Cloaked network exfiltration detection

WO2026047604A4PCT designated stage Publication Date: 2026-04-23DEADBOLT CYBER HOLDINGS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
DEADBOLT CYBER HOLDINGS INC
Filing Date
2025-08-28
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Existing network security methods, such as honeytokens and network taps, are ineffective against sophisticated attackers who can bypass surveillance mechanisms, and low-level network monitoring tools like eBPF are not used for exfiltration detection.

Method used

A cloaked network surveillance system using a traffic-copy mechanism, a surveillance computer isolated from the network, and an analytics engine that compares observed traffic data with a subset store of earmarked identifiers to distinguish exfiltration from normal activity, employing eBPF for metadata analysis and AI for heuristic learning.

Benefits of technology

Effectively detects exfiltration without being detected, providing real-time alerts and isolating threats, while maintaining anonymity and reducing false positives.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025058708_23042026_PF_FP_ABST
    Figure IB2025058708_23042026_PF_FP_ABST
Patent Text Reader

Abstract

A network data surveillance system that detects exfiltration of data records, files and fields: a. using and storing valuable record, file and field data from the network that is earmarked as an indicator of exfiltration activity and; b. where the surveillance is achieved with the use of a network tap or similar on cloud that allows the surveillance to be achieved without having a physical presence on the network and therefore without detection by attackers and; c. Where a surveillance computer system is attached to the network tap in order to analyse network and file transfer traffic and compare activity to a subset database of valuable earmarked records, files and or fields and where the surveillance computer remains cloaked from the network and; d. Where the system alerts network owners or operators of exfiltration and or intrusion activity using out of network communications.
Need to check novelty before this filing date? Find Prior Art

Description

Cloaked Network Exfiltration DetectionRic Richardson and Dennis GrovesBackground

[0001] Prior art in the field of network security includes several established techniques and methods . These include honeytokens , network taps and their cloud equivalent called traffic mirroring .

[0002] Honey tokens , which are decoy data inserted into systems to detect unauthorised access , are well-known in the industry . These tokens use tagged records and are detected through logs or data analysis tools . However, a notable limitation is that attackers can often identify the presence of these honey tokens , reducing their effectiveness . This is because the tags that are written to the database are readable and detectable to a talented attacker who can then adj ust their attack to avoid these records during exfiltration .

[0003] Additionally, network taps , which are another technique recognized in the art , can be used to monitor network traffic without interacting with it at all . This technique is not usually used to detect the exfiltration of honeytoken data but rather they are used to detect network errors and efficiency issues . The advantage of network taps is that they do not interact with the network, making them less detectable or even not detectable by attackers .

[0004] Despite the effectiveness of honey tokens , their utility as an exfiltration deterrent is reduced or even nullified if the surveillance methods are not cloaked . Attackers can implement countermeasures to bypass these tokens if they detect the surveillance tools . Some of these countermeasures include monitoring for anomalies that might indicate the presence of honey tokens or using sophisticated tools to filter out decoy data . Consequently, the need arises for more advanced solutions .

[0005] What is needed in this context are honey tokens that use real data that is indiscernible from actual customer or patient data . This would make it unlikely for attackers to identify data that is being used to identify exfiltration . Additionally, there is a requirement for a surveillance method that is imperceptible to attackers , ensuring that the detection mechanism being used remains hidden and effective in identifying unauthorised exfiltration without being detected .

[0006] Further, existing exfiltration and malware detection systems do not include surveillance and security analysis of low level network layer data such as the layers that can be retrieved by low level network tools such as by an extended Berkely Packet Filter ( eBPF ) . eBPF filters are not used for exfiltration detection, but their unique ability to observe network activity at the operating system level and tie traffic to specificprocesses and user identities makes them ideally suited for building advanced exfiltration detection systems .

[0007] OWASP AppSensor provides a framework for detecting anomalous behavior within applications by generating messages when suspicious patterns such as inj ection attempts , session tampering, or abnormal request rates occur . These messages are not used for exfiltration or malware attack surveillance , as their primary role is intrusion detection at the application layer . However, when correlated with lower-level system or network monitoring technologies such as eBPF— which can observe kernellevel events and tie network traffic to specific processes and users— AppSensor messages can contribute to a multi-layered defense that extends detection capabilities beyond the application itself to include potential data exfiltration and malware activity . This combined use creates a richer context for identifying and responding to sophisticated attacks .

[0008] The described invention is designed to address these issues or at least provide a useful alternative .Notes

[0009] The term "comprising" ( and grammatical variations thereof ) is used in this specification in the inclusive sense of "having" or "including" , and not in the exclusive sense of "consisting only of" .

