Method for preventing data leakage and device thereof
The data leakage prevention system addresses the challenge of preventing technology leakage by employing a client device with monitoring and control modules to secure file transfers and storage via the Internet and removable media, effectively blocking unauthorized data transmission and maintaining business efficiency.
Patent Information
- Application Number
- PCT/KR2024/012569
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-26
- Filing Date
- 2024-08-22
- Publication Date
- 2025-06-12
AI Technical Summary
Existing security solutions fail to effectively prevent technology leakage while maintaining business efficiency, as they often cause work inconvenience and cannot block all types of computer files, including sensitive data like CAD and GIS, through external transfer paths.
A data leakage prevention system and method that includes a client device with modules for monitoring and controlling file transfers and storage via the Internet and removable media, using encryption and decryption techniques to secure files and prevent unauthorized transmission or storage.
The system effectively blocks technology leakage while maintaining business efficiency by securely managing all types of computer files through external transfer paths, reducing the risk of data exposure and maintaining productivity.
Smart Images

Figure KR2024012569_12062025_PF_FP_ABST
Abstract
Description
Method and device for preventing data leakage
[0001] The present disclosure relates to a method and device for preventing technology leaks via the Internet and removable media. More specifically, the present disclosure relates to a technology leak prevention solution and a device utilizing the same, which blocks files leaking outside a computer in an environment utilizing the Internet and removable media.
[0002] Leaks of industrial technology and trade secrets are occurring frequently, either intentionally or accidentally, by insiders, and the damage is concentrated in small and medium-sized enterprises. Recent technology leaks, in particular, have centered on computer programs and software source code, and 71% of recently detected technology leaks are believed to be caused by insiders.
[0003] Corporate computers are connected to networks such as the Internet and are configured to be able to connect to external storage media such as USB, so this is done through external storage media or networks such as the Internet.
[0004] Meanwhile, conventional security solutions to prevent data leaks largely include 1) information leak prevention (Data Loss Protection, DLP), 2) document security (Data Rights Management, DRM), and 3) document centralization (Enterprise Content Management, ECM). However, these solutions cause work inconvenience due to changes in the computer usage environment that follow their introduction. In addition, due to technological limitations, connections to external media are either blocked at the source or allowed only in limited ways. When such connections are allowed, they sacrifice convenience for security, such as encrypting specific (or all) types of files. However, they have a fatal flaw in that they cannot protect some important data, such as CAD and GIS. Furthermore, if the security implemented at the expense of convenience is intentionally or inadvertently circumvented to allow external access, data is exposed to the outside world.
[0005] In other words, existing methods have problems such as being unable to prevent leaks or having security solutions that reduce corporate work efficiency. To address this, a software solution is needed that can block files going out through external transfer paths (Internet services, removable media, etc.) connected to the computer while still maintaining the existing computer environment (Internet, removable media, etc.) to maintain work efficiency. This prevents data leaks of any type, including electronic documents (management, accounting, sales data, etc.) and technical data (source code, CAD, GIS, graphic data, etc.), regardless of the type, due to internal errors or intentional actions.
[0006] Ultimately, there was a need for a security method and device capable of appropriately blocking technology leakage while maintaining corporate work efficiency, but there was a problem in that conventional technology could not provide this, and the present disclosure is intended to solve this problem.
[0007] The present disclosure provides a security system and its device that can appropriately block technology leakage while maintaining the business efficiency of a company.
[0008] Another purpose of the present disclosure is to accommodate various computer usage environments of a company, thereby preventing inconvenience in work due to the introduction of security solutions and reducing work efficiency and productivity.
[0009] Another purpose of the present disclosure is to provide strong security by blocking leakage of all types of computer files, including electronic documents and specialized data, through all external transfer paths connected to the computer.
[0010] Another purpose of the present disclosure is to eliminate the risk of technology leakage due to sharing of electronic documents or specialized data through external Internet services by allowing encrypted file transmission and storage through Internet services and removable media for internal file sharing.
