Risk
7/9/2009
11:33 AM
50%
50%

IBM To Patent Data Mask

Big Blue's MAGEN system uses optical character recognition to selectively scramble sensitive onscreen information such as healthcare or financial records.

IBM said Thursday that it has filed for patents on a new technology that can selectively hide data contained in files that hold sensitive information such as healthcare or financial records.

IBM's Masking Gateway for Enterprises (MAGEN) was developed in the company's labs in Haifa, Israel. Magen is the Hebrew word for "shield".

The system differs from other data masking products in that it does not make changes to the data file itself. Rather, it treats onscreen information as a picture and uses optical character recognition (OCR) technology to render parts of the image that are deemed sensitive unreadable.

"This results in an extremely fast and flexible system," IBM said. "If companies had to create and store modified copies, the process would be relatively expensive and slow," Big Blue added.

IBM said MAGEN is only at the proof-of-concept stage, but sees big potential for the technology in a business world that is becoming increasingly regulated.

For instance, the technology could be used to prevent workers at a claims processing center from viewing patient healthcare data while still being able to access the information needed to put through an insurance claim.

"MAGEN's screen masking approach eliminates the need to painstakingly tailor 'data masking' solutions to specific environments," said Haim Nelken, manager for Integration Technologies at IBM Haifa, in a statement. "The bottom line is faster performance, simpler database security, and reduced costs for protecting sensitive data," said Nelken.

IBM has filed for patents on two aspects of MAGEN. One for what the company calls "unique ways of manipulating images," and the other for a word scrambling system.

InformationWeek Analytics has published an independent analysis on data-loss prevention. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3653
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

CVE-2014-5406
Published: 2015-07-06
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, ...

CVE-2014-9737
Published: 2015-07-06
Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.

CVE-2014-9738
Published: 2015-07-06
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.

CVE-2014-9739
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report