File Tagging for Automated External Network Leak Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting unauthorized access to confidential information in internal networks are not automated and require manual selection and preparation of files, making it difficult to monitor and secure large numbers of files when transmitted to external networks.
Innovation Solution
A computing system and method that automates the identification of files transmitted from an internal network to an external network by using an insertion device to generate tagged data files, which are then monitored by a server upon opening or processing, allowing for real-time detection of security leaks through embedded data file elements that trigger responses to a monitoring server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual selection and preparation of files is used for detection, then detection accuracy for individual files is improved, but productivity and scalability to large numbers of files deteriorates
Solution Approach 1:
The system performs preliminary actions by automatically inserting tracking objects into files before they are transmitted to external networks. This preliminary tagging enables automated identification and monitoring of confidential information without requiring manual selection or preparation of each file, thus maintaining detection accuracy while dramatically improving productivity and scalability across large numbers of files.
2Productivity
If automated file tagging is implemented, then productivity and scalability are improved, but device complexity increases
Solution Approach 1:
The system achieves automated file monitoring scalability by implementing a universal tagging mechanism that can be applied to any file type transmitted through the network. The tracking object serves multiple functions: it identifies confidential information, enables automated detection, and provides a standardized interface for monitoring. This multi-functionality reduces the need for separate manual processes for different file types, thereby improving productivity while managing system complexity through a unified approach.
3Reliability
If tracking objects are embedded in all files, then detection completeness is improved, but processing time and computational resources increase
Solution Approach 1:
The system applies partial action by selectively embedding tracking objects in files that contain confidential information rather than all files. The automated detection system identifies which files require tagging based on their content and transmission destination, applying the tracking mechanism only where necessary. This approach maintains detection completeness for confidential information while reducing overall processing time and computational resource consumption compared to universal tagging of all files.
Data Source
Figure 1
Figure 1
Figure 2A~2D
AI summary
The invention relates to a computing system (), and more particularly to a computing system and a method for identifying files transmitted from an internal computing device within an internal network to an external computing device (3) within an external network (2). The computing system comprises one or more internal computing devices which are connectable by an internal network. At least one of the internal computing devices is configured to be operable as a workstation (4,4') or as a file server (8), wherein the workstation or the file server is capable of generating, storing and/or transmitting a data file (20). Further, at least one of the internal computing devices is configured to be operable as an insertion device (6). The insertion device is capable of inserting a data file element (21) into the data file to generate a tagged data file (22). Further, at least one of the internal computing devices is configured to be operable as a gateway (5). The gateway is capable of connecting the internal network to an external network (2). Further, at least one computing device is configured to be operable as a monitoring server (7). The monitoring server (7) is capable of receiving information transmitted by an external computing device (3) connected to the external network (2) upon opening, reading and/or processing the tagged data file (22).