[0011] Another object of the present disclosure is to provide a function to encrypt and decrypt original files by inserting an encryption fingerprint for secure internal file sharing.
[0012] The purposes of the present disclosure are not limited to those mentioned above, and other purposes and advantages of the present disclosure not mentioned above can be understood through the following description and will be more clearly understood through the embodiments of the present disclosure. Furthermore, it will be readily apparent that the purposes and advantages of the present disclosure can be realized by the means and combinations thereof set forth in the claims.
[0013] One embodiment of the present disclosure provides a method for preventing technology leakage through the Internet and a removable medium and a server thereof.
[0014] One embodiment of the present disclosure may provide a data leak prevention client device. The data leak prevention client device includes a removable media file storage control module that processes file storage event information received from a removable media file storage monitoring module, determines whether to store or block a file by referring to whether the removable media is encrypted or authorized, and requests the removable media file storage monitoring module to do so; a removable media file storage monitoring module that receives a file storage event from a client operating system (OS) and transmits it to the removable media file storage control module, or receives a file storage or blocking request from the removable media file storage control module and requests the client operating system (OS) to do so; an Internet service file transfer control module that receives a file transfer event from the client operating system (OS) and transmits it to the Internet service file transfer control module, or receives a file transfer or blocking request from the Internet service file transfer control module and requests the client operating system (OS) to do so; and an Internet service file transfer monitoring module that receives a file transfer event from the client operating system (OS) and transmits it to the Internet service file transfer control module, or receives a file transfer or blocking request from the Internet service file transfer control module and requests the client operating system (OS) to do so.
[0015] In one embodiment, the data leak prevention client device may further include a file encryption module and a file decryption module.
[0016] In one embodiment, the data leak prevention client device may further include a process management module and a client communication module.
[0017] In one embodiment, the data leak prevention client device may further include a list of allowed programs and a list of running processes.
[0018] One embodiment of the present disclosure may provide a data leak prevention client server. The data leak prevention client server includes: a database; a server communication module; a user interface module; and an allowed program management module that processes allowed program information, such as program names, program types, apps, and Internet services, received from the user interface module and stores them in a database (DB) or transmits allowed program information stored in the DB to the server communication module.
[0019] One embodiment of the present disclosure may provide a method for monitoring Internet service file transfer. The method for monitoring Internet service file transfer includes the steps of: receiving computer file access event information from a client operating system (OS); transmitting the received computer file access event information to an Internet service file transfer control module; receiving a request for transmission or blocking of a file corresponding to the computer file access event information from the Internet service file transfer control module; requesting the client operating system (OS) to transmit a file corresponding to the computer file access event information when the request is a transmission request; and requesting the client operating system (OS) to block a file corresponding to the computer file access event information when the request is a blocking request.
[0020] In one embodiment, the computer file access event information may include a process ID or a file name.
[0021] One embodiment of the present disclosure may provide a method for controlling Internet service file transfer. The method includes the steps of: receiving computer file access event information from an Internet service file transfer monitoring module; obtaining a program type corresponding to a process ID of the computer file access event information by referring to a list of running processes and a list of permitted programs; reading an encrypted identification area of a file corresponding to a file name of the computer file access event information when the program type is an Internet service; requesting the Internet service file transfer monitoring module to transmit a file corresponding to the computer file access event information when the program type is not an Internet service or when the program type is an Internet service and an encrypted fingerprint exists; and requesting the Internet service file transfer monitoring module to block a file corresponding to the computer file access event information when the program type cannot be obtained or when the program type is an Internet service and an encrypted fingerprint does not exist.
[0022] In one embodiment, the computer file access event information may include a process ID or a file name.
[0023] One embodiment of the present disclosure may provide a method for monitoring storage of a removable media file. The method for monitoring storage of a removable media file includes the steps of: receiving computer file storage event information from a client operating system (OS); transmitting the received computer file storage event information to a removable media file storage control module; receiving a request for storing or blocking a file corresponding to the computer file storage event information from the removable media file storage control module; requesting the client operating system (OS) to store the file corresponding to the computer file storage event information when the request is for storing the file; and requesting the client operating system (OS) to block the file corresponding to the computer file storage event information when the request is for blocking the file.
