Nova Patents
EP1540542A2

Detection of preselected data

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 17 September 2023, 3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

91 claims: 46 independent, 45 dependent

  1. 1
    Claims of equivalent WO 2004027653 A2 CLAIMS We claim:1. A method comprising: monitoring messages electronically transmitted over a network for embedded preselected data;and performing content searches on the messages to detect the presence of the embedded preselected data using an abstract data structure derived from the preselected data.
  2. 2
    The method defined in Claim 1 wherein the preselected data comprises database data.
  3. 3
    The method defined in Claim 1 wherein the abstract data structure comprises an index.
  4. 4
    The method defined in Claim 3 wherein the index does not include a copy of the preselected data.
  5. 5
    The method defined in Claim 3 wherein the index comprises a relative placement of elements in a database in relation to other elements in the database.
  6. 6
    The method defined in Claim 3 wherein the index comprises a hash table derived from string values of the cells of database data.
  7. 7
    The method defined in Claim 3 wherein the index comprises a row number, column number and type of column associated with a fragment within the database.
  8. 8
    The method defined in Claim 1 further comprising:querying a database;extracting at least one copy of the preselected data from the database;and creating the abstract data structure based on the preselected data extracted from the database.
  9. 9
    The method defined in Claim 1 further comprising creating the abstract data structure based on the preselected data extracted from a database.
  10. 10
    The method defined in Claim 9 wherein creating the abstract data structure comprises:storing a row number, column number, and data type indicator for each cell in a database table into a hash table;and sorting the hash table based on a predefined order into a collision list.
  11. 11
    The method defined in Claim 10 wherein the order comprises ascending lexicographic order.
  12. 12
    The method defined in Claim 1 wherein performing content searches on the messages using an abstract data structure derived from the preselected data comprises:parsing individual lines of text in one of the messages to parse the one message into individual words;applying a hash function to each of the individual words in a line to generate individual hash table collision lists for each of the individual words on each of the individual lines;and identifying data sets within the individual hash table collision lists with common row numbers and distinct column numbers as preselected data.
  13. 13
    The method defined in Claim 1 wherein the preselected data is selected based on a policy.
  14. 14
    The method defined in Claim 1 further comprising accepting user input specifying the policy.
  15. 15
    The method defined in Claim 14 wherein accepting user input specifying the policy comprises receiving information on a graphical user interface.
  16. 16
    The architecture defined in Claim 13 wherein the policy includes a specification of the data and a network location of the data.
  17. 17
    The architecture defined in Claim 16 wherein the specification of the data comprises a table name.
  18. 18
    The architecture defined in Claim 16 wherein the specification of the data comprises a database identifier.
  19. 19
    The architecture defined in Claim 16 wherein the network location comprises an IP address of a server.
  20. 20
    The architecture defined in Claim 19 wherein the network location comprises a server identifier.
  21. 21
    The method defined in Claim 1 wherein monitoring messages occurs at a plurality of exit points of the network.
  22. 22
    The method defined in Claim 1 further comprising:periodically querying a database;extracting copies of data base data that is to be protected;and deriving an abstract data structure based on extracted data and its location in the database.
  23. 23
    The method defined in Claim 1 further comprising sending the abstract data structure to a message monitoring system.
  24. 24
    The method defined in Claim 1 further comprising:preventing escape of messages containing preselected database content.
  25. 25
    The method defined in Claim 1 further comprising:logging messages that contain database content.
  26. 26
    The method defined in Claim 1 further comprising:reporting violations of the policy.
  27. 27
    The method defined in Claim 1 further comprising:intercepting one or more messages;and re-routing one or more messages to a new destination.
  28. 28
    An architecture comprising:a policy management system to set a policy;and a message monitoring system to implement the policy by monitoring messages electronically transmitted over a network for embedded preselected data;and performing content searches on the messages to detect the presence of the embedded preselected data using an abstract data structure derived from the preselected data.
  29. 29
    The architecture defined in Claim 28 wherein the policy includes a specification of the data and a network location of the data.
  30. 30
    The architecture defined in Claim 29 wherein the specification of the data comprises a table name.
  31. 31
    The architecture defined in Claim 29 wherein the specification of the data comprises a database identifier.
  32. 32
    The architecture defined in Claim 29 wherein the network location comprises an JP address of a server.
  33. 33
    The architecture defined in Claim 32 wherein the network location comprises a server identifier.
  34. 34
    The architecture defined in Claim 32 wherein the network location comprises a file name of columnar-formatted data.
  35. 35
    The architecture defined in Claim 28 wherein the policy management system and the message monitoring system are incorporated into the same physical system.
  36. 36
    The architecture defined in Claim 28 wherein the policy management system and the message monitoring system are incorporated into the same logical system.
  37. 37
    The architecture defined in Claim 28 wherein the policy management system and the message monitoring system do not reside on the same local area network (LAN).
  38. 38
    The architecture defined in Claim 28 wherein the policy management system and the message monitoring system reside on two distinct LANs coupled together via the Internet.
  39. 39
    A method comprising:receiving information content;detecting, in the information content, a sequence of content fragments that may contain a portion of preselected data;and determining whether a subset of content fragments within the sequence matches any sub-set of the preselected data using an abstract data structure that defines a tabular structure of the preselected data.
  40. 57
    An apparatus comprising:means for receiving information content;means for detecting, in the information content, a sequence of content fragments that may contain a portion of preselected data;and means for determining whether a subset of content fragments within the sequence matches any sub-set of the preselected data using an abstract data structure that defines a tabular structure of the preselected data.
  41. 58
    A system comprising:a memory containing an abstract data structure that defines a tabular structure of preselected data;and at least one processor coupled to the memory, the at least one processor executing a set of instructions which cause the processor to receive information content, detect, in the information content, a sequence of content fragments that may contain a portion of the preselected data, and determine whether a subset of content fragments within the sequence matches any sub-set of the preselected data using the abstract data structure.
  42. 59
    A computer readable medium that provides instructions, which when executed on a processor cause the processor to perform a method comprising:receiving information content;detecting, in the information content, a sequence of content fragments that may contain a portion of preselected data;and determining whether a subset of content fragments within the sequence matches any sub-set of the preselected data using an abstract data structure that defines a tabular structure of the preselected data.
  43. 60
    A method comprising:searching contents of a plurality of data storage media of a personal computing device for pre-selected sensitive data;and if at least a portion of the pre-selected sensitive data is detected, sending a notification of detection of the pre-selected sensitive data to a system via a network.
  44. 79
    An apparatus comprising:means for searching contents of a plurality of data storage media of a personal computing device for pre-selected sensitive data;and means for sending a notification of detection of the pre-selected sensitive data to a system via a network if at least a portion of the pre-selected sensitive data is detected.
  45. 90
    A personal computing device comprising:a plurality of storage media storing various data;and at least one processor coupled to the plurality of storage media, at least one processor executing a set of instructions which cause the processor to search contents of the plurality of data storage media for pre-selected sensitive data, and to send a notification of detection of the pre-selected sensitive data to a system via a network if at least a portion of the pre-selected sensitive data is detected.
  46. 91
    A computer readable medium that provides instructions, which when executed on a processor cause the processor to perform a method comprising:searching contents of a plurality of data storage media of a personal computing device for pre-selected sensitive data;and if at least a portion of the pre-selected sensitive data is detected, sending a notification of detection of the pre-selected sensitive data to a server via a network.
Independent claims46