[0010] The above discussion of the prior art in the Background of the invention, is not an admission that any information discussed therein is citable prior art or part of the common general knowledge of persons s killed in the art in any country .Brief Description of Invention

[0011] Accordingly, in one broad form of the invention, there is provided a cloaked network surveillance system for detecting exfiltration of data from a protected data store ; the protected data store in communication with a network, the system comprising : a traffic-copy mechanism configured to provide a passive copy of network traffic passing from or to the protected data store ; and wherein the traffic-copy mechanism observes and copies data from the network traffic without interacting with the network traffic; a surveillance computer isolated from and non-addressable on the monitored network; a subset store containing earmarked identifiers derived from the protected data store , the identifiers corresponding to one or more of database records or fields , unstructured files , or network metadata entries ; an analytics engine configured to compare observed traffic data and metadata with the subset store data and analytics to distinguish exfiltration and / or networkattack from day-to-day activity; an alerting interface operative to notify an administrator of suspected exfiltration .

[0012] Preferably the analytics engine is configured to compare observed traffic data and metadata with baseline access patterns by users over time to distinguish exfiltration and / or network attack from day-to- day activity;

[0013] Preferably the traffic-copy mechanism comprises a cloud virtual tap or traffic-mirroring service .

[0014] Preferably the alerting interface is an out-of-band alerting interface .

[0015] Preferably the alerting interface is operative to notify an administrator of suspected exfiltration without using the monitored network .[ 0001 6 ] Preferably a client device connected to the data store generates the subset store by querying for a parsed subset of earmarked identifiers that uniquely represent records , files , or metadata entries while preserving anonymity .

[0017] Preferably the parsed subset is copied to the surveillance computer for comparison against traffic observed at the traffic-copy mechanism.

[0018] Preferably the subset store comprises a spread of earmarked items distributed across the data store at randomized intervals to reveal sequential or bulk retrieval indicative of exfiltration .

[0019] Preferably the analytics engine performs ongoing heuristic surveillance to build rules that separate exfiltration from normal activity .

[0020] Preferably the regularity or irregularity of access to earmarked items forms part of the heuristic analysis .

[0021] Preferably the system comprises a rules database that is refined over time to increase confidence in exfiltration determinations .

[0022] Preferably the analytics engine employs artificial intelligence to learn differences between exfiltration activity and legitimate activity .

[0023] Preferably the subset store is generated clientlessly by observing day-to-day traffic and selecting earmarked items from such observation .

[0024] Preferably the subset store additionally includes identifiers associated with well-known or celebrity names to detect small-scale exfiltration .

[0025] Preferably full unparsed identifiers of records , files , or metadata are earmarked .[ 0002 6 ] Preferably realistic honeytoken data entries or files are inj ected into the data store and treated as earmarked indicators of exfiltration .

[0027] Preferably the system further comprises an operating-system- level capture pipeline that passively observes link-layer and networklayer metadata using an extended Berkeley Packet Filter ( eBPF) program or similar, the metadata including at least one or more of MAC addresses ,EtherType values, VLAN identifiers, frame sizes, timestamps, IP source and destination addresses, time-to-live values, dif f erentiated-services code points, and cumulative byte and packet counts, without retrieving or storing file content.

[0028] Preferably the kernel is extended or a signed kernel module is employed to associate per-flow activity with operating-system process identifiers or authenticated user sessions.

[0029] Preferably the equivalent link-layer filters are implemented using Windows NDIS lightweight filter drivers or similar or BSD / macOS packet-filter extensions or similar with materially the same effect.

[0030] Preferably the analytics engine hashes and stores metadata only, and indexes events primarily by network address and secondarily by other attributes, thereby maintaining a metadata-only surveillance posture .

[0031] Preferably the out-of-band alerting interface comprises a smartphone application secured with passkeys and configured to allow an administrator to invoke a "break-the-glass" isolation of an implicated share or endpoint.

[0032] Preferably the analytics engine escalates states from normal to concern to breach based on volumetric and timing deviations from baseline .

[0033] Preferably the protected data store comprises one or more of: personal, business, departmental, human-resources, finance, or healthcare file shares; structured databases; or network metadata repositories, and wherein the analytics engine detects abnormal out-of-hours access and triggers escalation.

[0034] Preferably the subset store includes parsed or hashed file metadata comprising one or more of: file name, file type, file size, file path, creation time, modification time, and access time.

[0035] Preferably the analytics engine detects abnormal activity by identifying bulk retrievals of files with similar metadata characteristics, including sequential file names or common file type groupings .

[0036] Preferably access frequency to sensitive file types such as spreadsheets, word-processing documents, portable document format files, or compressed archives forms part of the heuristic analysis.

