Network Data Awareness via Passive Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Data Leak Prevention (DLP) systems assume that the location of company data is known, which is often not the case, leading to inefficiencies in monitoring and securing data as it moves across networks, especially in dynamic environments where data is shared through emails and file shares rather than file servers.

Innovation Solution

A system that passively analyzes network traffic to catalog attributes of data in motion, such as file names, hashes, user roles, and access maps, without prior knowledge of the data's location, using sensors and processors to generate real-time profiles and detect inappropriate usage, and embeds 'honeytokens' to track file movement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional DLP systems assume known data locations, then monitoring can be simplified, but the system fails to track data in dynamic environments where data moves through emails and file shares

Engineering Contradiction:
Improvemonitoring simplicityVSAvoiddata tracking capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by proactively scanning and cataloging data locations and movements before security incidents occur. Sensors continuously monitor network traffic to identify where company data is stored and how it moves, building a baseline map of data locations and access patterns that enables future security enforcement

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces sensors as intermediary components that passively monitor network traffic between data sources and destinations. These sensors act as mediators that observe data movements without interfering with normal operations, capturing information about file transfers, email attachments, and shared resources to build comprehensive data location maps

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If the system passively analyzes network traffic to catalog data attributes, then real-time data awareness is achieved, but processing complexity increases

Engineering Contradiction:
Improvedata location awarenessVSAvoidprocessing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the complex task of data monitoring into distinct functional components: sensors that passively capture network traffic, processing modules that analyze traffic patterns, and cataloging systems that organize data location information. This segmentation allows each component to specialize in specific tasks, reducing overall system complexity while maintaining comprehensive monitoring capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates copies of data metadata and location information from network traffic without needing to handle the actual data files. By cataloging attributes such as file names, hashes, user roles, and access patterns rather than duplicating the files themselves, the system achieves real-time awareness while minimizing processing complexity and storage requirements

Inventive Principle:
Principle #26Copying

3Reliability

If honeytokens are embedded to track file movement, then unauthorized access detection is improved, but file integrity may be compromised

Engineering Contradiction:
Improveunauthorized access detectionVSAvoidfile integrity
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system applies local quality by embedding honeytokens in specific non-critical portions of files rather than uniformly throughout. Honeytokens are placed in designated areas such as file headers, metadata sections, or unused space, allowing the file to maintain its functional integrity while containing trackable elements that can detect unauthorized access or modification

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9584535B2System and method for real time data awareness
Publication Date: 2017.02.28 CISCO TECHNOLOGY INC
  • US9584535B2 patent drawing
  • US9584535B2 patent drawing
  • US9584535B2 patent drawing

AI summary

A system includes a sensor and a processor. The sensor is configured to passively read data in packets as the packets are in motion on a network. The processor is cooperatively operable with the sensor. The processor is configured to receive the read data from the sensor; and originate map profiles of files and file data, both from the read data from the sensor, as the passively read packets are in motion on the network. The processor is also configured to infer a user role for a user who is using the file and the file data and how the user is transferring or accessing the file and the file data. Inappropriate usage being performed by the user can then be detected from the user role and the read data to control access to particular files.