Network Data Awareness via Passive Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Data Leak Prevention (DLP) systems assume that the location of company data is known, which is often not the case, leading to inefficiencies in monitoring and securing data as it moves across networks, especially in dynamic environments where data is shared through emails and file shares rather than file servers.
Innovation Solution
A system that passively analyzes network traffic to catalog attributes of data in motion, such as file names, hashes, user roles, and access maps, without prior knowledge of the data's location, using sensors and processors to generate real-time profiles and detect inappropriate usage, and embeds 'honeytokens' to track file movement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional DLP systems assume known data locations, then monitoring can be simplified, but the system fails to track data in dynamic environments where data moves through emails and file shares
Solution Approach 1:
The system performs preliminary actions by proactively scanning and cataloging data locations and movements before security incidents occur. Sensors continuously monitor network traffic to identify where company data is stored and how it moves, building a baseline map of data locations and access patterns that enables future security enforcement
Solution Approach 2:
The patent introduces sensors as intermediary components that passively monitor network traffic between data sources and destinations. These sensors act as mediators that observe data movements without interfering with normal operations, capturing information about file transfers, email attachments, and shared resources to build comprehensive data location maps
2Loss of information
If the system passively analyzes network traffic to catalog data attributes, then real-time data awareness is achieved, but processing complexity increases
Solution Approach 1:
The system segments the complex task of data monitoring into distinct functional components: sensors that passively capture network traffic, processing modules that analyze traffic patterns, and cataloging systems that organize data location information. This segmentation allows each component to specialize in specific tasks, reducing overall system complexity while maintaining comprehensive monitoring capabilities
Solution Approach 2:
The system creates copies of data metadata and location information from network traffic without needing to handle the actual data files. By cataloging attributes such as file names, hashes, user roles, and access patterns rather than duplicating the files themselves, the system achieves real-time awareness while minimizing processing complexity and storage requirements
3Reliability
If honeytokens are embedded to track file movement, then unauthorized access detection is improved, but file integrity may be compromised
Solution Approach 1:
The system applies local quality by embedding honeytokens in specific non-critical portions of files rather than uniformly throughout. Honeytokens are placed in designated areas such as file headers, metadata sections, or unused space, allowing the file to maintain its functional integrity while containing trackable elements that can detect unauthorized access or modification
Data Source
AI summary
A system includes a sensor and a processor. The sensor is configured to passively read data in packets as the packets are in motion on a network. The processor is cooperatively operable with the sensor. The processor is configured to receive the read data from the sensor; and originate map profiles of files and file data, both from the read data from the sensor, as the passively read packets are in motion on the network. The processor is also configured to infer a user role for a user who is using the file and the file data and how the user is transferring or accessing the file and the file data. Inappropriate usage being performed by the user can then be detected from the user role and the read data to control access to particular files.