[0024] In one embodiment, the computer file access event information may include a process ID or a file name.
[0025] One embodiment of the present disclosure may provide a method for controlling storage of a removable media file. The method includes the steps of: receiving computer file storage event information from a removable media file storage monitoring module; processing file name information of computer file storage event interception information to obtain a storage drive type; if the drive is a removable drive, performing reading of an encrypted identification area of a file corresponding to a file name of the computer file storage event information; if the drive is a removable drive and an encrypted fingerprint does not exist, requesting the removable media file storage monitoring module to block a file corresponding to the computer file storage event information; if the drive is not a removable drive or is a removable drive and an encrypted fingerprint exists, requesting the removable media file storage monitoring module to store a file corresponding to the computer file storage event information.
[0026] In one embodiment, the computer file access event information may include a process ID or a file name.
[0027] The system, device and method according to the present disclosure are effective in appropriately blocking technology leakage while maintaining the business efficiency of a company.
[0028] In addition, the system and method according to the present disclosure have the effect of not causing inconvenience in work due to solution introduction and not reducing work efficiency and productivity by accepting various computer usage environments of a company, such as the Internet and removable media file formats.
[0029] In addition, the method and device according to the present disclosure have the effect of providing strong security by blocking the leakage of all types of computer files, including electronic documents (management accounting sales data, etc.) and specialized data (source code CAD, GIS, graphic data, etc.) through all external mobile paths, Internet services, and portable media connected to a computer.
[0030] In addition, the system and method according to the present disclosure have the effect of eliminating the risk of technology leakage by sharing electronic documents or specialized data through Internet services and removable media in the form of encrypted files for internal file sharing.
[0031] In addition to the above, the specific effects of the present disclosure are described together with the specific matters for carrying out the disclosure below.
[0032] FIG. 1 is a conceptual diagram illustrating the configuration of a data leak prevention system according to one embodiment of the present disclosure.
[0033] FIG. 2 is a flowchart illustrating a method for managing an allowed program according to one embodiment of the present disclosure.
[0034] FIG. 3 is a flowchart illustrating a method for managing an allowable process according to one embodiment of the present disclosure.
[0035] FIG. 4 is a flowchart illustrating a method for monitoring Internet service file transfer according to one embodiment of the present disclosure.
[0036] FIG. 5 is a flowchart illustrating an Internet service file transfer control method according to one embodiment of the present disclosure.
[0037] FIG. 6 is a flowchart illustrating a method for monitoring storage of a removable media file according to one embodiment of the present disclosure.
[0038] FIG. 7 is a flowchart illustrating a method for controlling storage of a removable media file according to one embodiment of the present disclosure.
[0039] FIG. 8 is a flowchart illustrating a file encryption method according to one embodiment of the present disclosure.
[0040] FIG. 9 is a flowchart illustrating a file decryption method according to one embodiment of the present disclosure.
[0041] To clarify the technical idea of the present disclosure, embodiments of the present disclosure will be described in detail with reference to the attached drawings. In describing the present disclosure, if a detailed description of a related known function or component is determined to unnecessarily obscure the gist of the present disclosure, the detailed description will be omitted. Components having substantially the same functional configuration among the drawings are given the same reference numbers and symbols as possible even if they are shown in different drawings. For convenience of explanation, devices and methods are described together when necessary. Each operation of the present disclosure does not necessarily have to be performed in the described order and may be performed in parallel, selectively, or individually.
[0042] The terms used in the embodiments of this disclosure have been selected from widely used, current terms, taking into account the functions of the present disclosure. However, these terms may vary depending on the intentions of those skilled in the art, precedents, the emergence of new technologies, etc. Furthermore, in certain cases, the applicant may arbitrarily select terms, and in such cases, their meanings will be described in detail in the description of the relevant embodiments. Therefore, the terms used in this specification should not be defined simply as names of terms, but rather based on their meanings and the overall content of the present disclosure.
