×

Method and apparatus for automatically correlating related incidents of policy violations

  • US 9,235,629 B1
  • Filed: 06/30/2011
  • Issued: 01/12/2016
  • Est. Priority Date: 03/28/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • identifying a plurality of incidents of violations of a policy upon detecting presence of confidential information in a plurality of messages;

    storing the plurality of violation incidents of the policy in a data repository, wherein each of the plurality of violation incidents is associated with one or more message attribute values;

    receiving a user request to correlate one of the plurality of violation incidents of the policy stored in the data repository to other incidents of the plurality of violation incidents of the policy based on at least one common message attribute value;

    in response to the user request, correlating, by a processing device, a requested violation incident with the other incidents of the plurality of violation incidents of the policy based on the at least one common message attribute value of the one or more message attribute values, wherein the correlating comprises searching the data repository using the at least one common message attribute value;

    providing, for a user interface, resulting correlation information that identifies, for each of a plurality of time periods, a count of a number of incidents similar to the one of the plurality of violation incidents that occurred during a corresponding time period of the plurality of time periods; and

    providing the incidents similar to the one of the plurality of violation incidents that occurred during the corresponding time period of the plurality of time periods in response to a selection associated with the count for the corresponding time period of the plurality of time periods.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×