Document Signature Generation for Unauthorized Data Transmission Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network systems lack a comprehensive solution to capture, store, and analyze data transmitted over the network, failing to prevent unauthorized data transmission and monitor for policy violations.

Innovation Solution

A capture system that intercepts and reconstructs outgoing data, generates and stores signatures of documents, and alerts users of unauthorized transmissions, using a network interface module, packet capture module, object assembly module, and registration module to implement document registration and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security tools (firewalls, intrusion detection systems) are used, then network access control is improved, but comprehensive data capture and analysis capability deteriorates

Engineering Contradiction:
Improvenetwork access controlVSAvoiddata capture completeness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the data capture function into multiple components: packet capture module for raw data acquisition, object assembly module for reconstructing complete objects, extraction module for identifying content, and signature generation module for creating detection patterns. This segmentation allows comprehensive data capture while maintaining network security control through modular processing stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by capturing packets before they leave the network, assembling complete objects from fragmented packets, extracting content before transmission, and generating signatures in advance. This preliminary processing enables comprehensive data capture and analysis while preventing unauthorized data exfiltration.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If no document registration system is implemented, then network device complexity is reduced, but ability to track unauthorized data transmission deteriorates

Engineering Contradiction:
Improvenetwork device structureVSAvoidunauthorized transmission detection
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary registration of documents and generation of signatures before any transmission occurs. Documents are registered with the system, signatures are generated and stored, and these signatures are then used to detect unauthorized transmissions. This preliminary setup enables effective detection without requiring complex real-time analysis during transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of documents and generates signatures that represent the document content without storing the actual document data. These signatures act as fingerprints that can be used for detection and tracking, reducing the complexity of handling and storing original documents while maintaining detection capability.

Inventive Principle:
Principle #26Copying

3Loss of information

If comprehensive data capture is implemented, then monitoring capability is improved, but data processing time deteriorates

Engineering Contradiction:
Improvedata monitoring capabilityVSAvoiddata processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system extracts only the necessary information from captured packets and documents for signature generation and monitoring purposes. By extracting content, generating signatures, and storing only these signatures rather than complete documents, the system maintains comprehensive monitoring capability while significantly reducing data processing time and storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the representation of data from raw packet formats to normalized extracted content, then to compact signatures. This parameter transformation reduces the amount of data that needs to be processed and stored, improving processing speed while maintaining the ability to detect unauthorized transmissions through signature matching.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7434058B2Generating signatures over a document
Publication Date: 2008.10.07 MCAFEE LLC
  • US7434058B2 patent drawing
  • US7434058B2 patent drawing
  • US7434058B2 patent drawing

AI summary

A document accessible over a network can be registered. A registered document, and the content contained therein, cannot be transmitted undetected over and off of the network. In one embodiment, the invention includes maintaining a plurality of stored signatures over a registered document. In one embodiment, the plurality of stored signatures are generated by extracting content from the document, normalizing the extracted content, and generating the plurality of signatures using the normalized content.