpoint computing device, and

the one or more files are temporarily stored on a local storage device or a memory associated with the endpoint computing device and permanently stored on a remote storage device.

12 . A system comprising:

one or more computing devices each including,

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors of the one or more computing devices to perform alone, or in combination with other computing devices, a method comprising

intercepting a plurality of operating system calls at an endpoint computing device, wherein

the plurality of operating system calls are associated with a plurality of files edited by the endpoint computing device;

generating a file list at the endpoint computing device, wherein

the file list comprises information that identifies the plurality of files associated with the intercepted operating system calls;

communicating the file list from the endpoint computing device to an approval computing device;

determining, at the approval computing device, whether the plurality of files in the file list are to be classified by the endpoint computing device as files with restricted access or unrestricted access;

in response to the approval computing device determining that the plurality of files in the file list are to be classified at the endpoint computing device, communicating a file classification request from the approval computing device to the endpoint computing device, wherein the file classification request includes user benchmark data relating to file classification performance of a user of the endpoint computing device;

determining, at the endpoint computing device, whether the endpoint computing device is idle and whether execution of a classification operation by the endpoint computing device would increase a processing load imposed on the endpoint computing device beyond a threshold, wherein the classification operation is configured to allow classification of the one or more files; and

in response to a determination that the endpoint computing device is idle and the classification operation will not increase the processing load imposed on the endpoint computing device beyond the threshold,

classifying each of the plurality of files as confidential with restricted access or not confidential with unrestricted access by the endpoint computing device.

13 . The system of claim 12 , wherein the method further comprises:

in response to determining that the classification operation will cause deterioration in performance of the endpoint computing device, and that the endpoint computing device is not idle

inhibiting or delaying performance of the classification operation on the endpoint computing device.

14 . The system of claim 12 , wherein the determining whether the endpoint computing device is idle is based, at least in part, on a user history or a geolocation of the endpoint computing device.

15 . The system of claim 12 , wherein

intercepting the one or more operating system calls comprises

accessing a kernel of the operating system,

monitoring a file system associated with the operating system,

identifying one or more network events associated with the endpoint computing device, and

identifying the one or more files.

16 . The system of claim 12 , wherein

the benchmark data of the user of the endpoint computing device is associated with an employee level in an active directory, a peer of the user of the endpoint computing device in the active directory, a business unit of the user of the endpoint computing device, or a peer organization of the user of the endpoint computing device.

17 . The system of claim 12 , wherein

the request to classify the one or more files is generated by a file classification manager executing on a server computing device,

the file list comprising the one or more files is generated by a file classification engine executed by the endpoint computing device, and

the one or more files are temporarily stored on a local storage device or a memory associated with the endpoint computing device and permanently stored on a remote storage device.

Assignments (14)
SECURITY INTEREST Recorded Dec 12, 2025
From: ARCTERA US LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 073951/0470 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 070530/0497 Recorded Dec 1, 2025
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: ARCTERA US LLC
Reel/Frame 073833/0730 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 069585/0150 Recorded Dec 1, 2025
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: ARCTERA US LLC
Reel/Frame 073833/0848 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069697/0238 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
PATENT SECURITY AGREEMENT Recorded Dec 10, 2024
From: ARCTERA US LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069585/0150 →
SECURITY INTEREST Recorded Dec 10, 2024
From: ARCTERA US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 069563/0243 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC
To: ARCTERA US LLC
Reel/Frame 069548/0468 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 052426/0001 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 054535/0565 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Apr 16, 2020
From: VERITAS TECHNOLOGIES, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 052426/0001 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 18, 2020
From: VERITAS TECHNOLOGIES LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 052189/0311 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2018
From: CHAUDHARY, ABHISHEK SURESHCHANDRA; MURUGAPPAN, MUTHUKANNAN; THAKUR, PARAG V.
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 044613/0409 →