[0043] Throughout this disclosure, singular expressions may include plural expressions unless the context clearly dictates otherwise. Terms such as "comprise" or "have" should be understood to indicate the presence of a feature, number, step, operation, component, part, or combination thereof, but do not preclude the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof. In other words, when it is said throughout this disclosure that a part "comprises" a certain component, unless specifically stated otherwise, this does not mean that other components may be included, but rather that other components may be excluded.
[0044] Expressions such as "at least one" modify the entire list of elements, not individual elements of the list. For example, "at least one of A, B, and C" and "at least one of A, B, or C" refer to only A, only B, only C, both A and B, both B and C, both A and C, all of A, B, and C, or any combination thereof.
[0045] In addition, terms such as “...unit”, “...module”, etc. described in the present disclosure mean a unit that processes at least one function or operation, which may be implemented as hardware or software, or a combination of hardware and software.
[0046] Throughout this disclosure, when a part is said to be "connected" to another part, this includes not only cases where the parts are "directly connected," but also cases where the parts are "electrically connected" with other elements intervening. Furthermore, when a part is said to "include" a component, this does not exclude other components, but rather includes other components, unless otherwise specifically stated.
[0047] The expression “configured to” as used throughout this disclosure can be used interchangeably with, for example, “suitable for,” “having the capacity to,” “designed to,” “adapted to,” “made to,” or “capable of.” The term “configured to” does not necessarily mean something that is “specifically designed to” in terms of hardware. Instead, in some contexts, the expression “a system configured to” can mean that the system, together with other devices or components, is “capable of.” For example, the phrase “a processor configured (or set) to perform A, B, and C” may mean a dedicated processor (e.g., an embedded processor) for performing those operations, or a generic-purpose processor (e.g., a CPU or application processor) that can perform those operations by executing one or more software programs stored in memory.
[0048] Throughout this disclosure, terms including ordinal numbers, such as "first," "second," etc., may be used to describe various components, but the components are not limited by the terms. The terms are used solely to distinguish one component from another. For example, without departing from the scope of the present disclosure, a first component could be referred to as a second component, and similarly, a second component could also be referred to as a first component. The term "and / or" includes any combination of multiple related items or any one of multiple related items.
[0049] The present disclosure relates to a method and device for preventing technology leaks via the Internet and removable media. More specifically, the present disclosure relates to a data leak prevention solution and a device utilizing the same, which blocks files from leaking outside a computer in an environment utilizing the Internet and removable media.
[0050] A security method according to one embodiment of the present disclosure can detect attempts to transmit all types of computer files, such as electronic documents (management, accounting, sales data, etc.) and specialized data (source code, CAD, GIS, graphic data, etc.), to the outside, either intentionally or accidentally by an insider, and block the transmission and storage of unencrypted files. According to one embodiment, the attempted external transmission may include attempts to transfer files over the Internet or store files on removable media. For example, external movement paths may include i) electronic devices such as mobile phones, smart phones, and digital cameras; ii) removable media such as CDs, USBs, and external hard drives; iii) network services such as Internet email, webmail, web hard drives, and cloud services; and iv) communication services such as messengers and SNS.
[0051] According to one embodiment, when an attempt to transfer a file using an Internet service or to store a file on a removable medium is detected, the type of the file being transferred or stored can be checked, and if the file is encrypted, the file transfer and storage can be performed, and if the file is not encrypted, the file transfer and storage attempt can be blocked.
[0052] FIG. 1 is a conceptual diagram illustrating the configuration of a data leak prevention system according to one embodiment of the present disclosure.
[0053] Referring to FIG. 1, a data leak prevention system may be provided. According to one embodiment of the present disclosure, the data leak prevention system may include a data leak prevention client and a data leak prevention server. In one embodiment, the data leak prevention client may include application programs for data leak prevention on a client operating system (OS).
