Distributed Data Reconstruction for Fragmented Exfiltration Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to detect and prevent the exfiltration of confidential information in distributed networks, particularly when data is fragmented and obfuscated through methods like breaking it up into smaller pieces, using cryptography, and collaborating with multiple individuals, making it difficult to trace and analyze effectively.

Innovation Solution

A system for data protection in a distributed network that reconstructs and analyzes data segments by initiating network flow analysis, isolating specialized access nodes, capturing discrete data segments, constructing arrangements, and using a sensitive information detection engine to determine the presence of sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is fragmented into smaller pieces and distributed across multiple nodes, then data protection is improved, but detection capability deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments data into discrete data segments distributed across multiple specialized access nodes in the network. Each node holds only a portion of the complete information, making it difficult for insiders to exfiltrate meaningful data while maintaining protection. The segmentation is implemented through network flow analysis that identifies and isolates specific nodes containing particular data segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary detection mechanism that reconstructs data segments from multiple nodes to analyze for sensitive information. Rather than directly monitoring each node, the system uses network flow analysis as an intermediary to capture, reconstruct, and evaluate data segments, enabling detection without compromising the protective fragmentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual analysis of data segments is performed, then detection accuracy is improved, but productivity deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements self-service through automated network flow analysis that performs data segment reconstruction and sensitive information detection without manual intervention. The automated analysis engine evaluates reconstructed segments to identify potential insider threats, maintaining high detection accuracy while eliminating the time and resource costs of manual analysis.

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If complete data is monitored for exfiltration, then detection capability is improved, but resource consumption deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidcomputing resources
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The system extracts only the necessary data segments from specialized access nodes for analysis, rather than monitoring complete data flows. By isolating and analyzing only the discrete segments that could potentially constitute sensitive information when combined, the system maintains detection capability while significantly reducing computing resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12363176B2System and method for data protection in a distributed network via reconstruction and analysis of data segments
Publication Date: 2025.07.15 BANK OF AMERICA CORP
  • US12363176B2 patent drawing
  • US12363176B2 patent drawing
  • US12363176B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for data protection in a distributed network via reconstruction and analysis of data segments. The present invention is configured to initiate a network flow analysis to assign indicators to specialized access nodes of a network diagram, execute a first cut to remove predetermined nodes, store the corresponding discrete data segments for each of the first plurality of electronic communications at the nodes, construct a first arrangement of a selected group of the corresponding discrete data segments, determine a presence of sensitive information, and construct additional arrangements of the selected group of the corresponding discrete data segments to determine a presence of sensitive information.