[0037] Preferably the subset store includes hashed identifiers derived from file directory structures such that retrieval of files across multiple directories in sequential order is detectable as potential exfiltration.

[0038] Preferably the analytics engine detects exfiltration based on anomalous access to dormant or rarely accessed files, as determined from historical file access metadata.

[0039] Preferably honeytoken files are generated with realistic file names, metadata, and content attributes, and inserted into the data store to act as exfiltration tripwires .

[0040] Preferably the analytics engine applies weighting factors to different file metadata fields so that access patterns to highly sensitivefile categories trigger escalated states earlier than access to low- sensitivity files .

[0041] In yet a further broad form of the invention there is provided a method of detecting abnormal data exfiltration, comprising : passively observing traffic at a link-layer interface using a tap or cloud mirror; extracting link-layer and network-layer metadata; hashing and storing the metadata in association with a baseline model ; identifying deviations in retrieval volume , sequence , or timing indicative of exfiltration; and escalating an alert for immediate action .

[0042] Preferably the alert is communicated by means of a secure out- of-band administrative device .

[0043] Preferably the abnormal activity comprises bulk retrieval from human-resources , finance , or patient-record shares outside normal working hours , and the escalated action isolates the affected share or account .

[0044] Preferably the method further comprises detecting queries for celebrity or well-known names as an early indicator of exfiltration .

[0045] Preferably the method further comprises generating the earmarked subset by either ( i ) client-initiated querying of the data store for parsed identifiers or ( ii ) clientless observation of day-to-day traffic .[ 0004 6 ] Preferably the method further comprises using artificial intelligence to refine rules that distinguish exfiltration from normal activity .

[0047] Preferably parsed identifiers are reduced such that personally identifiable information elements are shortened below a size that preserves anonymity while remaining uniquely identifying when combined, and are stored as hashes .

[0048] Preferably all administrator notifications and controls are transmitted out-of-band so that attackers cannot observe alerting or remediation activity on the monitored network .

[0049] Preferably the method further comprises monitoring file metadata including one or more of : file name , file type , file size , file path, creation time , modification time , and access time .

[0050] Preferably abnormal activity is identified by detecting bulk retrievals of files with sequential file names , common file type groupings , or access outside normal working hours .

[0051] Preferably the method further comprises detecting anomalous access to dormant or rarely accessed files as determined from historical file access metadata .

[0052] Preferably the method further comprises generating honeytoken files with realistic file metadata and treating access to such files as an indicator of exfiltration .

[0053] Preferably the method further comprises weighting metadata fields according to sensitivity such that anomalous access to high- sensitivity file types produces escalated alerts earlier than low- sensitivity file types .

[0054] In yet a further broad form of the invention there is provided a non-transitory computer-readable medium storing instructions that , whenexecuted by one or more processors of the surveillance computer , cause the computer to perform the method as described above .

[0055] In yet a further broad form of the invention there is provided a network database surveillance system that detects exfiltration of database records and fields : using and storing valuable record and field data from the database that is earmarked as an indicator of exfiltration activity and; where the surveillance is achieved with the use of a network tap or similar on cloud that allows the surveillance to be achieved without having a physical presence on the network and therefore without detection by attackers and; Where a surveillance computer system is attached to the network tap in order to analyse network and database traffic and compare activity to a subset database of valuable earmarked records and fields and where the surveillance computer remains cloaked from the network and; Where the system alerts database owners or operators of exfiltration activity using out of network communications .

[0056] Preferably the equivalent of a network tap is used in a cloud based network to achieve the same effect as a network tap . These are known as a virtual network tap or as traffic mirroring .

[0057] Preferably a client device attached to the network and the database is used to build a parsed subset of earmarked records and field data . This subset of parsed data is then used as a baseline or starting point in building a subset database of records and fields that can be earmarked as indicators of possible exfiltration activity .

[0058] Preferably the parsed subset of data is copied and shared with a surveillance computer that watches for exfiltration activity by comparing records retrieved over the network against the subset database of parsed records and fields .

[0059] Preferably an initial spread of records and field data is earmarked for monitoring across the whole database of records and field data so that widespread exfiltration activity can be easily detected and an alarm triggered to take action against the exfiltration .

[0060] Preferably the system uses ongoing surveillance of the traffic to and from the database thru a network tap or cloud equivalent in order to generate heuristic pattern detections that can be used to detect and reliably diagnose exfiltration activity and separate it from normal day to day network activity .

[0061] Preferably the regularity or lack of regularity of access to earmarked records can be used as part of the heuristic analysis of database traffic .

[0062] Preferably the system allows the surveillance computer or system to generate and or build a database of rules that help separate exfiltration activity from normal day to day database query and action activity and where the learnings of the system over time allow it to become more accurate and more confident in its evaluations .

