Systems and methods for data loss prevention
    1.
    发明授权
    Systems and methods for data loss prevention 有权
    防止数据丢失的系统和方法

    公开(公告)号:US09191279B1

    公开(公告)日:2015-11-17

    申请号:US13484752

    申请日:2012-05-31

    IPC分类号: G06F17/30 H04L12/24 G06F21/62

    摘要: A computer-implemented method for data loss prevention may include 1) identifying a file hierarchy within a file system (where, e.g., the file hierarchy includes a plurality of files and folders), 2) identifying a defined file hierarchy structure that is associated with a data loss prevention policy (where, e.g., the defined file hierarchy structure identifies the relative locations of files and folders), 3) determining that the file hierarchy is implicated in the data loss prevention policy by determining that the defined file hierarchy structure corresponds to the file hierarchy, and 4) applying the data loss prevention policy to at least a portion of the file hierarchy based on determining that the file hierarchy is implicated in the data loss prevention policy. Various other methods, systems, and computer-readable media are also disclosed.

    摘要翻译: 用于数据丢失防止的计算机实现的方法可以包括:1)识别文件系统内的文件层级(其中,例如,文件层次结构包括多个文件和文件夹),2)识别与 数据丢失预防策略(例如,定义的文件层次结构标识文件和文件夹的相对位置),3)通过确定所定义的文件层次结构对应于文件层级结构,确定文件层次结构涉及数据丢失防范策略 文件层次结构,以及4)基于确定文件层次结构涉及数据丢失防范策略,将数据丢失防范策略应用于文件层级的至少一部分。 还公开了各种其它方法,系统和计算机可读介质。

    Systems and methods for end-user initiated data-loss-prevention content analysis
    2.
    发明授权
    Systems and methods for end-user initiated data-loss-prevention content analysis 有权
    最终用户启动的数据丢失防护内容分析的系统和方法

    公开(公告)号:US09021389B1

    公开(公告)日:2015-04-28

    申请号:US12558930

    申请日:2009-09-14

    申请人: Milind Torney

    发明人: Milind Torney

    IPC分类号: G06F3/048 G06F7/04 G06F21/60

    CPC分类号: G06F21/60 G06F21/6218

    摘要: A computer-implemented method for end-user initiated data-loss-prevention content analysis may include identifying an end-user application that handles content subject to data-loss-prevention policies. The computer-implemented method may also include receiving a request through a user interface associated with the end-user application to analyze selected content for data-loss-prevention policy compliance. The computer-implemented method may further include performing an analysis of the selected content for data-loss-prevention policy compliance. The computer-implemented method may additionally include providing a result of the analysis through the user interface associated with the end-user application. Various other methods, systems, and computer-readable media are also disclosed.

    摘要翻译: 用于最终用户启动的数据丢失 - 防止内容分析的计算机实现的方法可以包括识别处理依赖于数据丢失预防策略的内容的最终用户应用。 计算机实现的方法还可以包括通过与最终用户应用相关联的用户界面来接收请求,以分析选择的内容以进行数据丢失预防策略的遵从。 计算机实现的方法还可以包括执行所选择的内容的分析以用于防止数据丢失的策略。 计算机实现的方法可以另外包括通过与最终用户应用相关联的用户界面来提供分析结果。 还公开了各种其它方法,系统和计算机可读介质。

    Monitoring network-based printing for data loss prevention (DLP)
    3.
    发明授权
    Monitoring network-based printing for data loss prevention (DLP) 有权
    监控基于网络的打印数据丢失预防(DLP)

    公开(公告)号:US09202063B1

    公开(公告)日:2015-12-01

    申请号:US13453214

    申请日:2012-04-23

    IPC分类号: G06F21/60

    CPC分类号: G06F21/60 G06F21/608

    摘要: A method and apparatus for monitoring network-based printing for data loss prevention (DLP). A DLP system may monitor outbound data transfers performed by a computing system, and detect a network print request in a current one of the outbound data transfers being sent to a network-based printer over a network, the network print request identifying data to be printed by the network-based printer. The DLP system determines whether the identified data of the current outbound data transfer violates a DLP policy and prevents the current outbound data transfer when the current outbound data transfer violates the DLP policy.

