Filtering Hidden Data in Media Files via Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for methods and systems to resist the spread of media files containing malware or sensitive information embedded in human-imperceptible forms, as existing technologies fail to effectively filter out such hidden data from network traffic.

Innovation Solution

A network security device captures and analyzes network traffic to extract media files, identifying hidden data items like barcodes or digital watermarks, and takes appropriate actions based on predefined security policies, using signature matching and decoding techniques to determine the safety of the media files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If media files are transmitted through network traffic, then information exchange is enabled, but hidden malware or sensitive information embedded in human-imperceptible forms can spread

Engineering Contradiction:
Improveinformation exchangeVSAvoidmalware spread
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing security scanning and analysis on media files before they are allowed to propagate through the network. The system proactively detects hidden data items such as barcodes, digital watermarks, and steganographic content embedded in media files, and takes preventive measures by blocking or quarantining suspicious files before they can execute malware or leak sensitive information. This advance detection and prevention mechanism resolves the contradiction by maintaining information exchange while eliminating harmful factors beforehand.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If hidden data detection is performed on all media files, then network security is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by implementing selective and targeted detection strategies rather than uniform processing of all media files. The system analyzes specific characteristics and patterns indicative of hidden data embedding, such as unusual file properties, metadata anomalies, or specific structural features associated with barcodes and watermarks. By focusing computational resources on suspicious or high-risk files rather than processing every media file equally, the system maintains high security reliability while reducing overall processing time and resource consumption.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If advanced decoding techniques are used to identify hidden data, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by breaking down the complex task of hidden data detection into multiple specialized modules and components. The system divides the analysis process into distinct stages such as initial file assessment, targeted decoding attempts, pattern recognition, and threat evaluation. Each module handles a specific aspect of detection, allowing the system to achieve high detection precision through coordinated specialized functions rather than a single monolithic complex system. This modular approach manages device complexity by organizing functions into manageable, independent segments.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10097514B2Filtering hidden data embedded in media files
Publication Date: 2018.10.09 FORTINET INC
  • US10097514B2 patent drawing
  • US10097514B2 patent drawing
  • US10097514B2 patent drawing

AI summary

Systems and methods for filtering unsafe content by a network security device are provided. According to one embodiment, a network security device captures network traffic and extracts a media file from the network traffic. The network security device then determines the presence of a hidden data item embedded in the media file in a machine-readable form. When such a hidden data item is identified, the network security device performs one or more actions on the media file based on a predefined security policy.