[0054] According to one embodiment, the data leak prevention client may include a file encryption module and a file decryption module for encrypting and decrypting computer files, a removable media file storage control module and a removable media file storage monitoring module for monitoring file leaks through removable media, and an Internet service file transfer control module and an Internet service file transfer monitoring module for monitoring file leaks using Internet services. In addition, the data leak prevention client may store a list of allowed programs and a list of running processes, and may include a process management module, a user interface module, and a client communication module. For example, the data leak prevention client may be composed of one or more computing devices and may include various user terminals.
[0055] In one embodiment, the data leak prevention server may include a database (DB), a user interface module, an authorized program management module, and a server communication module. For example, the data leak prevention server may be comprised of one or more computing devices and implemented using various computing technologies, including cloud and virtual servers.
[0056] According to one embodiment of the present disclosure, the user interface module receives information about permitted apps or Internet services from a user and transmits the information to the permitted app and Internet service management module. The permitted program management module processes the permitted program information, such as program name, program type, app, and Internet service, received from the user interface module and stores the information in a database (DB) or transmits the permitted program information stored in the DB to the server communication module. The server communication module may receive the permitted program information from the permitted program management module and transmit it to the client communication modules of all data leak prevention clients.
[0057] According to one embodiment, the client communication module receives information on allowed programs from the server communication module of the data leak prevention server. The process management module receives information on allowed programs from the client communication module to configure a list of allowed programs and acquires information on running processes from the client operating system (OS) to configure a list of running processes. The Internet service file transfer monitoring module receives file transfer events from the client operating system (OS) and forwards them to the Internet service file transfer control module, or receives a request for file transfer or blocking from the Internet service file transfer control module and requests the client operating system (OS). The Internet service file transfer control module processes the file transfer event information received from the Internet service file transfer monitoring module and determines whether to transfer or block files based on whether the list of running processes and the list of allowed programs are encrypted or approved, and requests the Internet service file transfer monitoring module to do so. The removable media file storage monitoring module receives a file storage event from the client operating system (OS) and forwards it to the removable media file storage control module, or receives a request for file storage or blocking from the removable media file storage control module and requests the client operating system (OS). The removable media file storage control module processes file storage event information received from the removable media file storage monitoring module, determines whether to store or block files based on whether the removable media is encrypted or authorized, and can request the removable media file storage monitoring module to do so.
[0058] In one embodiment, the user interface module serves to provide the user with information about files that have been blocked from being transmitted or stored by the Internet service file transfer control module and the removable media file storage control module. The file encryption module serves to encrypt a file selected by the user using the AES 128 symmetric key method and insert an encryption identification fingerprint to create an encrypted file. The file decryption module serves to verify and remove the encryption identification fingerprint of the encrypted file selected by the user and create a file decrypted using the AES 128 symmetric key method. Meanwhile, the AES 128 symmetric key method is only an example, and the algorithms available to the file encryption module and the file decryption module are not limited thereto.
[0059] According to one embodiment of the present disclosure, a method for blocking file transfers to an Internet service may include functions for managing permitted programs, managing permitted processes, monitoring Internet service file transfers, and controlling Internet service file transfers. In one embodiment, a method for blocking file transfers to a removable medium may include functions for monitoring removable medium file storage and controlling removable file transfers. In one embodiment, a method for blocking file transfers may include file encryption and file decryption.
[0060] FIG. 2 is a flowchart illustrating a method for managing an allowed program according to one embodiment of the present disclosure.
[0061] Referring to FIG. 2, a method for managing permitted programs may be provided. According to one embodiment of the present disclosure, the method for managing permitted programs may include: receiving permitted program information (program name, program type, etc.) from a user; storing permitted program information (program name, program type, etc.) from the user in a database (DB); and transmitting permitted program information (program name, program type, etc.) to all connected clients.
[0062] In one embodiment, a method for managing permitted programs may include the steps of: receiving a request for permitted program information (program name, program type, etc.) from a client; searching for permitted program information (program name, program type, etc.) in a database (DB); and transmitting permitted program information (program name, program type, etc.) to the requesting client.