    摘要翻译: 一种用于监控数据丢失预防(DLP)的基于网络的打印的方法和装置。 DLP系统可以监视由计算系统执行的出站数据传输,并且在通过网络发送到基于网络的打印机的当前数据传输中的当前一个中检测网络打印请求,网络打印请求标识要打印的数据 由基于网络的打印机。 DLP系统确定当前出站数据传输的识别数据是否违反DLP策略,并且在当前出站数据传输违反DLP策略时阻止当前的出站数据传输。

    Language detection to improve efficiency of content scanning engine in data loss prevention (DLP) systems
    4.
    发明授权
    Language detection to improve efficiency of content scanning engine in data loss prevention (DLP) systems 有权
    语言检测,以提高数据丢失预防(DLP)系统中内容扫描引擎的效率

    公开(公告)号:US09111069B1

    公开(公告)日:2015-08-18

    申请号:US13661637

    申请日:2012-10-26

    IPC分类号: G06F17/28 G06F21/00 H04L29/06

    摘要: A method and apparatus for detection of DLP violations with language detection are described. A DLP product may monitor data content associated with the computing system, and identify a language of the data content. Based on the identified language, the DLP product identifies from among multiple DLP policies a first set of one or more DLP policies that are applicable for the identified language (referred to herein as language-specific DLP policies). The DLP product scans the data content using the first set to detect a violation of one of the DLP policies in the data content, and performs a DLP action in response to the detected violation.

    摘要翻译: 描述了通过语言检测来检测DLP违规的方法和装置。 DLP产品可以监视与计算系统相关联的数据内容,并且识别数据内容的语言。 基于所识别的语言,DLP产品从多个DLP策略中识别适用于所识别的语言(本文称为语言特定DLP策略)的第一组一个或多个DLP策略。 DLP产品使用第一组来扫描数据内容,以检测违反数据内容中的一个DLP策略,并响应于检测到的违规执行DLP动作。

    Pre-calculating and updating data loss prevention (DLP) policies prior to distribution of sensitive information
    5.
    发明授权
    Pre-calculating and updating data loss prevention (DLP) policies prior to distribution of sensitive information 有权
    在分发敏感信息之前预先计算和更新数据丢失预防(DLP)政策

    公开(公告)号:US08990882B1

    公开(公告)日:2015-03-24

    申请号:US13341041

    申请日:2011-12-30

    IPC分类号: G06F17/00

    摘要: A method and apparatus submitting information to be protected before permitting an outbound data transfer with the information is described. A DLP agent, incorporating a DLP submission tool, receives information of an outbound data transfer by the client computing system. The DLP agent can temporarily block the outbound data transfer and send a request to update a DLP policy to protect the information before permitting the outbound data transfer. The DLP agent subsequently receives receiving an indication that the DLP policy is updated to protect the information. After receiving the indication, the DLP agent permits the outbound data transfer.

    摘要翻译: 描述了在允许使用该信息的出站数据传送之前提交要保护的信息的方法和装置。 包含DLP提交工具的DLP代理接收客户端计算系统的出站数据传输信息。 DLP代理可以临时阻止出站数据传输,并发送更新DLP策略的请求,以便在允许出站数据传输之前保护信息。 DLP代理随后接收到接收DLP策略被更新以保护信息的指示。 接收到指示后,DLP代理允许出站数据传输。

    Systems and methods for preventing data loss from files sent from endpoints
    6.
    发明授权
    Systems and methods for preventing data loss from files sent from endpoints 有权
    从端点发送的文件中防止数据丢失的系统和方法

