Inferring content sensitivity from partial content matching
First Claim
1. A method comprising the steps of:
- determining content of monitored data;
determining if the monitored data content is entirely included in a first set of content associated with a first classification, and if so, then classifying the monitored data as the first classification; and
performing a first action if the monitored data is classified as the first classification, and performing a second action otherwise.
15 Assignments
0 Petitions
Accused Products
Abstract
Monitored content is analyzed to determine full and partial matches to previously classified content. Monitored content matching previously classified public content is classified as public, even if the monitored content is also found to match previously classified private content. In other words, public classification “overrides” potentially private classification. Monitored content matching only previously classified private content is classified as private. All remaining otherwise unclassified monitored content is classified as unknown. Monitored content is analyzed with respect to a session. If any content in a session is private, then the session is classified as private. If all content in a session is public, then the session is classified as public. Otherwise, the session is classified as unknown. In a related aspect, a set of policies are searched for a first match in part according to the classification, and a designated action taken if the first match is found.
-
Citations
55 Claims
-
1. A method comprising the steps of:
-
determining content of monitored data;
determining if the monitored data content is entirely included in a first set of content associated with a first classification, and if so, then classifying the monitored data as the first classification; and
performing a first action if the monitored data is classified as the first classification, and performing a second action otherwise. - View Dependent Claims (2, 3, 4)
-
-
5. A method comprising the steps of:
-
determining content of monitored data;
determining if the monitored data content is entirely included in a first set of content associated with a first classification, and if so, then classifying the monitored data as the first classification;
determining if the monitored data content is entirely included in a second set of content associated with a second classification, and if so, then classifying the monitored data as a second classification;
if the monitored data is not the first classification and the monitored data is not the second classification, then classifying the monitored data as a third classification; and
performing a first action if the monitored data is classified as the first classification, and performing a second action otherwise. - View Dependent Claims (6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21)
-
-
22. A method comprising the steps of:
-
dividing monitored data into sections;
classifying each section selectively as one of a group of classifications including a first and a second classification;
if at least one of the sections is classified as the second classification, then classifying the monitored data as the second classification;
if none of the sections are classified as the second classification, and all of the sections are classified as the first classification, then classifying the monitored data as the first classification; and
wherein classifying each section comprises if the respective section is a subset of content designated as the first classification, then classifying the respective section as the first classification, if the respective section is not a subset of content designated as the first classification, and the respective section is a subset of content designated as the second classification, then classifying the respective section as the second classification. - View Dependent Claims (23, 24, 25, 26, 27, 28)
-
-
29. A method comprising the steps of:
-
dividing monitored data into sections;
classifying each section selectively as one of a first, second, and third classification;
combining the classification of each of the sections into an overall monitored data classification; and
wherein classifying each section comprises if the section is a subset of content designated as the first classification, then classifying the section as the first classification, if the section is not a subset of content designated as the first classification, and the section is a subset of content designated as the second classification, then classifying the section as the second classification, and if the section is not classified as the first classification and the section is not classified as the second classification, then classifying the section as the third classification. - View Dependent Claims (30, 31)
-
-
32. A content appliance including:
-
a processor adapted to execute software;
a network interface coupled to the processor; and
wherein the software includes functions enabling collecting network traffic via the network interface, analyzing content of the collected traffic to determine if it is entirely included in a first set of content associated with a first classification, and if so, then classifying the collected content as the first classification, and otherwise classifying the collected content as a second classification, and performing a first action if the collected content is classified as the first classification, and performing a second action otherwise. - View Dependent Claims (33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43)
-
-
44. A content appliance including:
-
a processor adapted to execute software;
a network interface coupled to the processor; and
wherein the software includes functions enabling collecting network traffic via the network interface, analyzing content of the collected traffic to determine if it is entirely included in a first set of content associated with a first classification, and if so, then classifying the collected content as the first classification, and performing a first action if the collected content is classified as the first classification, and performing a second action otherwise. - View Dependent Claims (45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55)
-
Specification