Application Layer Data Inspection for Sensitive Information Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security systems fail to identify and control the transmission of sensitive application-layer data, allowing inadvertent or intentional exposure of sensitive information outside the firewall, as they are designed to prevent external attacks rather than internal data leakage.
Innovation Solution
A method and system that identifies sensitive data at the application layer, detects packetization, inserts flags in packets to indicate sensitive data, and enforces transmission control rules and policies across network layers to prevent unauthorized data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewall technology is employed to prevent external attacks and access, then external security is improved, but internal data transmission control deteriorates (sensitive data can still be transmitted outward)
Solution Approach 1:
The patent segments the network security function into two distinct components: (1) traditional firewall for external attack prevention, and (2) application-layer data inspection system for sensitive data identification and control. This segmentation allows each component to specialize in its respective function without compromising the other.
Solution Approach 2:
The patent introduces an intermediary component (application-layer gateway or proxy server) that sits between internal applications and the network. This intermediary inspects application-layer data, identifies sensitive information, and enforces transmission control policies before data leaves the network, thereby bridging the gap between external security and internal data protection.
2Productivity
If routers are designed to route communications efficiently, then network performance is improved, but data transmission control deteriorates (routers cannot prevent sensitive data transmission)
Solution Approach 1:
The patent separates routing functions from data inspection functions. Routers continue to handle efficient packet forwarding at lower layers, while a dedicated application-layer inspection system handles sensitive data identification and control. This segmentation maintains network performance while adding data protection capabilities.
Solution Approach 2:
The patent introduces an application-layer intermediary that inspects data content before it is routed outward. This intermediary works in conjunction with existing routers, allowing routers to maintain their efficient routing performance while the intermediary provides the additional layer of sensitive data control.
3Loss of information
If application-layer data inspection is implemented to identify sensitive data, then data transmission control is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal data inspection framework that can identify multiple types of sensitive data (personal information, financial data, confidential business information) using a single system. This multi-functional approach reduces complexity compared to implementing separate inspection mechanisms for each data type.
Solution Approach 2:
The patent uses pattern matching and signature-based identification to detect sensitive data, effectively creating simplified representations (copies) of sensitive data patterns. This allows the system to identify sensitive information without needing to deeply analyze or store the actual data, reducing computational complexity.
4Reliability
If transmission control policies are enforced at the application layer, then data security is improved, but processing overhead increases
Solution Approach 1:
The patent implements preliminary action by pre-defining sensitive data patterns, classification rules, and transmission control policies before actual data inspection occurs. This preparation work is done once and stored for rapid reference during data inspection, significantly reducing processing overhead during actual transmission control operations.
Solution Approach 2:
The patent applies different inspection and control strategies to different types of data and different transmission scenarios. Rather than applying a uniform complex inspection process to all data, the system uses local quality principles to apply appropriate-level inspection based on data type, sensitivity, and destination, reducing overall processing overhead.
Data Source
AI summary
Disclosed are methods, systems, and computer program products for identifying sensitive application-layer data and controlling transmission of the data in a network. According to one method, sensitive data in a system resource is identified at an application layer. A packetization of the identified sensitive data is detected. A flag indicative of the presence of sensitive data is inserted in a packet having at least a portion of the identified sensitive data in response to identifying the sensitive data and detecting the packetization. The flag is inserted in a portion of the packet corresponding to a layer other than the application layer. Transmission of the packet is controlled in a network based on the flag.


