Systems and methods for monitoring and mitigating information leaks
Abstract
Systems and methods are disclosed for determining whether a third party observer could determine that an organization has an intent with respect to subject matter based on the organization's web activity. The determination that there is a risk of information leaks to the third party observer can be completed by analyzing the entropy of web usage information destined for the third party observer's servers. Systems and methods are also disclosed for mitigating the risk of information leaks by obscuring the organization's web activity. The web activity can be obscured by selecting candidate actions that can be used to generate neutralizing web traffic from the organization's network which will obscure an intent the organization has with respect to a particular subject matter. For example, the candidate actions can identify specific queries, links, or actions that the organization can take to neutralize their web activity to a less remarkable point in the search space.
Claims
exact text as granted — not AI-modified1 . A method for determining whether a third party observer could determine that an organization has an intent with respect to subject matter, the method comprising:
collecting data in transit between the group of users and Internet-connected elements associated with a plurality of third party observers; extracting metadata from the collected data; processing the extracted metadata to identify information each of the plurality of third party observers has received from the organization; and determining, based on the processed extracted metadata, that at least one of the third party observers has received sufficient information from the organization to determine that the organization has an intent with respect to a particular subject matter.
2 . The method of claim 1 , wherein the data in transit is collected from a position in the network where network communications are consolidated.
3 . The method of claim 1 , further comprising:
incrementing a value of a counter of a plurality of counters based on the extracted metadata, wherein each of the plurality of counters is associated with each of the plurality of third party observers, and wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on the relative values of the plurality of counters.
4 . The method of claim 1 , further comprising:
determining, based on the extracted metadata, what information the at least one third party observer has acquired about the group of users.
5 . The method of claim 1 , further comprising:
identifying the at least one third party observer based on the extracted metadata.
6 . The method of claim 1 , further comprising:
generating an entropy graph based on the extracted metadata, wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on peaks in the entropy graph.
7 . The method of claim 1 , wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on distance metrics that are calculated with respect to the extracted metadata.
8 . The method of claim 1 , wherein the extracted metadata includes at least one of HTTP cookies, HTML meta tags, the times at which application transactions occur, URLs that are accessed, IP addresses, and MAC addresses.
9 . A system for determining whether a third party observer could determine that an organization has an intent with respect to subject matter, the system comprising:
metadata extracting circuitry configured to:
collect data in transit between the group of users and Internet-connected elements associated with a plurality of third party observers, and
a extract metadata from the collected data; and
privacy analyzing circuitry configured to:
processing the extracted metadata to identify information each of the plurality of third party observers has received from the organization; and
determine, based on the processed extracted metadata, that at least one of the third party observers has received sufficient information from the organization to determine that the organization has an intent with respect to a particular subject matter.
10 . The system of claim 9 , wherein the metadata extractor is positioned within the network at a point where network communications are consolidated.
11 . The system of claim 9 , wherein the privacy analyzing circuitry is further configured to:
maintain a plurality of counters associated with each of the plurality of third party observers, and increment a value of a respective counter of the plurality of counters based on the extracted metadata, wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on the relative values of the plurality of counters.
12 . The system of claim 9 , wherein the privacy analyzing circuitry is further configured to determine, based on the extracted metadata, what information the at least one third party observer has acquired about the group of users.
13 . The system of claim 9 , wherein the privacy analyzing circuitry is further configured to identify the at least one third party observer based on the extracted metadata.
14 . The system of claim 9 , wherein the privacy analyzing circuitry is further configured to generate an entropy graph based on the extracted metadata, wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on peaks in the entropy graph.
15 . The system of claim 9 , wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on distance metrics that are calculated with respect to the extracted metadata.
16 . The system of claim 9 , wherein the extracted metadata includes at least one of HTTP cookies, HTML meta tags, the times at which application transactions occur, URLs that are accessed, IP addresses, and MAC addresses.
17 . A computer readable medium storing computer executable instructions, which, when executed by a processor, cause the processor to carryout a method for determining whether a third party observer could determine that an organization has an intent with respect to subject matter, the computer readable medium comprising:
collecting data in transit between the group of users and Internet-connected elements associated with a plurality of third party observers; extracting metadata from the collected data; processing the extracted metadata to identify information each of the plurality of third party observers has received from the organization; and determining, based on the processed extracted metadata, that at least one of the third party observers has received sufficient information from the organization to determine that the organization has an intent with respect to a particular subject matter.