[0063] Preferably the system uses Al to analyse and learn the difference between exfiltration activity and legitimate day to day network and database activity .

[0064] Preferably no initial subset database is generated but rather the surveillance system uses only data monitored during normal day to day activity to generate a subset of earmarked records for use in determining exfiltration activity versus day to day database and network activity .

[0065] Preferably the system enables a database of well known and or celebrity names can be used to earmark records in the database that can be used as an indicator of exfiltration activity rather than day to day activity .

[0066] Preferably full unparsed record and field data is earmarked

[0067] Preferably instead of earmarking records , a series of realistic honeytoken records are inj ected into the database and used as indicators of exfiltration activity .DrawingsEmbodiments of the present invention will now be described with reference to the accompanying drawings wherein :

[0068] Figure 1 is a block diagram showing main components of example embodiment

[0069] Figure 2 illustrates dissection of a record being an example of earmarking records to detect exfiltration

[0070] Figure 3 illustrates an example of spread earmarked records in a database to be protected

[0071] Figure 4 is a flowchart illustrating an example of onboarding process for the example embodiment

[0072] Figure 5 is a flowchart illustrating a process flow for an eBPF enabled surveillance systemExample embodimentFigure 1 discloses the main components of an example embodiment . A network such as a hospital network contains a number of computers acting as servers and / or clients as well as storage systems containing valuable data . The storage may comprise structured databases of records and fields , or unstructured data such as files , images , and documents . A key component of the network is a data store 10 that contains high-value information for use by the computers on the network . Client computers 11 can connect by means of the network to the data store 10 in order to create , read, update , and delete data in the normal course of business . The value of the data stored, which may include sensitive personal information such as payment details , insurance records , social security numbers , or patient information, makes the store a prime target for hackers and other cybercriminals . One common technique is to obtain credentials for legitimate users on the network and then use those credentials to exfiltrate data en masse for sale or extortion on the black market .In the example embodiment a specialised client 11 is used to access the data store 10 and then select a number of representative data items— whether records , fields , or files— to serve as indicators of unauthorisedexfiltration . A subset 15 of these items is copied and set aside for later use in determining when large-scale exfiltration is in progress .

[0073] An analysis of the application programming interface (API ) of the data store 10 , or of the file access protocols used by the store , helps determine what data is normally accessed in day-to-day operation and what patterns of access are not characteristic of legitimate activity .

[0074] During later surveillance , if the earmarked subset of data items is accessed in a pattern inconsistent with normal operational activity, an alarm is triggered and the system owners are alerted to the activity as likely exfiltration rather than routine business use .

[0075] The subset 15 may also be stored in a parsed or reduced formto preserve privacy . For example , only the last four digits of a social security number may be retained, optionally combined with a partial date of birth or name , to uniquely identify a record while ensuring the data cannot itself be used for identity theft . This parsing approach ensures the detection subset remains effective while avoiding storage of personally identifiable information .[ 0007 6 ] In this way, when the monitoring system later observes data from the subset being retrieved from the main store 10 , it can confidently tag such access as an exfiltration event .The network monitoring component of the embodiment comprises a network tap 12 , or a cloud-based equivalent such as a virtual tap or traffic mirroring service , positioned between the data store 10 and the rest of the network . The tap 12 allows a monitoring computer 14 to receive a copy of traffic 13 without introducing an observable presence . As it observes traffic to and from the data store 10 , the monitoring computer 14 can identify access patterns that diverge from ordinary behaviour .To achieve this , a copy 16 of the parsed subset 15 is compared by the monitoring computer 14 against the observed traffic . If the usage patterns of the subset diverge from normal day-to-day activity, the monitoring computer 14 triggers an alert to indicate a probable exfiltration event .

[0077] As the surveilling computer 14 detects valuable data being read from the database 10 it compares the monitored data to its own subset and parsed database 16 to see if there are any matches and then consults a set of rules 14 that help the system to know the difference between normal record and field reading activity and specific exfiltration type activity .

[0078] These rules can include but not be limited to requests for field data from a client that does not normally access that data . For example a nurses station in a hospital retrieving payment data may be anindicator of exfiltration activity . The trigger rules used by the surveillance computer 14 can be expanded and refined over time to more accurately discern the difference between normal day to day database activity and exfiltration activity .

[0079] Figure 2 discloses an example of how a subset of parsed record data from a database can be reduced to a state where the data cannot be used for the purposes of extracting personally identifiable information or other highly valuable data while still allowing the parsed data subset to be effectively used in detecting when a data exfiltration event is happening and to help differentiate such an event from everyday normal activity .

