File Tagging for Automated External Network Leak Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting unauthorized access to confidential information in internal networks are not automated and require manual selection and preparation of files, making it difficult to monitor and secure large numbers of files when transmitted to external networks.

Innovation Solution

A computing system and method that automates the identification of files transmitted from an internal network to an external network by using an insertion device to generate tagged data files, which are then monitored by a server upon opening or processing, allowing for real-time detection of security leaks through embedded data file elements that trigger responses to a monitoring server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual selection and preparation of files is used for detection, then detection accuracy for individual files is improved, but productivity and scalability to large numbers of files deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidfile monitoring throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary actions by automatically inserting tracking objects into files before they are transmitted to external networks. This preliminary tagging enables automated identification and monitoring of confidential information without requiring manual selection or preparation of each file, thus maintaining detection accuracy while dramatically improving productivity and scalability across large numbers of files.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated file tagging is implemented, then productivity and scalability are improved, but device complexity increases

Engineering Contradiction:
Improveautomated file monitoring capacityVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves automated file monitoring scalability by implementing a universal tagging mechanism that can be applied to any file type transmitted through the network. The tracking object serves multiple functions: it identifies confidential information, enables automated detection, and provides a standardized interface for monitoring. This multi-functionality reduces the need for separate manual processes for different file types, thereby improving productivity while managing system complexity through a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If tracking objects are embedded in all files, then detection completeness is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection completenessVSAvoidfile processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial action by selectively embedding tracking objects in files that contain confidential information rather than all files. The automated detection system identifies which files require tagging based on their content and transmission destination, applying the tracking mechanism only where necessary. This approach maintains detection completeness for confidential information while reducing overall processing time and computational resource consumption compared to universal tagging of all files.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2963864B1Computing system and method for identifying files transmitted to an external network
Publication Date: 2019.04.24 VOLKSWAGEN AG
  • EP2963864B1 patent drawingFigure 1
  • EP2963864B1 patent drawingFigure 1
  • EP2963864B1 patent drawingFigure 2A~2D

AI summary

The invention relates to a computing system (), and more particularly to a computing system and a method for identifying files transmitted from an internal computing device within an internal network to an external computing device (3) within an external network (2). The computing system comprises one or more internal computing devices which are connectable by an internal network. At least one of the internal computing devices is configured to be operable as a workstation (4,4') or as a file server (8), wherein the workstation or the file server is capable of generating, storing and/or transmitting a data file (20). Further, at least one of the internal computing devices is configured to be operable as an insertion device (6). The insertion device is capable of inserting a data file element (21) into the data file to generate a tagged data file (22). Further, at least one of the internal computing devices is configured to be operable as a gateway (5). The gateway is capable of connecting the internal network to an external network (2). Further, at least one computing device is configured to be operable as a monitoring server (7). The monitoring server (7) is capable of receiving information transmitted by an external computing device (3) connected to the external network (2) upon opening, reading and/or processing the tagged data file (22).