    公开(公告)号:US08321560B1

    公开(公告)日:2012-11-27

    申请号:US12540567

    申请日:2009-08-13

    IPC分类号: G06F13/00

    CPC分类号: G06F11/0709 G06F11/0793

    摘要: A computer-implemented method for data loss prevention may include intercepting a packet sent by an application of an endpoint. The computer-implemented method may also include extracting file-identification information from the packet. The computer-implemented method may further include identifying a list of opened files and matching the file-identification information to a file in the list of opened files. The computer-implemented method may additionally include identifying a data-loss-prevention policy that applies to the file. The computer-implemented method may moreover include filtering the packet based on the data-loss-prevention policy. Various other methods, systems, and computer-readable media are also disclosed.

    摘要翻译: 用于数据丢失防止的计算机实现的方法可以包括截取由端点的应用发送的分组。 计算机实现的方法还可以包括从分组中提取文件识别信息。 计算机实现的方法还可以包括识别打开的文件的列表并将文件标识信息与打开的文件列表中的文件进行匹配。 计算机实现的方法还可以包括识别适用于该文件的数据丢失预防策略。 计算机实现的方法还可以包括基于数据丢失防范策略来过滤该分组。 还公开了各种其它方法,系统和计算机可读介质。

    Method and system for protecting content of sensitive web applications
    7.
    发明授权
    Method and system for protecting content of sensitive web applications 有权
    用于保护敏感Web应用程序内容的方法和系统

    公开(公告)号:US08950005B1

    公开(公告)日:2015-02-03

    申请号:US13289998

    申请日:2011-11-04

    申请人: Milind Torney

    发明人: Milind Torney

    摘要: A web page running on a client computing device accesses a web application hosted by a remote server. The local application receives data from the web application. The client computing device uses a data loss prevention (DLP) policy to determine whether the web application is a sensitive web application. In response to determining that the web application is a sensitive web application, the client computing device restricts a capability of at least one of the local application or the client computing device to perform one or more operations associated with the data received from the web application.

    摘要翻译: 在客户端计算设备上运行的网页访问远程服务器托管的Web应用程序。 本地应用程序从Web应用程序接收数据。 客户端计算设备使用数据丢失防护(DLP)策略来确定Web应用程序是否是敏感的Web应用程序。 响应于确定web应用是敏感的web应用,客户端计算设备限制本地应用或客户端计算设备中的至少一个的能力来执行与从web应用接收的数据相关联的一个或多个操作。

    Systems and methods for preventing data loss from files sent from endpoints
    8.
    发明授权
    Systems and methods for preventing data loss from files sent from endpoints 有权
    从端点发送的文件中防止数据丢失的系统和方法

    公开(公告)号:US08612594B1

    公开(公告)日:2013-12-17

    申请号:US13652452

    申请日:2012-10-15

    IPC分类号: G06F13/00

    CPC分类号: G06F11/0709 G06F11/0793

    摘要: A computer-implemented method for data loss prevention may include intercepting a packet sent by an application of an endpoint. The computer-implemented method may also include extracting file-identification information from the packet. The computer-implemented method may further include identifying a list of opened files and matching the file-identification information to a file in the list of opened files. The computer-implemented method may additionally include identifying a data-loss-prevention policy that applies to the file. The computer-implemented method may moreover include filtering the packet based on the data-loss-prevention policy. Various other methods, systems, and computer-readable media are also disclosed.

    摘要翻译: 用于数据丢失防止的计算机实现的方法可以包括截取由端点的应用发送的分组。 计算机实现的方法还可以包括从分组中提取文件识别信息。 计算机实现的方法还可以包括识别打开的文件的列表并将文件标识信息与打开的文件列表中的文件进行匹配。 计算机实现的方法还可以包括识别适用于该文件的数据丢失预防策略。 计算机实现的方法还可以包括基于数据丢失防范策略来过滤该分组。 还公开了各种其它方法,系统和计算机可读介质。