US2021240848A1PendingUtilityA1

Detecting an attempted access of personal information on client computing devices

Assignee: LOOKOUT INCPriority: Oct 25, 2013Filed: Apr 12, 2021Published: Aug 5, 2021
Est. expiryOct 25, 2033(~7.2 yrs left)· nominal 20-yr term from priority
H04W 12/08H04W 12/02H04W 88/02G06F 21/6245H04L 63/20
73
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are disclosed for managing personal data on a client computer in which personal data stored at one or more locations on the client computer is identified by a policy management module on the computer or a server. A policy is then created based on the identified personal data. The policy management module monitors at least the personal data stored in the one or more locations and detects attempts to access the monitored data and determines whether the attempts are in violation of the policy.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 identifying, by a policy management module on a client computer or a server, data stored at one or more network-enabled locations for storing data;   determining, by the policy management module, that a subset of the identified data is personal data representing data relating to an identifiable individual;   creating, by the policy management module, a policy based on the determined subset of the identified data;   applying the created policy, by the policy management module, to monitor only the subset of the identified data at the one or more network-enabled locations where the subset is stored;   detecting an attempted access of the subset of the identified data in violation of the created policy; and   generating an alert indicating the attempt to access the subset of the identified data in violation of the created policy.   
     
     
         2 . The method of  claim 1 , wherein detecting an attempted access of the subset of the identified data in violation of the created policy includes one of: detecting a transmission of a part of the subset of identified data; identifying an application transmitting a part of the subset of data; or observing a transmission of a part of the subset of data over a network. 
     
     
         3 . The method of  claim 1 , wherein monitoring only the subset of the identified data includes:
 detecting a request for access to the subset of the identified data by an application executing on the client computer.   
     
     
         4 . The method of  claim 3 , wherein detecting the request for access to the subset of the identified data includes determining that the application executing on the client computer is requesting access to the subset of the identified data. 
     
     
         5 . The method of  claim 1 , wherein the alert notification is sent to an administrator and includes a prompt for a response from the administrator to allow access to the subset of the identified data, and further comprises:
 receiving, by the policy management module, a response from the administrator and   granting, by the policy management module, the access to the subset of the identified data when the response from the administrator is to allow the access.   
     
     
         6 . The method of  claim 1 , further comprising identifying, by the policy management module using the created policy, additional personal data stored in the one or more locations for storing data on the client computer, and applying the created policy to monitor the additional identified personal data. 
     
     
         7 . The method of  claim 1 , wherein the policy is created further based on at least one of: indexed document matching, data identifiers, or a classifier. 
     
     
         8 . The method of  claim 7 , wherein creating the policy based on the indexed document matching includes creating the policy based on text identified from the determined subset of the identified data. 
     
     
         9 . The method of  claim 7 , wherein creating the policy based on the data identifiers includes creating the policy by identifying known formats associated with the determined subset of the identified data. 
     
     
         10 . The method of  claim 7 , wherein creating the policy based on the classifier includes creating the policy by analyzing the determined subset of the identified data, sorting the determined subset of the identified data by classification, and creating a model to be used to identify additional personal data that match classifications of the model. 
     
     
         11 . A method comprising:
 identifying, by a policy management module on a client computer or a server, one or more network-enabled locations for storing data;   identifying, by the policy management module, data stored at the one or more locations for storing data;   determining, by the policy management module, that a subset of the identified data contains personal data relating to an identifiable individual;   creating, by the policy management module, a policy based on the determined subset of the identified data stored at the one or more locations;   applying, by the policy management module, the created personal data policy to the client computer;   monitoring, by the policy management module, only the determined subset of the identified data at the one or more network-enabled locations where the subset is stored based on the personal data policy applied to the client computer;   detecting, by the policy management module, an attempted access of the subset of the identified data in violation of the created policy; and   generating, by the policy management module, an alert indicating the attempt to access the subset of the identified data in violation of the created policy.   
     
     
         12 . The method of  claim 11 , wherein monitoring only the determined subset of the identified data at the one or more network-enabled locations comprises:
 detecting a request, from an application executing on the client computer, for access to the subset of the identified data.   
     
     
         13 . The method of  claim 12 , wherein detecting the request for access includes determining if the requested access results in a transmission of at least part of the monitored data from the client computer. 
     
     
         14 . The method of  claim 12 , wherein, the application is associated with a container wrapper, and wherein detecting the request for access of the subset of identified data is based on the application interacting with an interface of the container wrapper. 
     
     
         15 . The method of  claim 11 , wherein the alert is sent to an administrator, the alert notification including a prompt for a response from the administrator to allow the request for access to the subset of the identified data. 
     
     
         16 . The method of  claim 15 , further comprising:
 receiving, by the policy management module, a response from the administrator; and   granting, by the policy management module, the request for access to the subset of the identified data when the response from the administrator is to allow the request.   
     
     
         17 . A non-transitory, computer-readable storage medium having stored thereon a plurality of instructions, which, when executed by a processor of a client computer or a server, cause the processor to:
 identify data stored at one or more network-enabled locations on the client computer;   determine that a subset of the identified data is personal data representing data relating to an identifiable individual;   create a policy based on the determined subset of the identified data stored at the one or more locations;   apply the created policy to monitor only the subset of the identified data at the one or more network-enabled locations where the subset is stored;   detect an attempted access of the subset of identified data in violation of the created policy; and   generate an alert indicating the attempt to access the subset of identified data in violation of the created policy.   
     
     
         18 . The computer-readable storage medium of  claim 17 , wherein monitoring only the subset of the identified data at the one or more network-enabled locations includes:
 detecting a request, from an application executing on the client computer, for access to the subset of the identified data; and   determining if the requested access results in a transmission of at least part of the monitored data from the client computer.   
     
     
         19 . A system, comprising at least one processor and memory and instructions that when executed cause the at least one processor to:
 identify data stored at one or more network-enabled locations on a client computer;   determine that a subset of the identified data is personal data representing data relating to an identifiable individual;   create a policy based on the determined subset of the identified data stored at the one or more locations;   apply the created policy to monitor only the subset of the identified data at the one or more network-enabled locations where the subset is stored;   detect an attempted access of the subset of identified data in violation of the created policy; and   generate an alert indicating the attempt to access the subset of identified data in violation of the created policy.   
     
     
         20 . The system of  claim 19 , wherein monitoring only the subset of the identified data at the one or more network-enabled locations on the client computer includes:
 detecting a request, from an application executing on the client computer, for access to the subset of the identified data; and   determining if the requested access results in a transmission of at least part of the monitored data from the client computer.

Join the waitlist — get patent alerts

Track US2021240848A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.