Data exfiltration detection system

The application-level data leak detection system addresses resource-intensive kernel-level issues by detecting leaks through networks and peripherals with minimal impact, ensuring stable and efficient data security.

WO2025254246A1PCT designated stage Publication Date: 2025-12-11SIOT
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/008277
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-04
Filing Date
2024-06-17
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing data leak detection systems often operate at the kernel level, causing collisions and interference with other programs and require significant memory and CPU usage, while information leaks pose a significant threat due to hacking and unauthorized data access.

Method used

A data leak detection system operating at the application level, utilizing a management server and user terminal to detect leaks through various channels, including networks and peripherals, with minimal memory and CPU usage, providing real-time tracking and immediate file viewing capabilities.

Benefits of technology

Prevents collisions with other programs, uses minimal resources, and offers real-time leak detection and immediate file access, enhancing user trust and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024008277_11122025_PF_FP_ABST
    Figure KR2024008277_11122025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a data exfiltration detection system, comprising a management server that detects exfiltration attempts over a network, wherein the data exfiltration detection system is operated at the application level rather than the Kernel level to prevent collision and interference with other programs, and may use a memory with an average CPU usage rate as low as 0%.
Need to check novelty before this filing date? Find Prior Art

Description

Data Leak Detection System

[0001] The present invention relates to a data leak detection system.

[0002] Information leaks account for the second largest percentage of breaches, at 29%.

[0003] There are also records of the hacking group Lapsus$ successfully attacking domestic and foreign companies and stealing confidential information, and Infostealer3, an information-stealing malware targeting personal and corporate information, is on the rise.

[0004] Additionally, the stolen information is being used for secondary attacks, and personal information transactions through black markets such as the dark web are becoming active, with blog accounts being traded for as much as 15 million won.

[0005] Meanwhile, the background technology described above is technical information that the inventor possessed for the purpose of deriving the present invention or acquired in the process of deriving the present invention, and cannot necessarily be said to be publicly known technology disclosed to the general public prior to the application for the present invention.

[0006] The purpose of the present invention is to provide a data leak detection system that operates at the application level rather than the kernel level to prevent collisions and interference with other programs and uses a small amount of memory with an average CPU usage rate of 0%.

[0007] The technical problems of the present invention are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art from the description below.

[0008] A data leak detection system according to one embodiment of the present invention may include a management server that detects a leak through a network.

[0009] According to one embodiment, a data leak detection system may further include a user terminal in which a leak is detected by the management server; and a monitoring server that outputs real-time tracking results for leak detection and aggregated information leak status through the management server.

[0010] According to one embodiment, the management server may include a network leak detection unit that detects leaks through a network including a web browser, an Internet messenger, a cloud client, Windows sharing, a work management collaboration tool, remote access, Outlook, FTP, a malware network printer, and an unauthorized network, and detects all leaked files regardless of the encryption and encoding method and the type of protocol; a peripheral leak detection unit that detects leaks through PC peripherals including a Bluetooth device or a removable storage medium such as a USB or CDROM, and detects all leaked files regardless of the encryption and encoding method and the type of protocol; a leak detection extraction unit that checks whether personal information and important keywords are included in the leaked file and monitors important information in the leaked file when information leaks are detected by the network leak detection unit and the peripheral leak detection unit; and a function providing unit that includes a GUI function, a utility function, and a self-security function.

[0011] According to one embodiment, the network leak detection unit, when information leak is detected through a network, stores a PC name, a Process name, a Process ID, a source IP / Port, a destination IP / Port, web browser URL information, a screen capture at the moment of leak, a leaked file path name, a copy of the leaked file, and a file size; when information leak is detected through Outlook sending history, stores a PC name, a Process name, a Process ID, an email subject, sender / recipient email addresses, a copy of the attached file, and a file size; when information leak is detected through a medium, stores a PC name, a Process name, a Process ID, a medium type, a leaked file path name, a copy of the leaked file, and a file size; and when information leak is detected through a network printer, stores a PC name, a Process name, a Process ID, a printer name, a printed document name, a printing owner, a spool file name, a size, and a printed file.

