Communication Watermark for Exfiltration Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures are ineffective in distinguishing legitimate voice or video calls from malicious ones disguised as such, leading to potential security breaches through 'exfiltration' where sensitive information is extracted using legitimate protocols, making it difficult to detect unauthorized data transfer.

Innovation Solution

Incorporating a watermark into voice or video communication sessions that is not readily observable during the session but can be verified later, allowing only legitimate sessions to continue and identifying potential security breaches by monitoring for the watermark's presence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If voice or video communication sessions are allowed without verification, then ease of operation is improved, but security reliability deteriorates due to inability to distinguish legitimate calls from malicious exfiltration attempts

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A watermark is embedded into legitimate voice or video communication sessions before they proceed, allowing verification of legitimacy without affecting user experience. The watermark is inserted in advance into the communication stream, enabling subsequent detection to distinguish authorized sessions from malicious exfiltration attempts.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security monitoring is implemented to detect exfiltration, then security reliability is improved, but device complexity increases due to additional monitoring and verification mechanisms

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A watermark acts as an intermediary mechanism embedded within the communication stream itself, rather than requiring complex external monitoring systems. The watermark is a simple data element that can be detected through straightforward verification, reducing the complexity of security infrastructure while maintaining high reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If watermarks are embedded in communication sessions, then security reliability is improved, but loss of information increases due to modification of communication data

Engineering Contradiction:
ImprovereliabilityVSAvoidloss of information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The watermark modifies only specific local portions of the communication data stream rather than altering the entire communication. The watermark is embedded in a localized manner within the voice or video stream, preserving the overall quality and integrity of the communication while adding verification capability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2961127B1Voice and video watermark for exfiltration prevention
Publication Date: 2020.09.02 AVAYA INC
  • EP2961127B1 patent drawingFigure 1
  • EP2961127B1 patent drawingFigure 2
  • EP2961127B1 patent drawingFigure 3

AI summary

A legitimate voice or video communication application modifies data in a communication session to produce a watermark. The watermark is a piece of information that is part of a communication session that is not readily observable, but can be verified later on. The purpose of a watermark is to verify that the communication session is a legitimate communication session and does not pose a security breach. The video or audio communication session is monitored for a watermark. In response to determining that the communication session contains the watermark, the communication session is allowed continue. In response to determining that the communication session does not contain the watermark, the communication session is identified as a potential security breach. If the communication session is identified as a potential security breach, the communication session can be dropped and a user can be notified of the potential security breach.