| CPC G06F 21/6218 (2013.01) | 22 Claims |

|
1. A data security system for protecting private data within a database, the data security system comprising:
at least one AI-powered assistant configured to analyze available data, create a contextual framework based on a nature of a query, a persona, and a permission of a user and the at least one AI-powered assistant configured to define and analyze a task associated with a role within an organization;
the at least one AI-powered assistant configured to provide a task-specific response and action to ensure compliance with a defined operational and security protocol, including ensuring no traffic from a restricted country is allowed on a WAN interface, preventing a download of a schematic design, and blocking traffic to RFC 1918 IP addresses;
the at least one AI-powered assistant configured to interact with the user, interpret the query and provide a context-aware, personalized response;
the at least one AI-powered assistant configured to perform behavioral analysis based on a history of the user and user's associated benign or malicious behavior, determine suspicious behavior from outliers in user activity by monitoring sudden changes in an amount and type of data sought by the user, apply probabilistic reasoning to classify suspicious behavior when query patterns change in scope or frequency, maintain a complete audit trail of all data access events, and enable zero trust for data use; and
at least one data access proxy communicatively coupled with at least one private database, the at least one data access proxy further communicatively coupled with at least one server, the at least one server configured to operate the at least one data access proxy to:
a) identify the user and a request from the user to access at least one data item stored in the at least one private database;
b) validate the user and the request using the behavioral analysis and outlier detection, the validation including inspecting the user's identity, evaluating the user's activity history, evaluating permissions and restrictions associated with the user and the at least one data item, and analyzing patterns in user activity for suspicious behavior including sudden changes in the scope or the frequency of queries;
c) access the at least one private database to retrieve the at least one data item;
d) inspect one or more security attributes related to the at least one data item; and
e) transform the at least one data item based on one or more privacy rules, the transformation including: redacting information from the at least one data item, deleting information from the at least one data item, substituting information from the at least one data item with other information, adding information to the at least one data item, providing synthetic data as a private data item, and providing proxy data for the at least one data item.
|