[0012] According to one embodiment, the network leak detection unit and peripheral device leak detection unit may provide URL information when a leak is detected through a web browser, provide a screen dump at the moment of the leak, and provide a function for immediate downloading and viewing of leaked files.

[0013] According to one embodiment, the network leak detection unit may determine whether to perform a check for leak detection using the following [mathematical formula] based on a preset inspection period, the number of times a leak is detected through the network, the number of times a leak is detected through the Outlook sending history, the number of times a leak is detected through the medium, and the number of times a leak is detected through the network printer.

[0014] [Mathematical formula]

[0015]

[0016] (P srefers to the inspection period of the preset network leak detection unit, and D n means the number of times a leak was detected through the network, and D o refers to the number of times information leakage was detected through Outlook sending history, and D m D refers to the number of times information leakage through the media was detected. mv refers to the number of times information leakage through network printers was detected, and I r refers to a numerical value that serves as a standard for determining the inspection of the network leak detection unit.)

[0017] According to one aspect of the present invention described above, the data leak detection system proposed by the present invention operates at the application level rather than the kernel level, thereby preventing collisions and interference with other programs, and can use less memory with an average CPU usage rate of 0%.

[0018] In addition, the data leak detection system proposed by the present invention can provide URL information when a leak is detected through a web browser by an application installed on a user terminal, provide a screen dump at the moment of the leak, and provide a function for immediate downloading and viewing of the leaked file.

[0019] Additionally, it can increase trust with users by providing information related to leaks to administrators or users by outputting real-time tracking results for leak detection and aggregated information on information leaks.

[0020] The effects of the present invention are not limited to the effects mentioned above, and various effects may be included within a range obvious to those skilled in the art from the contents described below.

[0021] FIG. 1 is a conceptual diagram of a data leak detection system according to one embodiment of the present invention.

[0022] Figure 2 is a conceptual diagram of a management server according to one embodiment of the present invention.

[0023] The detailed description of the present invention, which follows, refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be implemented in other embodiments without departing from the spirit and scope of the present invention.

[0024] When it is said that a component is "connected" or "fastened" to another component, it should be understood that it may be directly connected or fastened to that other component, but that there may be other components in between. Conversely, when it is said that a component is "directly connected" or "fastened" to another component, it should be understood that there are no other components in between.

[0025] Furthermore, it should be understood that the location or arrangement of individual components within each disclosed embodiment may be modified without departing from the spirit and scope of the present invention. Therefore, the following detailed description is not intended to be limiting, and the scope of the present invention, if properly described, is defined solely by the appended claims, along with the full scope equivalents thereof. Similar reference numerals in the drawings designate the same or similar functions throughout.

[0026] Hereinafter, preferred embodiments of the present invention will be described in more detail with reference to the drawings.

[0027]

[0028] FIG. 1 is a conceptual diagram of a data leak detection system according to one embodiment of the present invention.

[0029] Figure 1 is a conceptual diagram of a system according to one embodiment of the present invention.

[0030] Referring to FIG. 1, a data leak detection system according to one embodiment of the present invention may include a management server (100), a monitoring server (300), and a user terminal (500).

[0031] The management server (100) detects leakage through a network according to the present invention and can monitor events occurring at the kernel (operating system) level.

[0032] The user terminal (500) can detect leakage behavior by the management server (100).

[0033] The monitoring server (300) can output real-time tracking results for leak detection and aggregated information leak status through the management server (100).

[0034] The management server (100), monitoring server (300), and user terminal (500) may be their own servers or cloud servers for providing services according to the present invention, or may be a p2p (peer-to-peer) collection of distributed nodes.

[0035] The management server (100) can perform one or more of the operations, storage, reference, input / output, and control functions of a general computer, and can include an artificial neural network, which will be described later, based on input data.

[0036] The management server (100) may include a processor and memory. The processor may detect network leakage according to the present invention and may include devices capable of performing the detection. The processor may also execute programs or control the management server (100). Program code executed by the processor may be stored in memory. The memory may store relevant information for performing services according to the present invention or a program for implementing a method. The memory may be volatile or non-volatile memory.