18 . A method for obscuring an existence of an intent of an organization with respect to subject matter, the method comprising:
generating an organization's similarity matrix based on the organization's web usage information; providing a desired similarity matrix that meets an obfuscation constraint; generating a distance matrix based on the organization's similarity matrix and the desired similarity matrix; selecting a candidate action from a plurality of candidate actions based on the distance matrix, wherein the selected candidate action includes web behaviors that would make the organization's similarity matrix more similar the desired similarity matrix; modifying the organization's similarity matrix based on the candidate action; and determining whether the modified organization's similarity matrix meets the obfuscation constraint.
19 . The method of claim 18 , further comprising iterating the selecting the candidate action and modifying the organization's similarity matrix until the modified organization's similarity matrix meets the obfuscation constraint.
20 . The method of claim 18 , further comprising iterating the selecting the candidate action and modifying the organization's similarity matrix until the number of iterations reaches a maximum number of iterations.
21 . The method of claim 18 , wherein the candidate action is selected based on a gradient descent calculation on the distance matrix.
22 . The method of claim 18 , further comprising:
generating neutralizing web activity based on the selected candidate action.
23 . The method of claim 22 , wherein the candidate action includes a website and a behavior to perform on the website and the generated web activity is based on the performance of the behavior.
24 . The method of claim 22 , wherein the web activity is generated with a spoofed address associated with a user in the organization.
25 . The method of claim 18 , wherein the obfuscation constraint sets a maximum similarity index value for the organization's similarity matrix.
26 . A system for obscuring an existence of an intent of an organization with respect to subject matter, the system comprising:
obfuscating circuitry configured to:
generate an organization's similarity matrix based on the organization's web usage information;
provide a desired similarity matrix that meets a obfuscation constraint;
generate a distance matrix based on the organization's similarity matrix and the desired similarity matrix;
select a candidate action from a plurality of candidate actions based on the distance matrix, wherein the selected candidate action includes web behaviors that would make the organization's similarity matrix more similar the desired similarity matrix;
modify the organization's similarity matrix based on the candidate action; and
determine whether the modified organization's similarity matrix meets the obfuscation constraint.
27 . The system of claim 26 , wherein the obfuscating circuitry is further configured to iterate the selecting the candidate action and modifying the organization's similarity matrix until the modified organization's similarity matrix meets the obfuscation constraint.
28 . The system of claim 26 , wherein the obfuscating circuitry is further configured to iterate the selecting the candidate action and modifying the organization's similarity matrix until the number of iterations reaches a maximum number of iterations.
29 . The system of claim 26 , wherein the candidate action is selected based on a gradient descent calculation on the distance matrix.
30 . The system of claim 26 , wherein the obfuscating circuitry is further configured to generate neutralizing web activity based on the selected candidate action.
31 . The system of claim 30 , wherein the candidate action includes a website and a behavior to perform on the website and the generated web activity is based on the performance of the behavior.
32 . The system of claim 30 , wherein the web activity is generated with a spoofed address associated with a user in the organization.
33 . The system of claim 26 , wherein the obfuscation constraint sets a maximum similarity index value for the organization's similarity matrix.
34 . A computer readable medium storing computer executable instructions, which, when executed by a processor, cause the processor to carryout a method for obscuring an existence of an intent of an organization with respect to subject matter, the computer readable medium comprising:
generating an organization's similarity matrix based on the organization's web usage information; providing a desired similarity matrix that meets a obfuscation constraint; generating a distance matrix based on the organization's similarity matrix and the desired similarity matrix; selecting a candidate action from a plurality of candidate actions based on the distance matrix, wherein the selected candidate action includes web behaviors that would make the organization's similarity matrix more similar the desired similarity matrix; modifying the organization's similarity matrix based on the candidate action; and determining whether the modified organization's similarity matrix meets the obfuscation constraint.Join the waitlist — get patent alerts
Track US2012158953A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.