Network Data Capture System for Policy Violation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network configurations lack a comprehensive system to capture, store, and analyze data transmitted through networks, failing to prevent unauthorized data transmission and monitor for policy violations or track information leaks.

Innovation Solution

A capture system is introduced that intercepts data leaving a network, reconstructs documents, and stores them in a searchable format, using a combination of network interface modules, packet capture modules, object assembly modules, and object classification modules to identify and classify content based on signatures, grammar, and biometrics, and applies capture rules to determine storage or discardment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall and router devices are used to provide basic network security and data forwarding, then network connectivity and basic access control are achieved, but comprehensive data capture, analysis, and prevention of unauthorized transmission are not possible

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple previously separate functions (data capture, reconstruction, classification, analysis, and storage) into a single integrated network security system. The network interface module, packet capture module, object assembly module, object classification module, and data storage module work together as a unified system, eliminating the need for multiple separate devices and improving both security reliability and managing complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network security system performs multiple functions through a single integrated architecture: it captures data packets, reconstructs complete documents, classifies content using multiple methods (signatures, grammar, biometrics), analyzes data for policy violations, stores captured information, and generates reports. This multi-functional approach improves security while avoiding the complexity of coordinating multiple specialized devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If no data capture and analysis system is implemented, then network traffic flows freely, but unauthorized data transmission and policy violations cannot be detected or prevented

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary data capture and reconstruction before analysis and classification occur. By intercepting and assembling complete documents from packet streams early in the process, the system prepares data in advance for multiple classification methods (signatures, grammar analysis, biometrics), enabling comprehensive detection without adding significant complexity to the overall system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The object assembly module acts as an intermediary between packet capture and classification/analysis. It reconstructs complete documents from fragmented packets, providing a unified intermediate representation that facilitates subsequent classification using multiple methods and improves detection capability while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple classification methods (signatures, grammar, biometrics) are used to identify content, then classification accuracy and detection precision are improved, but processing time and computational resources increase

Engineering Contradiction:
Improveclassification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The classification process is segmented into multiple independent methods (signatures, grammar analysis, biometrics) that can operate in parallel on the same document. This segmentation allows the system to apply different classification techniques simultaneously, improving overall accuracy while managing processing time through parallel execution rather than sequential processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies multiple classification methods beyond what a single method could provide. By using signatures, grammar analysis, and biometrics together, the system performs excessive classification actions that ensure high accuracy in identifying content, even though this requires more computational resources and time than a single method would require.

Inventive Principle:
Principle #16Partial or excessive action

4Loss of information

If all transmitted data is captured and stored for analysis, then comprehensive monitoring and tracking of information leaks are achieved, but storage requirements and data processing load increase

Engineering Contradiction:
Improveinformation tracking capabilityVSAvoiddata storage volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system extracts only the essential information from captured data packets by reconstructing complete documents and identifying key content through classification. Rather than storing all raw packet data, the system extracts and stores reconstructed documents with associated metadata and classification results, reducing storage requirements while maintaining comprehensive tracking capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates simplified copies of transmitted data in the form of reconstructed documents with extracted metadata and classification information. These copies retain the essential information needed for tracking and analysis while requiring significantly less storage space than the original complete data sets, enabling comprehensive monitoring with manageable storage requirements.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8635706B2System and method for data mining and security policy management
Publication Date: 2014.01.21 MCAFEE LLC
  • US8635706B2 patent drawing
  • US8635706B2 patent drawing
  • US8635706B2 patent drawing

AI summary

A system and method to generate and maintain controlled growth DAG are described. The controlled growth DAG conveys information about objects captured by a capture system.