[0080] For example a social security number 51 is typically a nine digit number that is unique to every individual 50 in the United States . By parsing the number down from nine digits 51 to four digits such as the last four digits of the social security number 54 , the data becomes relatively unusable for the purposes of identity fraud . In fact amongst security engineers the reduction of most personally identifiable information data to a size under thirty bytes is a recognised way of maintaining anonymity .

[0081] However, a four character parsed social security number 54 when combined with a parsed birthdate 55 will statistically make the record unique enough in all but a very few cases to ensure that duplicate records can be avoided .

[0082] This process can be applied to all the fields in a record that are deemed to be of high value to an attacker .

[0083] In the case of figure 2 , which is an example of personally identifiable information, a person ' s name 50 , their social security number 51 and their birthdate 52 can all be parsed to under four characters each 53 54 55 with a combined identifier record 56 that combines parsed elements 53 54 55 in a unique identity that can be indexed to ensure that each record remain unique in the database and to minimise duplication of records , yet the data itself remain unable to be used as personally identifiable information .

[0084] Figure 3 discloses an example of how a spread of records across a database can be used to produce a subset of data that is useful for the purposes of detecting exfiltration activity in a database . By earmarking records across the whole database 80 at regular intervals 82 a surveillance system that sees access to a number of these records 81 83 84 85 86 87 88 and especially records that are not in current high use , such as a current patient record at a hospital , can indicate the intention of the inquirer not to conduct everyday business but rather the intentional exfiltration of record and field data .

[0085] In the example shown the spread of records between each other81 83 87 88 may be of a specified number 82 but the records earmarked may be either before 86 or after 85 84 the desired chosen record separation count 82 . This approach allows the earmarked record database to be a smaller subset of the data to be protected but still enables intentional exfiltration to be easily detected . By randomising the distance between target records 81 83 87 88 , the system will resist attempts by exfiltration attackers to establish what records have been earmarked for detection .[ 0008 6 ] In use this spread 82 of earmarked records can be used as an indicator of exfiltration activity . It does this because in normal day to day activity, records and fields are queried for specific reasons and for specific cyclical activity . When a database is queried for records in a methodic or a sequential manner across one or even multiple clients there is a good basis to believe an exfiltration attack is occurring . The assumption is that a person retrieving data for exfiltration will search for larger groups of records and quite possibly records that are in successive order or relatively sequential order . Only larger batch activities that are part of the normal cycle of activity would not be reasonably tagged as exfiltration activity .

[0087] Figure 4 discloses an example onboarding process for the example embodiment . To establish an initial subset of earmarked records a client device 100 is connected to the network and the database in order to query the database for a subset of records and field data to be earmarked . Once a representative spread of records are earmarked 100 the subset database is transferred to the surveillance computer 101 in order to have a baseline of earmarked records to look for during exfiltration detection . Once connected to the network by means of network tap the surveillance computer commences heuristic assessment of the network and database traffic and activity 102 . Using this information the surveillance computer builds a database of queries and use case rules that indicate normal day to day activity 103 . This heuristic analysis will be used in addition to the mechanically earmarked spread of records and fields previously gathered 100 to help heuristically differentiate between exfiltration and normal day to day network and database activity .

[0088] In addition the surveillance computer queries the database ' sAPIs 104 to determine what database queries and activities are considered day to day activities and which queries may indicate exfiltration activity . For example some API data calls may be very rarely called or used and any use of those calls could be very heavily scrutinised .

[0089] The surveillance computer then adds these rules 105 to its exfiltration detection database to further improve the ability of the system to detect exfiltration .

[0090] FURTHER EMBODIMENTS

[0091] Example Embodiment OSI Low Level Traffic Capture

[0092] In one embodiment , the surveillance system is deployed as a transparent monitor positioned on a server-side link so that all ingress and egress traffic associated with protected file services traverses the monitoring point . The system observes traffic passively without altering payloads , operating as a virtual tap or mirror at a j unction that already aggregates file-share flows . This placement keeps the mechanism invisible to adversaries while allowing continuous observation of metadata useful for data-exf iltration detection . The system' s alerts are consumed by an out-of-band administrative application that is secured with high security cryptography and authentication and enables immediate remediation, including isolation of a target share via a "break-the-glass" action .

[0093] Operating System and Tools

[0094] The capture function executes in the operating system kernel on a Linux host that has extended Berkeley Packet Filter ( eBPF ) support enabled . In a stock configuration, the system attaches eBPF programs at the link-layer ingress and egress hook points ( for example , XDP or tc hooks ) to sample or stream frame and packet headers to a user-space analytics agent via a lock-free ring buffer . In variants where deeper attribution is desired, the kernel is modified or extended through a signed kernel module to expose additional tracepoints that associate per-flow activity with process identifiers and authenticated account context obtained from cgroups or login subsystems . In other embodiments , equivalent link-layer filters are implemented using Windows NDIS lightweight filter drivers or BSD / macOS packet filter extensions , with materially the same effect .

