File Hash Tracking for Data Leakage Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems are inadequate in detecting and preventing data leakage and document propagation, especially in cloud-based services, due to limitations in monitoring and encryption, and struggle to manage complex network environments where sensitive data is at risk of unauthorized access and misuse.
Innovation Solution
A system and method using file hashes to track data leakage and document propagation by creating tables of file hashes, names, and paths on known reference systems, with active scanners collecting information from network devices and comparing it to the reference systems to identify unique or anomalous files, and employing matching and analytical algorithms to detect deviations and generate alerts for potential security breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud-based services are used to enable file sharing and collaboration, then user productivity and accessibility are improved, but data security and compliance control are worsened
Solution Approach 1:
The patent introduces an intermediary system that sits between cloud-based file sharing services and the network security infrastructure. This intermediary captures, inspects, and monitors file access and transmission events, enabling security control without blocking productivity-enhancing cloud services. The intermediary acts as a mediator that allows legitimate cloud collaboration while preventing data leakage.
2Reliability
If traditional network security systems are used to monitor data, then security control is maintained, but detection capability for cloud-based threats is worsened
Solution Approach 1:
The patent extends security monitoring from traditional network-layer inspection to include application-layer and cloud-service-layer observations. By adding this new dimension of monitoring that specifically targets cloud-based file sharing activities, the system detects threats that traditional network security systems miss, while maintaining overall security control.
3Reliability
If SSL encryption is used to protect data transmission, then data confidentiality is improved, but security vulnerability to advanced attacks is worsened
Solution Approach 1:
The patent implements feedback mechanisms that continuously monitor SSL/TLS connections for signs of compromise, such as suspicious certificate authorities or anomalous encryption patterns. When potential vulnerabilities are detected, the system responds by blocking or alerting on suspicious traffic, creating a feedback loop that maintains confidentiality while mitigating advanced threats.
Data Source
AI summary
In some embodiments, a set of hashes that are associated with files of a user system, and a reference set of hashes that are associated with files of a reference system, may be obtained. An additional subset of hashes (included in the set of hashes and not included in the reference set of hashes) may be obtained based on a comparison between the set of hashes and the reference set of hashes. A file may be predicted to be exclusive for certain users or user systems, where the file is associated with a hash included in the additional subset of hashes. Other user systems may be scanned to determine what files are on the other user systems, where each of the other user systems is assigned to another user or is not one of the user systems. An alert indicating unauthorized activity may be generated based on the scan.


