Distributed Data Entity Self-Detection for Exfiltration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures are inadequate in detecting and preventing data exfiltration, as they often fail to prevent damage once data has been exfiltrated and can be compromised by malicious actors, leading to unawareness of data breaches and subsequent damage.
Innovation Solution
Implementing a data-centric security system where data entities can detect exfiltration by verifying their location through communication with other entities and self-destructing if they are outside the secure environment, thereby preventing exploitation by malicious actors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized intrusion detection systems are used to monitor network services, then detection capability is provided, but the systems can be compromised by malicious actors resulting in failure to detect data exfiltration
Solution Approach 1:
The patent divides the centralized detection system into distributed data entities, each capable of independent exfiltration detection. Each data entity operates autonomously to determine its own exfiltration status by attempting to access other data entities, eliminating the single point of failure in centralized systems and preventing malicious compromise of the entire detection mechanism.
Solution Approach 2:
Data entities perform self-detection of exfiltration by autonomously attempting to communicate with other data entities. Each data entity independently determines its own security status without relying on external centralized detection, enabling self-protection capabilities that cannot be compromised by external attackers.
2Measurement precision
If data entities communicate to verify location within secure environment, then exfiltration detection accuracy is improved, but network communication overhead increases
Solution Approach 1:
Data entities establish communication channels and verify each other's presence before data exfiltration can occur. By performing preliminary location verification through mutual accessibility checks, the system ensures accurate exfiltration detection while minimizing ongoing communication overhead during normal operation.
Solution Approach 2:
The patent replaces continuous network monitoring with event-driven accessibility checks. Instead of maintaining constant communication to verify location, data entities perform spot-checks by attempting to access each other only when exfiltration detection is needed, significantly reducing network communication overhead while maintaining detection accuracy.
3Object-affected harmful factors
If data entities self-destruct upon detecting exfiltration, then damage from exfiltrated data is prevented, but data availability is lost
Solution Approach 1:
Data entities apply preliminary protective measures by encrypting data with keys that become unusable upon exfiltration detection. Instead of immediately destroying data, the system renders the exfiltrated data worthless by making decryption impossible, thus preventing damage while maintaining data availability within the secure environment.
Solution Approach 2:
The patent changes the security parameter from data existence to data usability. Upon detecting exfiltration, the system alters the cryptographic parameters to render data unreadable rather than deleting the data itself. This approach prevents malicious actors from exploiting exfiltrated data while preserving data availability for legitimate users within the secure boundary.
Data Source
AI summary
Aspects of the disclosure relate to exfiltrated data detection. A computing platform may receive secure enterprise data from an enterprise data management platform. In response to receiving the secure enterprise data, the computing platform may generate data entities. The computing platform may load, into the data entities, secure enterprise data. After loading the secure enterprise data into the data entities, the computing platform may activate a verification process associated with each data entity, which may include triggering each data entity to send verification messages to other data entities. Each data entity may be configured to receive and validate verification messages received from the other data entities of the plurality of data entities, and may be configured to delete secure enterprise data stored in the corresponding data entity upon failing to receive the verification messages from the other data entities.


