Systems and methods for managing data spills
Abstract
Systems, methods, and non-transitory computer readable media are provided for managing data spills. A classified document may be identified. The classified document may be associated with a document classification marking and one or more portion classification markings. Whether the classified document is misclassified may be determined based on a mismatch between the document classification marking and at least one of the one or more portion classification markings. Responsive to determining that the classified document is misclassified, one or more operations may be performed on the classified document.
Claims
exact text as granted — not AI-modified1 . A system comprising:
one or more processors; and a memory storing instructions that, when executed by the one or more processors, cause the system to perform:
receiving a document uploaded from a computing node;
determining a classification of the document based on classification markings associated with the document;
monitoring access to the document by other computing nodes through an object event stream that describes changes in a network of computing nodes, the object event stream enabling implementation, from a central location, of classified document identification logic at each node at an edge of the network;
parsing a first set of classification markings associated with a first upload of the classified document;
indexing the parsed first set of classification markings;
identifying a second upload of the classified document;
identifying a second set of classification markings associated with the second upload of the classified document; and
determining that the classified document is misclassified based at least in part on a mismatch between the second set of classification markings and the indexed classification markings.
2 . The system of claim 1 , wherein the determination that the classified document is misclassified is in response to identifying that the second set of classification markings has a portion marking that is dominant over an overall classification marking of the classified document.
3 . The system of claim 1 , wherein the determination of the classification of the document is based on identified semantics within the document.
4 . The system of claim 1 , wherein the instructions further cause the one or more processors to:
in response to determining a misclassification of the document from a second computing node, quarantine the document from further access and preventing the propagation of the document.
5 . The system of claim 1 , wherein determining the classification of the document based on the classification markings associated with the document comprises:
determining an overall classification marking associated with the document; determining one or more portion classification markings associated with the documents; and determining that the one or more portion classification markings do not exceed a security level associated with the overall classification marking; and identifying the overall classification marking as the classification of the document.
6 . The system of claim 4 , wherein the overall classification marking is stored as one of text, image, watermark, or metadata associated with the document.
7 . The system of claim 4 , wherein the one or more portion classification markings are embedded in headers associated with the document.
8 . The system of claim 1 , wherein the object event stream associated with the computing node tracks changes to the document through the computing node.
9 . The system of claim 1 , wherein the misclassification of the document by the second user occurs when the second user accesses the document without having a sufficient classification level to access the document.
10 . The system of claim 1 , wherein the misclassification of the document by the second user occurs when the second user changes the classification of the document without having a sufficient classification level to make classification changes to the document.
11 . The system of the claim 1 , wherein the misclassification of the document is determined based on the object event stream associated with the computing node.
12 . A computer-implemented method comprising:
receiving, by a computing system, a document uploaded from a computing node; determining, by the computing system, a classification of the document based on classification markings associated with the document; monitoring, by the computing system, access to the document by other computing nodes through an object event stream that describes changes in a network of computing nodes, the object event stream enabling implementation, from a central location, of classified document identification logic at each node at an edge of the network; parsing a first set of classification markings associated with a first upload of the classified document; indexing the parsed first set of classification markings; identifying a second upload of the classified document; identifying a second set of classification markings associated with the second upload of the classified document; and determining that the classified document is misclassified based at least in part on a mismatch between the second set of classification markings and the indexed classification markings.
13 . The method of claim 12 , wherein the determination of the classification of the document is based on identified semantics within the document.
14 . The method of claim 12 , wherein the access to the document includes at least one of creation, reception, and importation of the document.
15 . The method of claim 12 , wherein determining the classification of the document based on the classification markings associated with the document comprises:
determining an overall classification marking associated with the document; determining one or more portion classification markings associated with the documents; and determining that the one or more portion classification markings do not exceed a security level associated with the overall classification marking; and identifying the overall classification marking as the classification of the document.
16 . The method of claim 12 , wherein the misclassification of the document is determined based on the object event stream associated with the computing node.
17 . A non-transitory computer readable medium of a computing system comprising instructions that, when executed by one or more processors of the computing system, cause the computing system to perform:
receiving a document uploaded from a computing node; determining a classification of the document based on classification markings associated with the document; monitoring access to the document by other computing nodes through an object event stream that describes changes in a network of computing nodes, the object event stream enabling implementation, from a central location, of classified document identification logic at each node at an edge of the network; parsing a first set of classification markings associated with a first upload of the classified document; indexing the parsed first set of classification markings; identifying a second upload of the classified document; identifying a second set of classification markings associated with the second upload of the classified document; and determining that the classified document is misclassified based at least in part on a mismatch between the second set of classification markings and the indexed classification markings.
18 . The non-transitory computer readable medium of claim 17 , wherein the determination of the classification of the document is based on identified semantics within the document.
19 . The non-transitory computer readable medium of claim 17 , wherein the access to the document includes at least one of creation, reception, and importation of the document.
20 . The non-transitory computer readable medium of claim 17 , wherein determining the classification of the document based on the classification markings associated with the document comprises:
determining an overall classification marking associated with the document; determining one or more portion classification markings associated with the documents; and determining that the one or more portion classification markings do not exceed a security level associated with the overall classification marking; and identifying the overall classification marking as the classification of the document.Join the waitlist — get patent alerts
Track US2021295116A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.