[0037] The management server (100) can transmit data to an external device or receive data from an external device using a network.

[0038] The management server (100) can train an artificial neural network and utilize a trained artificial neural network. The processor can train or execute an artificial neural network stored in memory, and the memory can store a trained artificial neural network. The electronic device that trains the artificial neural network and the electronic device that utilizes the artificial neural network may be the same or separate.

[0039] Artificial intelligence (AI) is a computer system that embodies some of the functions of the human brain, capable of learning, making inferences, and making judgments on its own. As learning progresses, the probability of extracting answers increases. AI can be comprised of learning and the underlying technologies that utilize it. AI learning is an algorithmic technology that classifies and learns features based on input data, while the underlying technologies can utilize learning algorithms to partially emulate the functions of the human brain.

[0040] AI is a technology that easily approaches problems with multiple probabilistic answers, enabling it to logically and probabilistically infer optimal cycles, methods, and plans based on input data. AI inference techniques can include evaluating input data, making optimal predictions, knowledge- and probability-based inferences, and preference-based planning.

[0041] An artificial neural network (ANN) is a learning algorithm in the field of machine learning. It implements the connections between neurons and synapses in the brain through a program. An ANN can be programmed to create a neural network structure and then train it to achieve a desired function. While errors may exist, it can learn from massive amounts of data, producing appropriate output data based on input data. Its advantages include the ability to obtain output data that yields statistically positive results and its resemblance to human reasoning.

[0042] The management server (100) can infer individual characteristics and interests by analyzing consumers' online behavior data, social media activities, search history, etc. using an artificial intelligence algorithm built on big data, and for this purpose, can include a number of pre-learned artificial neural networks.

[0043] A network is a high-speed backbone network of a large communications network capable of providing large-capacity, long-distance voice and data services, and may be a next-generation wired or wireless network to provide the Internet or high-speed multimedia services.

[0044] If the network is a mobile communication network, it may be a synchronous mobile communication network or an asynchronous mobile communication network. An example of an asynchronous mobile communication network is a Wideband Code Division Multiple Access (WCDMA) network. In this case, although not shown in the diagram, the network may include a Radio Network Controller (RNC). While a WCDMA network is mentioned as an example, it could also be a 3G LTE network, a 4G network, a next-generation communication network such as 5G, or any other IP-based network.

[0045] The management server (100), monitoring server (300), and user terminal (500) may include any terminal capable of exchanging data via a network, such as a desktop computer, laptop, tablet, or smartphone.

[0046] The management server (100), monitoring server (300), and user terminal (500) may include at least one of the computational function, storage function, reference function, input / output function, and control function of a computer to perform the service according to the present invention.

[0047] The management server (100), monitoring server (300), and user terminal (500) can access a website or install an application to receive services according to the present invention. The management server (100) and user terminal (500) can exchange data via the website or application.

[0048] A network is a high-speed backbone network of a large communications network capable of providing large-capacity, long-distance voice and data services, and may be a next-generation wired or wireless network to provide the Internet or high-speed multimedia services.

[0049] If the network is a mobile communication network, it may be a synchronous mobile communication network or an asynchronous mobile communication network. An example of an asynchronous mobile communication network is a Wideband Code Division Multiple Access (WCDMA) network. In this case, although not shown in the drawing, the network (300) may include a Radio Network Controller (RNC). While a WCDMA network is mentioned as an example, it may also be a 3G LTE network, a 4G network, a next-generation communication network such as 5G, or another IP-based network.

[0050] A system (1) according to one embodiment of the present invention can detect all leakage activities through a network (TCP, UDP), log documents printed by a network printer, operate at an application level to prevent conflicts and interference with other programs, and use a small amount of memory with an average CPU usage rate of 0%.

[0051] That is, the system proposed by the present invention operates at the application level rather than the kernel level, so there is no conflict or interference with other programs, and since it operates only at the application level, when a problem occurs, the impact can be limited to its own process.

[0052] Additionally, stability can be guaranteed by excluding kernel level execution.

