Cloud Security Proxy for Microsoft Teams Data Exfiltration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based collaboration tools like Microsoft Teams lack effective mechanisms to prevent unauthorized data exfiltration and malicious file transfers between sanctioned and unsanctioned tenant instances, posing risks of data leakage and phishing attacks.

Innovation Solution

Implementing a cloud-based security system with deep packet inspection (DPI) inline proxy that identifies tenant identities and enforces instance-based policies to block sensitive content sharing and malicious file transfers, allowing fine-grained control over user actions in both sanctioned and unsanctioned workspaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based collaboration tools allow access between sanctioned and unsanctioned tenant instances, then collaboration versatility is improved, but data exfiltration risk increases

Engineering Contradiction:
Improvecollaboration accessVSAvoiddata exfiltration risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based security system as an intermediary between sanctioned and unsanctioned tenant instances. This security system includes a proxy that intercepts, inspects, and controls data traffic, allowing collaboration to continue while preventing unauthorized data exfiltration through active monitoring and policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the collaboration environment into sanctioned and unsanctioned tenant instances with distinct access controls. By dividing the network architecture and applying separate security policies to each segment, the system enables controlled collaboration while isolating potential data leakage paths.

Inventive Principle:
Principle #1Segmentation

2Reliability

If deep packet inspection is implemented to detect sensitive content, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a multi-functional security proxy that performs deep packet inspection, tenant identification, policy enforcement, and data loss prevention all within a single integrated system. This universal approach consolidates multiple security functions rather than requiring separate systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11811779B2Securing collaboration tools against unauthorized data exfiltration
Publication Date: 2023.11.07 NETSKOPE INC
  • US11811779B2 patent drawing
  • US11811779B2 patent drawing
  • US11811779B2 patent drawing

AI summary

The disclosed technology teaches securing a collaboration tool against unauthorized data exfiltration and malicious files, setting policies for file exfiltration to external guest users, uploading users in the external category, and using a proxy that intercepts an add request and response for a collaboration tool. The add response contains a tag identifying the invited user in the category. The request doesn't identify the user as a guest. Also taught is storing metadata identifying the user in the guest category for applying policies, and using a proxy that intercepts a user request and response for file transfer, and looking up and identifying the user as in the category, and applying the applicable policy. Responsive to the policy, included is invoking DPI and detecting that the referenced file contains sensitive information not permitted by the policy to be transferred by the particular user in the external guest category and blocking file transfer.