[0095] The same host may also run a standards-based sensor to generate enriched flow records ; suitable examples include Zeek or Suricata, which coexist with the eBPF pipeline and can provide flow-level counters without inspecting content . The analytics agent on the host is responsible for hashing , storing, and correlating the observed metadata with the system' s set of tripwires and escalation rules .

[0096] Captured Data at Low OSI Layers

[0097] The capture pipeline collects , without limitation, for each observed frame and the flows inferred therefrom: source and destinationmedia-access control identifiers ; link-type and EtherType values ; tagged virtual local area network identifiers ; interface indices ; frame lengths and timing; Internet-protocol source and destination addresses ; time-to-live and dif f erentiated-services fields ; protocol identifiers at the network layer ; and cumulative counters of bytes and packets per direction . Where the transport header is available in the same packet buffer, the system records source and destination port numbers only for attribution and volumetric analysis ; content is not read or stored . The collected metadata is hashed and retained for baseline modelling and anomaly detection, consistent with the inventions metadata-only approach .

[0098] Analytics and Correlation

[0099] The agent constructs per-endpoint and per-address baselines that describe typical retrieval volumes , timing , and counterpart relationships for protected file services . Events are indexed primarily by Internet-protocol address and secondarily by other available attributes so that the system can reason about behaviors even when application-level identifiers are unavailable . Deviations from the baseline— such as unusually high retrieval volumes , bursts of short-interval connections to file servers , or access occurring far outside business hours— are mapped to surveillance server states that progressively escalate from normal , to concern, to breach, minimizing false positives while preserving operator attention for materially risky events .[ 000100 ] Administrative Controls[ 000101 ] When an escalation threshold is crossed, the out-of-band smartphone application presents a real-time alert to an authenticated administrator , who may acknowledge , annotate , or invoke a break-the-glass isolation of the affected share or a disconnection action on the offending user or account . Isolation can be performed by instructing the share controller or upstream switch to block the implicated address or to detach the protected volume until the operator clears the condition . The same application allows on-the-spot sensitivity adj ustments or temporary exceptions .[ 000102 ] Practical Scenario (Healthcare File-Share)[ 000103 ] Consider a mid-sized hospital environment in which a small number of departmental file shares and human-resources and finance file shares reside on one or two file servers . The surveillance system is installed as two virtual taps at the server connections , with administrative privilege to tag sensitive data for monitoring and to configure exfiltration tripwires . The system preferably observes only metadata, not file contents even though full observation is possible in some cases and may need to be utilised .[ 000104 ] At twenty-two hundred hours local time , the agent observes a workstation address communicating with the human-resources share over the server link . Layer Two reveals the workstation' s media-access control identifier and the server-facing interface ; Layer Three shows a hospital-internal Internet-protocol address previously associated with daytime activity from a different department . Within a short interval , the per-address counters show a sustained increase in retrieved bytes far above the established baseline for that endpoint during out-of-hours periods . Because the system links events to addresses rather than relying on file names , it immediately classifies the behavior as a concern, then escalates to a breach when volumetric and timing thresholds are exceeded . An alert is delivered to the out-of-band application; the on-call administrator reviews the summary and invokes break-the-glass isolation for the human-resources share or the account or IP address involved, halting the transfer without touching any file content .[ 000105 ] Notes on Encrypted Services and Cloud Shares[ 000106 ] Where protected resources are accessed through encrypted web services rather than local file protocols , the same low level OSI data capture still yields counterpart domains , addresses , and volumes sufficient for anomaly detection; in such cases , filename-level telemetry is not available from passive capture and may be supplemented by administrative audit feeds when the customer environment permits . The surveillance remains metadata-only .[ 000107 ] As shown in Figure 5 , a protected file share 200 provides the source of data traffic that is to be monitored for potential exfiltration activity . This file share 200 may represent any of a wide range of storage systems , including departmental file servers , human-resources or finance repositories , or other unstructured data stores that are frequently targeted by attackers . All ingress and egress flows associated with the protected file share 200 are aggregated at a network j unction 210 , which may be implemented as a physical tap, a switch mirror port , or a virtualized traffic-mirroring service in a cloud environment . The placement of the network j unction 210 is deliberately transparent , so that observation can occur without modification of payloads and without detection by an adversary .[ 000108 ] Traffic traversing the network j unction 210 is delivered to a kernel-level capture agent 220 . In a preferred embodiment the capture agent 220 attaches extended Berkeley Packet Filter ( eBPF) programs at link-layer ingress and egress points such as XDP or tc hooks , allowing the system to stream selected headers and counters while avoiding the overhead of full content inspection . The capture agent 220 collects metadata 221 including , without limitation, Layer-2 media access control addresses , VLAN identifiers , EtherType values , Layer-3 Internet-protocol source and destination addresses , dif f erentiated-services fields , time-to-live values , Layer-4 source and destination ports , cumulative byte and packet counts , and, when available , higher-layer session identifiers .[ 000109 ] In variants where more granular attribution is desirable , the capture agent 220 cooperates with a kernel extension 222 , which may be a signed kernel module , to expose additional tracepoints . This extension 222 allows the system to associate per-flow activity with process identifiers or authenticated account context , producing an enriched attribution record 223 that links flows directly to user sessions or applications . By adding process-level detail 223 , the system can differentiate between legitimate automated services and anomalous bulk retrieval activity initiated under compromised credentials .[ 000110 ] The metadata 221 , together with optional attribution context223 , is streamed through a lock-free ring buffer 224 to user-space analytics 230 . The user-space analytics 230 provides a modular framework that applies multiple layers of processing . A first module 231 hashes and stores the captured metadata so that individual identifiers are anonymised while still permitting indexing and recall for correlation . A second module 232 constructs baselines per endpoint , per process , or per authenticated user , thereby defining what constitutes normal day-to-day usage in terms of retrieval volumes , access timing, and counterpart relationships . A third module 233 compares ongoing activity against a set of tripwire rules that have been defined for sensitive records or files . A fourth module 234 correlates observed events with auxiliary signals , such as OWASP AppSensor events , self-healing error messages , or alerts from standards-based flow sensors such as Zeek or Suricata .