[0053] If a leak is detected through a web browser by an application installed on the user's terminal, URL information can be provided, a screen dump can be provided at the moment of the leak, and a function to immediately download and view the leaked file can be provided.

[0054] An example of a leak case to which the management server (100) according to one embodiment of the present invention is applied will be described below.

[0055] First, the leak case is a case where data was leaked even though storage in a USB memory was controlled by a media control solution. The management server (100) according to one embodiment of the present invention connects a work PC and a personal PC with a UTP cable or wirelessly using a USB wireless LAN card, and can detect that files have been leaked from the work PC using Windows sharing and remote desktop.

[0056] Second, the leak case is a case where data was leaked even though storage to a USB memory was controlled by a media control solution. The management server (100) according to one embodiment of the present invention can detect that desired data was leaked to a USB by writing a program that copies a specific file to a USB with the same executable file name and location as an antivirus, and exploiting the fact that the media control allows modification and writing of USB files to a known antivirus.

[0057] The third leak case is a case where data was leaked even though the file attachment function of a web browser was controlled by Endpoint DLP. The management server (100) according to one embodiment of the present invention can detect that data was leaked by attaching a file using a web browser in which the file attachment function is blocked by MS Edge, IExplorer, and Chrome, but an uncontrollable web browser is installed arbitrarily and the use of the file attachment function is not controlled.

[0058] The fourth leak case is a case where data was leaked even though file encryption and network access control were being performed on the PC with DRM and network DLP. The management server (100) according to one embodiment of the present invention can detect that data was leaked through an Internet route (VPN, etc.) that network DLP cannot control, as most word processors such as MS-Office create temporary files when opening files for editing, and the temporary files do not have DRM applied, and the temporary files have DRM applied to them.

[0059] Meanwhile, the monitoring server (300) can determine whether to perform an inspection using [Mathematical Formula 1] below based on the accuracy of the real-time tracking results, the time required to calculate the aggregate status of information leakage, and the number of times communication with the management server (100) was delayed.

[0060] [Mathematical Formula 1]

[0061]

[0062] Here, T a may mean the accuracy of real-time tracking results provided by the monitoring server (300), and T c may mean the time taken by the monitoring server (300) to calculate the aggregate status of information leakage, and N d may mean the number of times communication with the management server (100) was delayed, may mean a numerical value that serves as a criterion for determining inspection of the monitoring server (300).

[0063] For example, T a is 8, T c is 0.5 (30 minutes), N d If is 2, I m-s can be calculated as 0.71, and T a is 4, T c is 0.16 (10 minutes), N d If is 5, I m-s can be calculated as 0.5.

[0064] Here, I to check the monitoring server (300) m-s The exact criteria for the resulting values ​​can be determined by the user.

[0065] In the two examples described above, if the calculated value is lower in the second example than in the first example, the probability that the user will check the monitoring server (300) may increase if the calculated value is lower in the second example than in the first example.

[0066] Meanwhile, the management server (100) can determine the overall satisfaction level of the user using the data leak detection system proposed by the present invention from the value calculated from [Mathematical Formula 2] below.

[0067] More specifically, the management server (100) can calculate the overall satisfaction level using [Mathematical Formula 2] below based on the detection rate of information leakage through the network leakage detection unit and the peripheral device leakage detection unit, the accuracy of information leakage detection through the network leakage detection unit and the peripheral device leakage detection unit, and the satisfaction level of monitoring through the monitoring server (300).

[0068] [Equation 2]

[0069]

[0070] Here, S r It can mean the detection rate of information leakage through the network leakage detection unit and peripheral device leakage detection unit, and S a It can mean the accuracy of information leak detection through network leak detection unit and peripheral device leak detection unit, and S m may mean the satisfaction level of monitoring through the monitoring server, and S may mean the overall satisfaction level of the user using the data leak detection system proposed by the present invention.

[0071] For example, S r is 8, S a is 8, S m If is 9, S can be calculated as 8.3, and S r is 5, S a is 2, S m If is 5, S can be calculated as 4.5.

