Distributed Data Entity Self-Detection for Exfiltration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures are inadequate in detecting and preventing data exfiltration, as they often fail to prevent damage once data has been exfiltrated and can be compromised by malicious actors, leading to unawareness of data breaches and subsequent damage.

Innovation Solution

Implementing a data-centric security system where data entities can detect exfiltration by verifying their location through communication with other entities and self-destructing if they are outside the secure environment, thereby preventing exploitation by malicious actors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized intrusion detection systems are used to monitor network services, then detection capability is provided, but the systems can be compromised by malicious actors resulting in failure to detect data exfiltration

Engineering Contradiction:
Improvedetection reliabilityVSAvoidvulnerability to compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the centralized detection system into distributed data entities, each capable of independent exfiltration detection. Each data entity operates autonomously to determine its own exfiltration status by attempting to access other data entities, eliminating the single point of failure in centralized systems and preventing malicious compromise of the entire detection mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Data entities perform self-detection of exfiltration by autonomously attempting to communicate with other data entities. Each data entity independently determines its own security status without relying on external centralized detection, enabling self-protection capabilities that cannot be compromised by external attackers.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If data entities communicate to verify location within secure environment, then exfiltration detection accuracy is improved, but network communication overhead increases

Engineering Contradiction:
Improveexfiltration detection accuracyVSAvoidnetwork communication overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Data entities establish communication channels and verify each other's presence before data exfiltration can occur. By performing preliminary location verification through mutual accessibility checks, the system ensures accurate exfiltration detection while minimizing ongoing communication overhead during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces continuous network monitoring with event-driven accessibility checks. Instead of maintaining constant communication to verify location, data entities perform spot-checks by attempting to access each other only when exfiltration detection is needed, significantly reducing network communication overhead while maintaining detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If data entities self-destruct upon detecting exfiltration, then damage from exfiltrated data is prevented, but data availability is lost

Engineering Contradiction:
Improvedamage preventionVSAvoiddata availability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

Data entities apply preliminary protective measures by encrypting data with keys that become unusable upon exfiltration detection. Instead of immediately destroying data, the system renders the exfiltrated data worthless by making decryption impossible, thus preventing damage while maintaining data availability within the secure environment.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent changes the security parameter from data existence to data usability. Upon detecting exfiltration, the system alters the cryptographic parameters to render data unreadable rather than deleting the data itself. This approach prevents malicious actors from exploiting exfiltrated data while preserving data availability for legitimate users within the secure boundary.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11895155B2Resilient self-detection of malicious exfiltration of sensitive data
Publication Date: 2024.02.06 BANK OF AMERICA CORP
  • US11895155B2 patent drawing
  • US11895155B2 patent drawing
  • US11895155B2 patent drawing

AI summary

Aspects of the disclosure relate to exfiltrated data detection. A computing platform may receive secure enterprise data from an enterprise data management platform. In response to receiving the secure enterprise data, the computing platform may generate data entities. The computing platform may load, into the data entities, secure enterprise data. After loading the secure enterprise data into the data entities, the computing platform may activate a verification process associated with each data entity, which may include triggering each data entity to send verification messages to other data entities. Each data entity may be configured to receive and validate verification messages received from the other data entities of the plurality of data entities, and may be configured to delete secure enterprise data stored in the corresponding data entity upon failing to receive the verification messages from the other data entities.