[ 000111 ] The outputs 240 of the user-space analytics 230 are then forwarded to a tripwire escalation engine 250 . The escalation engine 250 evaluates deviations from baselines and determines an appropriate surveillance state . States 251 are graded progressively from "normal" to "concern" to "breach, " ensuring that operator attention is only demanded when abnormal retrieval volumes , sequential file accesses , or anomalous timing patterns cross predetermined thresholds . In parallel , the escalation engine 250 communicates via an out-of-band interface 252 so that alerts are never visible on the monitored network .[ 000112 ] An administrator is notified on a secured smartphone application 260 , which receives the alert message 261 protected by strong cryptographic authentication . The application provides the administrator with options to acknowledge or annotate the event , to view supporting logs , or to immediately initiate remediation . In urgent scenarios , the administrator can invoke a break-the-glass action 262 , which instructs the system to isolate the implicated file share or endpoint , for example by instructing the file server to suspend the affected volume or by blocking the source address at an upstream switch . This design ensures that the protected file share 200 can be rapidly isolated in response to suspected exfiltration, while maintaining a metadata-only surveillance posture that avoids inspecting or storing file content .[ 000113 ][ 000114 ] Alternative Embodiments[ 000115 ] Cloud based network tap . The example embodiment uses a network tap to monitor for exfiltrated data . In a cloud based alternative embodiment the cloud equivalent of a network tap may be called a "virtual network tap" (vTap ) or a "traffic mirroring" service . In AWS , for example , this is called "VPC Traffic Mirroring . " In Azure , it is referred to as "Network Watcher Packet Capture . " These services allow a user to capture and inspect network traffic in a cloud environment , similar to how a physical network tap captures traffic in a traditional on-premises network . These alternative cloud based monitoring techniques could be used as an alternative to network tapping for the purposes of monitoring for exfiltrated data[ 00011 6 ] Unparsed data and honeytoken data . The example embodiment utilises existing database data that has been earmarked and parsed for later use as indicators of exfiltration activity . An alternative embodiment could use unparsed data or inj ected false data such as honeytokens as an indicator of exfiltration activity .[ 000117 ] The reason the example embodiment does not utilised these alternative data approaches as exfiltration indicators is because of the need to avoid building a database of personally identifiable information if the data is not parsed to the point of anonymity or secondly as a means to avoid false positives where a honeytoken is accidentally retrieved as part of a legitimate database query .[ 000118 ] Celebrity honeytoken data . The example embodiment uses earmarked records across the database as an indicator of exfiltration activity . An alternative embodiment could include a database of well known or celebrity names that could be used to earmark records for exfiltration activity . This is particularly useful where it is the database owners or managers intention to detect very small levels of exfiltration activity and could be used as an early indicator of exfiltration attack .[ 000119 ] For example , individual searches for "Taylor Swift" or "BillClinton" in single instances may not raise an exfiltration alarm but searches of multiple records of celebrity and or known people ' s names may well be a legitimate indicator of exfiltration activity in progress .[ 000120 ] Clientless onboarding alternative embodiment . The example embodiment uses a client computer to query the database and obtain a subset of earmarked records and fields . The example embodiment subsequently teaches that the subset data is copied to the surveillance computer as a baseline from which to start to detect exfiltration .[ 000121 ] An alternative embodiment could teach that there is no initial client computer to generate a list of earmarked records but rather thesurveillance computer itself uses its monitoring of day to day network activity to build its own earmarked record and field list .[ 000122 ] While this approach simplifies the installation and setup process of the system it does not benefit from the direct querying of records that are evenly spaced across the database that can detect larger scale exfiltration with a high degree of certainty and confidence .[ 000123 ] Al assisted heuristic exfiltration detection . The example embodiment uses an automated system of heuristic learning by the surveillance computer from watching day to day network and database traffic and activity . It builds a database of rules that reflect the difference between everyday activity and activity which may indicate exfiltration with a reasonably high degree of confidence .[ 000124 ] In an alternative embodiment artificial intelligence can be used to build and refine databases of rules to determine the difference between exfiltration activity and normal day to day activity .[ 000125 ] Alternative methods for spread of earmarked records . The example embodiment teaches a method for earmarking records throughout a database where candidates are chosen at a predetermined spread or number of records between candidates and where , to avoid detection, that spread is randomised to stop attackers from anticipating what specific records have been earmarked . An alternative embodiment could use any method to earmark records to be monitored for exfiltration where the earmarked records represent a useable spread of records across the whole database .[ 00012 6 ] General surveillance of valuable network data .The first example embodiment teaches surveillance focused on database records and fields . In an alternative embodiment , the same approach can be applied to any valuable network data, including but not limited to unstructured files , individual records , field data, or general network traffic metadata .[ 000127 ] Virtual Private network gateway . In an alternative embodiment , the capture point is placed on a customer' s virtual private network gateway so that all beta-tester or pilot traffic destined for protected shares must traverse the monitored interface ; this allows rapid trials with minimal integration and keeps user friction low . Another variant deploys the same analytics agent alongside tools like but not limited to Zeek or Suricata to emit flow records that the surveillance correlation engine ingests , providing additional counters without content inspection . In all cases , tripwires and escalation remain metadata-driven .[ 000128 ] Industrial ApplicationEmbodiments may be applied in the field of data processing in order to seek to flag potentially problematic data movements . In further embodiments specific actions can be taken to minimise the effects of problematic data movements .