[0072] Here, the higher the overall satisfaction of the user using the data leak detection system proposed by the present invention, the higher the satisfaction can be judged to be.

[0073] In the two examples described above, the calculated value for the second example is lower than that for the first example, and if the calculated value for the second example is lower than that for the first example, the satisfaction level may be judged to be lower, and accordingly, the manager managing the data leak detection system proposed by the present invention may take measures such as inspecting the entire system.

[0074]

[0075] Figure 2 is a conceptual diagram of a management server according to one embodiment of the present invention.

[0076] Referring to FIG. 2, a management server (100) according to one embodiment of the present invention may include a network leak detection unit (110), a peripheral device leak detection unit (130), a leak detection extraction unit (150), and a function providing unit (170).

[0077] The network leak detection unit (110) detects leaks through networks including web browsers, Internet messengers, cloud Cilent, Windows sharing, work management collaboration tools, remote access, Outlook, FTP, malware network printers, and unauthorized networks, and can detect all leaked files regardless of encryption and encoding methods and protocol types.

[0078] In addition, when information leakage through the network is detected, the network leak detection unit (110) can store the PC name, Process name, Process ID, source IP / Port, destination IP / Port, web browser URL information, screen capture at the moment of leakage, leaked file path name, leaked file copy, and file size.

[0079] In addition, when information leakage is detected through Outlook sending history, the network leak detection unit (110) can store the PC name, process name, process ID, mail title, sender and recipient email addresses, attached file copy, and file size.

[0080] In addition, when information leakage through a medium is detected, the network leak detection unit (110) can store the PC name, process name, process ID, medium type, leaked file path name, leaked file copy, and file size.

[0081] In addition, when information leakage through a network printer is detected, the network leak detection unit (110) can store the PC name, Process name, Process ID, printer name, print document name, print owner, spool file name, size, and print file.

[0082] Meanwhile, the network leak detection unit (110) can determine whether to perform a leak detection inspection using [Mathematical Formula 3] below based on the preset inspection period, the number of times a leak is detected through the network, the number of times a leak is detected through the Outlook sending history, the number of times a leak is detected through the medium, and the number of times a leak is detected through the network printer.

[0083] [Equation 3]

[0084]

[0085] P S may refer to the inspection period of the preset network leak detection unit, and D n can mean the number of times a leak was detected through the network, and D o can mean the number of times information leakage was detected through Outlook sending history, and D m can mean the number of times information leakage through the media is detected, and D mp can mean the number of times information leakage through a network printer was detected, and I r It may mean a numerical value that serves as a standard for determining the inspection of the network leak detection unit.

[0086] For example, P S is 5, D n is 7, D ois 6, D m Silver 7, D mp If is 8, I r can be calculated as 0.025, and P S is 3, D n is 3, D o is 2, D m Silver 2, D mp If is 2, I r can be calculated as 0.43, and the resulting I r The lower the value is calculated, the higher the probability of checking the network leak detection unit (110).

[0087] Here, I to check the network leak detection unit (110) r The exact criteria for the resulting values ​​can be determined by the user.

[0088] In the two examples described above, if the calculated value is lower in the first example than in the second example, and if the calculated value is similar to the first example than in the second example, the user may have a higher probability of checking the network leak detection unit (110).

[0089] The peripheral device leak detection unit (130) detects leaks through PC peripherals including Bluetooth devices or removable storage media such as USB and CDROM, and can detect all leaked files regardless of encryption and encoding method or protocol type.

[0090] The above-described network leak detection unit (110) and peripheral device leak detection unit (130) can provide URL information when a leak is detected through a web browser, provide a screen dump at the moment of the leak, and provide a function for immediate downloading and viewing of leaked files.

[0091] When information leakage is detected by the network leakage detection unit and the peripheral device leakage detection unit, the leakage detection extraction unit (150) can check whether the leaked file contains personal information and important keywords, and monitor important information in the leaked file.

[0092] The function providing unit (170) may include GUI functions, utility functions, and self-security functions.

[0093] To explain in more detail the functions included in the above-described function provision unit (170), the GUI function may include a function that provides a KPI dashboard screen and a scoring-based leak risk analysis function.

