Destination-Specific Network Management for Encrypted Data Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data loss occurs when computers on a network transfer data to unauthorized or undesirable destinations, especially due to malicious programs or hacking, and existing solutions struggle to detect and prevent such unauthorized data movement, especially with encrypted data.

Innovation Solution

Implementing a data movement monitoring system that applies rules to network traffic, geo-locates destinations, and takes actions such as quarantining computers when unauthorized data transfer is detected, allowing for flexible rule application across different servers and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is used to protect data during transmission, then data security is improved, but the ability to detect and monitor unauthorized data movement deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddetection of unauthorized data movement
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a data movement monitoring system as an intermediary component that sits between the data source and destination. This monitor collects metadata about data movements (destination addresses, data volumes, frequencies) without needing to decrypt the actual data content. The intermediary approach allows monitoring of encrypted traffic by focusing on connection-level information rather than payload content, thus resolving the contradiction between encryption security and detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts relevant monitoring information from the data transmission process, separating the detection function from the data content itself. By extracting metadata such as destination IP addresses, data volumes, and transmission frequencies, the system can monitor for unauthorized movements without interfering with or decrypting the encrypted data streams. This extraction approach maintains both encryption security and monitoring capability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Difficulty of detecting and measuring

If comprehensive data monitoring is implemented to detect unauthorized transfers, then detection capability is improved, but network complexity and operational overhead worsen

Engineering Contradiction:
Improvedetection capabilityVSAvoidnetwork complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing monitoring rules that are specific to different destinations, data types, and organizational contexts. Rather than a uniform comprehensive monitoring approach, the system allows administrators to define targeted monitoring parameters for specific scenarios (e.g., monitoring large data transfers to external destinations while ignoring internal traffic). This localized approach reduces complexity by focusing monitoring resources only where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The monitoring system segments data movement analysis into distinct components: collecting data movement information, analyzing against predefined rules, and executing actions. This segmentation allows the complex monitoring function to be broken down into manageable modules that can be independently configured and maintained, reducing overall system complexity while maintaining comprehensive detection capability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If strict data movement rules are applied to prevent unauthorized transfers, then data loss prevention is improved, but legitimate business operations may be restricted

Engineering Contradiction:
Improvedata loss preventionVSAvoidbusiness operation flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic monitoring and response through a rules engine that can adapt to different scenarios. The system allows administrators to define conditions for data movements (such as destination criteria, data volume thresholds, frequency patterns) and automatically executes appropriate actions when rules are triggered. This dynamic approach enables the system to prevent actual data losses while allowing legitimate business operations to continue by configuring rules that reflect real business needs rather than applying blanket restrictions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where monitored data movements are continuously evaluated against defined rules, and actions are automatically executed based on rule violations. The feedback loop allows the system to learn from patterns and adjust monitoring behavior, enabling sophisticated differentiation between legitimate business traffic and malicious data exfiltration attempts, thus balancing security with operational flexibility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8839425B1Destination-specific network management
Publication Date: 2014.09.16 IBOSS INC
  • US8839425B1 patent drawing
  • US8839425B1 patent drawing
  • US8839425B1 patent drawing

AI summary

Methods and systems for providing destination-specific network management are described. One example method includes identifying a data movement rule associated with a set of one or more computers, the data movement rule including one or more criteria identifying restricted data movement, and one or more actions to take when a computer from the set of computers violates the data movement rule, detecting a data movement associated with a computer from the set of computers, the data movement including data being transferred from the computer to a destination, determining that the detected data movement violates the data movement rule, and performing the one or more actions associated with the data movement rule upon determining that the data movement violates the data movement rule.