Claims

AMENDED CLAIMS received by the International Bureau on 19 February 2026 (19.02..2026)What is claimed is :1 . A network database surveillance system for detecting exfiltration of records or fields from a protected data store , the protected data store in communication with a network, the system comprising : a subset store containing earmarked records or fields derived from the protected data store , the earmarked records being distributed across the data store , wherein the earmarked records comprise parsed record data reduced such that personally identifiable information elements are shortened while remaining uniquely identifying when combined; a surveillance computer configured to receive metadata relating to access of the protected data store without retrieving file or record content , the surveillance computer being configured to compare metadata relating to retrieved records against the subset store of earmarked record; and an analytics engine configured to determine whether access to the earmarked records occurs in a pattern inconsistent with normal day-to-day database activity and to escalate an alert indicative of exfiltration .2 . The system of claim 1 , wherein the earmarked records are distributed across the protected data store at predetermined intervals .3 . The system of claim 2 , wherein the intervals between earmarked records are randomised to resist attempts to identify which records have been earmarked .4 . The system of claim 1 , wherein the parsed record data comprises truncated portions of one or more of : name , social security number, birthdate , or other identifying fields .5 . The system of claim 1 , wherein the parsed record data is combined from multiple shortened fields to form a composite identifier that is uniquely indexable while preserving anonymity .6 . The system of claim 1 , wherein the surveillance computer is further configured to build a database of rules that differentiate exfiltration activity from normal day-to-day activity .7 . The system of claim 1 , wherein access to multiple earmarked records in a sequential or bulk manner forms part of the determination of exfiltration activity .8 . The system of claim 1 , wherein the subset store is generated by a client device querying the protected data store to obtain a representative spread of records .9 . The system of claim 1 , wherein the subset store is generated clientlessly by observing day-to-day network activity .10 . The system of claim 1 , wherein realistic honeytoken records are inj ected into the protected data store and treated as earmarked records .11 . The system of claim 1 , wherein escalation comprises transmitting an alert over an out-of-band communication channel and enabling isolation of the protected data store .12 . The system of claim 1 , further comprising a traffic-copy mechanism configured to provide a passive copy of network traffic passing from or to the protected data store without interacting with the network traffic .