[0063] FIG. 3 is a flowchart illustrating a method for managing an allowable process according to one embodiment of the present disclosure.
[0064] Referring to FIG. 3, a method for managing permitted processes may be provided. According to one embodiment of the present disclosure, the method for managing permitted processes may include: acquiring information on all running processes from a client operating system (OS); adding the acquired information on all running processes (process ID, process name, etc.) to a list of running processes; and requesting information on permitted programs (program name, program type, etc.) from a server.
[0065] According to one embodiment, the method for managing permitted processes may further include: receiving a process start event from a client operating system (OS); adding the received process start event information (process ID, process name, etc.) to a list of running processes; and updating the list of running processes (process ID, process name, etc.).
[0066] According to one embodiment, the method for managing permitted processes may further include the steps of: receiving permitted program information from a server; adding the received permitted program information (program name, program type, etc.) to a list of permitted programs; and updating the list of permitted programs (program name, program type, etc.).
[0067] FIG. 4 is a flowchart illustrating a method for monitoring Internet service file transfer according to one embodiment of the present disclosure.
[0068] Referring to FIG. 4, a method for monitoring Internet service file transfers may be provided. According to one embodiment of the present disclosure, the method for monitoring Internet service file transfers may include the steps of receiving computer file access event information from a client operating system (OS); and transmitting the received computer file access event information (process ID, file name, etc.) to an Internet service file transfer control module.
[0069] According to one embodiment, an Internet service file transfer monitoring method may include the steps of: receiving a request for transfer or blocking a file corresponding to computer file access event information (process ID, file name, etc.) from an Internet service file transfer control module; (in the case of a transfer request) requesting transfer of a file corresponding to the computer file access event information (process ID, file name, etc.) to a client operating system (OS); and (in the case of a block request) requesting blocking of a file corresponding to the computer file access event information (process ID, file name, etc.) to the client operating system (OS).
[0070] FIG. 5 is a flowchart illustrating an Internet service file transfer control method according to one embodiment of the present disclosure.
[0071] Referring to FIG. 5, a method for controlling Internet service file transfer may be provided. According to one embodiment of the present disclosure, the method may include: receiving computer file access event information (process ID, file name, etc.) from an Internet service file transfer monitoring module; obtaining a program type corresponding to the process ID of the computer file access event information by referring to a list of running processes and a list of allowed programs; (if the program type is an Internet service) reading an encrypted identification area of a file corresponding to the file name of the computer file access event information; (if the program type is not an Internet service, or if the program type is an Internet service and an encrypted fingerprint exists) requesting the Internet service file transfer monitoring module to transfer a file corresponding to the computer file access event information (process ID, file name, etc.); (if the program type cannot be obtained, or if the program type is an Internet service and an encrypted fingerprint does not exist) requesting the Internet service file transfer monitoring module to block a file corresponding to the computer file access event information (process ID, file name, etc.).
[0072] FIG. 6 is a flowchart illustrating a method for monitoring storage of a removable media file according to one embodiment of the present disclosure.
[0073] Referring to FIG. 6, a method for monitoring removable media file storage may be provided. According to one embodiment of the present disclosure, the method for monitoring removable media file storage may include: receiving computer file storage event information from a client operating system (OS); and transmitting the received computer file storage event information (process ID, file name, etc.) to a removable media file storage control module. In one embodiment, the method may include: receiving a request for storing or blocking a file corresponding to the computer file storage event information (process ID, file name, etc.) from the removable media file storage control module; (in the case of a request for storing a file) requesting the client operating system (OS) to store a file corresponding to the computer file storage event information (process ID, file name, etc.); and (in the case of a request for blocking a file) requesting the client operating system (OS) to block a file corresponding to the computer file storage event information (process ID, file name, etc.).
[0074] FIG. 7 is a flowchart illustrating a method for controlling storage of a removable media file according to one embodiment of the present disclosure.
