Network Data Transmission Analysis for DLP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The administration and management of data loss prevention (DLP) systems in packet-switched communication networks, especially those with virtualized environments, have become increasingly complex due to the scale and scope of data transmission, requiring more sophisticated monitoring and routing solutions.
Innovation Solution
The implementation of network data transmission analysis systems that utilize contextual information based on organizational structure and services, rather than network topology, to monitor and manage data transmissions across virtual networks overlaid on intermediate physical networks, allowing for enhanced security and compliance with regulations through advanced routing and packet analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network data transmission monitoring is implemented using traditional network topology-based methods, then data loss prevention coverage is achieved, but system complexity and difficulty of management increase significantly
Solution Approach 1:
The patent introduces a network translation device as an intermediary component that sits between the virtual network and substrate network. This device translates virtual network addresses to substrate network addresses, enabling monitoring and control functions without requiring direct integration into the complex virtualized network infrastructure, thus reducing system complexity while maintaining DLP coverage
Solution Approach 2:
The patent creates a simplified copy or abstraction of the network monitoring function through the network translation device. Instead of implementing complex monitoring throughout the entire virtualized network, the system uses the translation device to capture and analyze traffic at a strategic point, providing effective DLP with reduced complexity
2Measurement precision
If comprehensive network flow monitoring is implemented in virtualized environments, then security detection capability is improved, but administrative complexity increases
Solution Approach 1:
The network translation device serves as an intermediary that simplifies administrative operations by providing a single point of control for monitoring and managing network flows. Administrators can configure and manage security policies at the translation device rather than dealing with the complexity of the entire virtualized network infrastructure
Solution Approach 2:
The network translation device performs multiple functions including address translation, packet filtering, and flow monitoring within a single unified system. This multi-functionality reduces administrative complexity by consolidating what would otherwise require multiple separate systems and management interfaces
3Adaptability or versatility
If virtual network routing is implemented over substrate networks, then network flexibility and virtualization capabilities are improved, but difficulty of detecting and measuring network flows increases
Solution Approach 1:
The network translation device acts as an intermediary that makes virtual network flows detectable and measurable. By positioning the device at the boundary between virtual and substrate networks, it can capture traffic information that would otherwise be hidden within the virtualized environment, enabling effective monitoring while preserving network flexibility
Solution Approach 2:
The patent employs address translation that can be thought of as a form of identification change. The network translation device translates virtual addresses to substrate addresses, effectively 'changing the color' or identification of packets as they cross the boundary, making them detectable and measurable by substrate network monitoring systems
Data Source
AI summary
Network computing systems may implement data loss prevention (DLP) techniques to reduce or prevent unauthorized use or transmission of confidential information or to implement information controls mandated by statute, regulation, or industry standard. Implementations of network data transmission analysis systems and methods are disclosed that can use contextual information in a DLP policy to monitor data transmitted via the network. The contextual information may include information based on a network user's organizational structure or services or network infrastructure. Some implementations may detect bank card information in network data transmissions. Some of the systems and methods may be implemented on a virtual network overlaid on one or more intermediate physical networks that are used as a substrate network.