[0094] In addition, the utility functions included in the above-described function provision unit (170) may include functions for automatically updating the Agent through a copy of the leaked file and saving the screen at the moment of leak, extracting personal information patterns and important keywords from the leaked file, providing web browser URL information in case of web leak, setting a detection exception band, and distributing an update file.

[0095] In addition, the self-security function included in the above-described function provision unit (170) may include differentially granting authority to each account according to the user's work, providing a view with a specific IP band restriction to each account, providing an audit log, and providing a web browser UI session timeout function.

[0096]

[0097] The embodiments described above are provided for illustrative purposes only, and those skilled in the art will readily appreciate that the embodiments described above can be readily modified into other specific forms without altering the technical concepts or essential characteristics of the embodiments described above. Therefore, the embodiments described above should be understood as illustrative in all respects and not restrictive. For example, components described as being single may be implemented in a distributed manner, and similarly, components described as being distributed may be implemented in a combined manner.

[0098]

[0099] The scope of protection sought through this specification is indicated by the claims described below rather than by the detailed description, and should be interpreted to include all changes or modifications derived from the meaning and scope of the claims and their equivalent concepts.

Claims

1. A data leak detection system, including a management server that detects leaks through a network.

2. In paragraph 1, A user terminal whose leakage is detected by the above management server; and Further comprising a monitoring server that outputs real-time tracking results and aggregated information leak status for leak detection through the above management server; The above management server, A network leak detection unit that detects leaks through networks, including web browsers, Internet messengers, cloud Cilent, Windows sharing, work management collaboration tools, remote access, Outlook, FTP, malware network printers, and unauthorized networks, and detects all leaked files regardless of encryption and encoding method or protocol type; A peripheral leak detection unit that detects leaks through PC peripherals including Bluetooth devices or removable storage media such as USB and CDROM, and detects all leaked files regardless of encryption and encoding method or protocol type; When information leakage is detected by the network leakage detection unit and the peripheral device leakage detection unit, a leakage detection extraction unit that checks whether the leakage file contains personal information and important keywords and monitors important information in the leakage file; and Includes a feature provider including GUI functions, utility functions and its own security functions; The above network leak detection unit is, When information leakage through the network is detected, the PC name, Process name, Process ID, source IP / Port, destination IP / Port, web browser URL information, screen capture at the moment of leakage, leaked file path name, leaked file copy, and file size are saved. If information leakage is detected through Outlook sending history, the PC name, process name, process ID, email subject, sender and recipient email addresses, attached file copy, and file size are saved. If information leakage through media is detected, the PC name, process name, process ID, media type, leaked file path name, leaked file copy, and file size are stored. If information leakage through a network printer is detected, the PC name, Process name, Process ID, Printer name, Print document name, Print owner, Spool file name, size, and Print file are saved. The above network leak detection unit and peripheral device leak detection unit are, A data leak detection system that provides URL information when a leak is detected via a web browser, provides a screen dump at the moment of the leak, and provides the ability to immediately download and view the leaked file.

3. In paragraph 2, The above network leak detection unit is, A data leak detection system that determines whether to perform an inspection for leak detection using the following [mathematical formula] based on a preset inspection period, the number of times a leak is detected through the network, the number of times a leak is detected through the Outlook sending history, the number of times a leak is detected through the medium, and the number of times a leak is detected through the network printer. [Mathematical formula] (P s refers to the inspection period of the preset network leak detection unit, and D n means the number of times a leak was detected through the network, and D o refers to the number of times information leakage was detected through Outlook sending history, and D m D refers to the number of times information leakage through the media was detected. mv refers to the number of times information leakage through network printers was detected, and I r refers to a numerical value that serves as a standard for determining the inspection of the network leak detection unit.)

Citation Information

Patent Citations

  • Security System detecting the leak of informationusing computer storage device

    KR1020010078840A

  • Folding plate and manufacturing method thereof

    KR1020230120680A

  • Light emitting device and polycyclic compound for the same

    KR1020240003784A

  • Method for Automatically Responding to Threat

    KR102222377B1