[0075] Referring to FIG. 7, a method for controlling storage of a removable media file may be provided. According to one embodiment of the present disclosure, the method for controlling storage of a removable media file may include: receiving computer file storage event information (process ID, file name, etc.) from a removable media file storage monitoring module; processing file name information of computer file storage event interception information to obtain a storage drive type; (in the case of a removable drive) performing reading of an encrypted identification area of a file corresponding to the file name of the computer file storage event information; (in the case of a removable drive and no encrypted fingerprint) requesting blocking of a file corresponding to the computer file storage event information (process ID, file name, etc.) to the removable media file storage monitoring module; (in the case of a non-removable drive or a removable drive and an encrypted fingerprint) requesting storage of a file corresponding to the computer file storage event information (process ID, file name, etc.) to the removable media file storage monitoring module.
[0076] FIG. 8 is a flowchart illustrating a file encryption method according to one embodiment of the present disclosure.
[0077] Referring to FIG. 8, a file encryption method may be provided. According to one embodiment of the present disclosure, the file encryption method may include the steps of: receiving a request for encryption of a selected computer file from a user; and the steps of inserting a specific fingerprint into a variable encryption identification area and encrypting the selected computer file using an AES 128 symmetric key method to generate an attached encrypted file.
[0078] FIG. 9 is a flowchart illustrating a file decryption method according to one embodiment of the present disclosure.
[0079] Referring to FIG. 9, a method for decrypting a file may be provided. According to one embodiment of the present disclosure, the method for decrypting a file may include: receiving a request for decryption of a selected computer file from a user; performing a reading of an encrypted identification area of the selected computer file; and generating a file decrypted using an AES 128 symmetric key method (if a specific fingerprint exists) of an encrypted file of the selected computer file.
[0080] The above description is merely an example of the technical idea of the present embodiment, and those skilled in the art will appreciate that various modifications and variations can be made without departing from the essential characteristics of the present embodiment. Therefore, the present embodiments are not intended to limit the technical idea of the present embodiment, but rather to explain it, and the scope of the technical idea of the present embodiment is not limited by these embodiments. The scope of protection of the present embodiment should be interpreted by the claims below, and all technical ideas within a scope equivalent thereto should be interpreted as being included in the scope of rights of the present embodiment.
[0081] [Explanation of symbols]
[0082] 100: Data Leakage Prevention Client
[0083] 110: Computer files
[0084] 115: File encryption module
[0085] 117: File Decryption Module
[0086] 120: Removable Media File Storage Control Module
[0087] 125: Removable Media File Storage Monitoring Module
[0088] 130: User Interface Module
[0089] 140: Internet Service File Transfer Control Module
[0090] 145: Internet Service File Transfer Monitoring Module
[0091] 150: Client operating system
[0092] 160: List of allowed programs
[0093] 165: List of running processes
[0094] 170: Process Management Module
[0095] 180: Client Communication Module
[0096] 200: Data Leakage Prevention Server
[0097] 210: Database
[0098] 220: User Interface Module
[0099] 230: Permitted Program Management Module
[0100] 240: Server Communication Module
[0101] 250: Server operating system
[0102] 300: Internet
Claims
1. For data leakage prevention client devices, A removable media file storage control module that processes file storage event information received from a removable media file storage monitoring module, determines whether to store or block files by referring to whether the removable media is encrypted or approved, and requests the removable media file storage monitoring module to do so; A removable media file storage monitoring module that receives a file storage event from a client operating system (OS) and forwards it to the removable media file storage control module, or receives a file storage or blocking request from the removable media file storage control module and requests the client operating system (OS); An Internet service file transfer control module that receives a file transfer event from a client operating system (OS) and forwards it to the Internet service file transfer control module or receives a file transfer or blocking request from the Internet service file transfer control module and requests it to the client operating system (OS); and Including an Internet service file transfer monitoring module that receives a file transfer event from a client operating system (OS) and forwards it to an Internet service file transfer control module or receives a file transfer or blocking request from the Internet service file transfer control module and requests it to the client operating system (OS). Data leak prevention client device.
