Network Gateway Contextual Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data leakage prevention methods in computer networks rely solely on data type classification, which is insufficient for ensuring secure transmission, as they cannot effectively limit data access to specific users or destinations, leading to potential unauthorized data dissemination.

Innovation Solution

A system and method that utilize a network gateway to determine a transmission policy based on both the type of data and contextual information, such as sender and destination details, to block, permit, or report data transmission, incorporating a classification module, context information module, policy/reporting module, and enforcement module to enforce these policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data classification based on type is used, then data leakage prevention is provided, but the level of prevention is insufficient and cannot limit transmission to specific users or destinations

Engineering Contradiction:
Improvedata leakage prevention effectivenessVSAvoidpolicy granularity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the data transmission control mechanism into multiple independent components: data type classification module, sender context identification module (IP address, user identity), destination context identification module, and policy determination module. Each component handles a specific aspect of transmission control, allowing granular policies to be constructed by combining these segmented elements rather than relying on a single coarse-grained classification approach.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from one-dimensional data type classification to multi-dimensional control by adding contextual dimensions (sender IP address, sender user identity, destination IP address, destination network, destination category). This dimensional expansion enables the system to differentiate between various transmission scenarios and apply appropriate granular policies for each combination of data type and context.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If only data type classification is applied, then transmission policy can be determined, but reliable policy cannot be developed for specific users or destinations

Engineering Contradiction:
Improvepolicy implementation simplicityVSAvoidtransmission control precision
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent introduces a network gateway as an intermediary component between the data source and destination. The gateway contains the classification module, context information module, and policy/reporting module that work together to determine transmission policies. This intermediary structure maintains implementation simplicity by centralizing the complex policy determination logic in one location while allowing precise control over specific users and destinations through contextual information analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If contextual information is added to data classification, then granular and effective data leakage prevention is enabled, but system complexity increases

Engineering Contradiction:
Improvedata leakage prevention effectivenessVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple control functions (data classification, sender identification, destination identification, policy determination, and transmission control) into a single integrated network gateway system. This consolidation reduces overall system complexity by eliminating the need for separate distributed control mechanisms, while still providing granular prevention through the combined use of contextual information and data classification within the unified gateway architecture.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9609001B2System and method for adding context to prevent data leakage over a computer network
Publication Date: 2017.03.28 FORCEPOINT LLC
  • US9609001B2 patent drawing
  • US9609001B2 patent drawing
  • US9609001B2 patent drawing

AI summary

Systems and methods for adding context to prevent data leakage over a computer network are disclosed. Data is classified and contextual information of the data is determined. A transmission policy is determined in response to the classification and contextual information. The data is either transmitted or blocked in response to the classification and the contextual information.