Network Data Transmission Analysis for DLP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The administration and management of data loss prevention (DLP) systems in packet-switched communication networks, especially those with virtualized environments, have become increasingly complex due to the scale and scope of data transmission, requiring more sophisticated monitoring and routing solutions.

Innovation Solution

The implementation of network data transmission analysis systems that utilize contextual information based on organizational structure and services, rather than network topology, to monitor and manage data transmissions across virtual networks overlaid on intermediate physical networks, allowing for enhanced security and compliance with regulations through advanced routing and packet analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network data transmission monitoring is implemented using traditional network topology-based methods, then data loss prevention coverage is achieved, but system complexity and difficulty of management increase significantly

Engineering Contradiction:
Improvedata loss prevention coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network translation device as an intermediary component that sits between the virtual network and substrate network. This device translates virtual network addresses to substrate network addresses, enabling monitoring and control functions without requiring direct integration into the complex virtualized network infrastructure, thus reducing system complexity while maintaining DLP coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a simplified copy or abstraction of the network monitoring function through the network translation device. Instead of implementing complex monitoring throughout the entire virtualized network, the system uses the translation device to capture and analyze traffic at a strategic point, providing effective DLP with reduced complexity

Inventive Principle:
Principle #26Copying

2Measurement precision

If comprehensive network flow monitoring is implemented in virtualized environments, then security detection capability is improved, but administrative complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidadministrative complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The network translation device serves as an intermediary that simplifies administrative operations by providing a single point of control for monitoring and managing network flows. Administrators can configure and manage security policies at the translation device rather than dealing with the complexity of the entire virtualized network infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network translation device performs multiple functions including address translation, packet filtering, and flow monitoring within a single unified system. This multi-functionality reduces administrative complexity by consolidating what would otherwise require multiple separate systems and management interfaces

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If virtual network routing is implemented over substrate networks, then network flexibility and virtualization capabilities are improved, but difficulty of detecting and measuring network flows increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidnetwork flow detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The network translation device acts as an intermediary that makes virtual network flows detectable and measurable. By positioning the device at the boundary between virtual and substrate networks, it can capture traffic information that would otherwise be hidden within the virtualized environment, enabling effective monitoring while preserving network flexibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent employs address translation that can be thought of as a form of identification change. The network translation device translates virtual addresses to substrate addresses, effectively 'changing the color' or identification of packets as they cross the boundary, making them detectable and measurable by substrate network monitoring systems

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS8416709B1Network data transmission analysis management
Publication Date: 2013.04.09 AMAZON TECH INC
  • US8416709B1 patent drawing
  • US8416709B1 patent drawing
  • US8416709B1 patent drawing

AI summary

Network computing systems may implement data loss prevention (DLP) techniques to reduce or prevent unauthorized use or transmission of confidential information or to implement information controls mandated by statute, regulation, or industry standard. Implementations of network data transmission analysis systems and methods are disclosed that can use contextual information in a DLP policy to monitor data transmitted via the network. The contextual information may include information based on a network user's organizational structure or services or network infrastructure. Some implementations may detect bank card information in network data transmissions. Some of the systems and methods may be implemented on a virtual network overlaid on one or more intermediate physical networks that are used as a substrate network.