File Hash Tracking for Data Leakage Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems are inadequate in detecting and preventing data leakage and document propagation, especially in cloud-based services, due to limitations in monitoring and encryption, and struggle to manage complex network environments where sensitive data is at risk of unauthorized access and misuse.

Innovation Solution

A system and method using file hashes to track data leakage and document propagation by creating tables of file hashes, names, and paths on known reference systems, with active scanners collecting information from network devices and comparing it to the reference systems to identify unique or anomalous files, and employing matching and analytical algorithms to detect deviations and generate alerts for potential security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud-based services are used to enable file sharing and collaboration, then user productivity and accessibility are improved, but data security and compliance control are worsened

Engineering Contradiction:
Improveuser productivityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary system that sits between cloud-based file sharing services and the network security infrastructure. This intermediary captures, inspects, and monitors file access and transmission events, enabling security control without blocking productivity-enhancing cloud services. The intermediary acts as a mediator that allows legitimate cloud collaboration while preventing data leakage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional network security systems are used to monitor data, then security control is maintained, but detection capability for cloud-based threats is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extends security monitoring from traditional network-layer inspection to include application-layer and cloud-service-layer observations. By adding this new dimension of monitoring that specifically targets cloud-based file sharing activities, the system detects threats that traditional network security systems miss, while maintaining overall security control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If SSL encryption is used to protect data transmission, then data confidentiality is improved, but security vulnerability to advanced attacks is worsened

Engineering Contradiction:
Improvedata confidentialityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms that continuously monitor SSL/TLS connections for signs of compromise, such as suspicious certificate authorities or anomalous encryption patterns. When potential vulnerabilities are detected, the system responds by blocking or alerting on suspicious traffic, creating a feedback loop that maintains confidentiality while mitigating advanced threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10447654B2System and method for facilitating data leakage and/or propagation tracking
Publication Date: 2019.10.15 TENABLE INC
  • US10447654B2 patent drawing
  • US10447654B2 patent drawing
  • US10447654B2 patent drawing

AI summary

In some embodiments, a set of hashes that are associated with files of a user system, and a reference set of hashes that are associated with files of a reference system, may be obtained. An additional subset of hashes (included in the set of hashes and not included in the reference set of hashes) may be obtained based on a comparison between the set of hashes and the reference set of hashes. A file may be predicted to be exclusive for certain users or user systems, where the file is associated with a hash included in the additional subset of hashes. Other user systems may be scanned to determine what files are on the other user systems, where each of the other user systems is assigned to another user or is not one of the user systems. An alert indicating unauthorized activity may be generated based on the scan.