2. In paragraph 1, The above data leak prevention client device, Further comprising a file encryption module and a file decryption module, Data leak prevention client device.
3. In paragraph 1, The above data leak prevention client device, Further including a process management module and a client communication module; Data leak prevention client device.
4. In paragraph 1, The above data leak prevention client device, Includes a list of allowed programs and a list of running processes. Data leak prevention client device.
5. For data leak prevention servers, database; Server communication module; User interface module; and A permission program management module that processes permission program information, such as program name, program type, app, and internet service, received from a user interface module and stores it in a database (DB) or transmits permission program information stored in the DB to a server communication module; Data leak prevention server.
6. As a method for monitoring Internet service file transfer, Step of receiving computer file access event information from a client operating system (OS); A step of transmitting received computer file access event information to an Internet service file transfer control module; A step of receiving a request for transmission or blocking of a file corresponding to computer file access event information from an Internet service file transfer control module; In case of a transfer request, a step of requesting transfer of a file corresponding to computer file access event information to the client operating system (OS); In the case of a blocking request, it includes a step of requesting blocking of a file corresponding to computer file access event information with the client operating system (OS). How to monitor Internet service file transfers.
7. In paragraph 6, The above computer file access event information includes a process ID or file name. How to monitor Internet service file transfers.
8. As a method for controlling Internet service file transfer, A step of receiving computer file access event information from an Internet service file transfer monitoring module; A step of obtaining a program type corresponding to the process ID of the computer file access event information by referring to the list of running processes and the list of allowed programs; If the program type is an Internet service, a step of performing reading of the encrypted identification area of the file corresponding to the file name of the computer file access event information; A step of requesting the transfer of a file corresponding to computer file access event information to the Internet service file transfer monitoring module, if the program type is not an Internet service, or if the program type is an Internet service and an encryption fingerprint exists; Including a step of requesting blocking of a file corresponding to computer file access event information by the Internet service file transfer monitoring module, if the program type cannot be obtained or the program type is an Internet service and an encryption fingerprint does not exist. Method for controlling Internet service file transfer.
9. In paragraph 8, The above computer file access event information includes a process ID or file name. Method for controlling Internet service file transfer.
10. As a method for monitoring the storage of mobile media files, A step of receiving computer file storage event information from a client operating system (OS); A step of transmitting the received computer file storage event information to the removable media file storage control module; A step of receiving a request for storing or blocking a file corresponding to computer file storage event information from a removable media file storage control module; In the case of a file storage request, a step of requesting the storage of a file corresponding to the computer file storage event information to the client operating system (OS); and In the case of a request for blocking a file, the step of requesting blocking of a file corresponding to the computer file storage event information to the client operating system (OS) is included. How to monitor storage of removable media files.
11. In paragraph 10, The above computer file access event information includes a process ID or file name. How to monitor storage of removable media files.
12. As a method for controlling storage of a mobile media file, A step of receiving computer file storage event information from a removable media file storage monitoring module; A step of obtaining a storage drive type by processing file name information of computer file storage event interception information; In case of a removable drive, a step of reading the encrypted identification area of the file corresponding to the file name of the computer file storage event information; If it is a removable drive and there is no encryption fingerprint, a step of requesting blocking of a file corresponding to computer file storage event information by the removable media file storage monitoring module; Including a step of requesting storage of a file corresponding to computer file storage event information by a removable media file storage monitoring module, if the drive is not a removable drive or is a removable drive and has an encryption fingerprint; Method for controlling storage of removable media files.
13. In paragraph 10, The above computer file access event information includes a process ID or file name. Method for controlling storage of removable media files.
Citation Information
Patent Citations
Method for preventing outflow of attached file information based on agent
KR100901356B1
Method and Apparatus for file maintain using content inspection based
KR101278317B1
Method for preventing data loss, server apparatus, client apparatus
KR101482903B1
Security management system for portable memory devices and security management method using the same
KR1020090050266A
USB memory management system
KR1020090062199A