Network Traffic Sampling for Internal Data Leakage Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention solutions fail to effectively monitor and protect unencrypted sensitive information within a network, leaving vulnerabilities as it travels inside the network.
Innovation Solution
A method and system utilizing packet sampling to detect suspected data loss by analyzing sampled traffic data for sensitive information, which includes embedding sampling agents in network devices to generate and forward sampled traffic data to a data collector for analysis, and employing detection policies to identify and remediate sensitive data leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DLP solutions are deployed at network borders (firewall/IDS), then data protection at network boundaries is improved, but monitoring capability for unencrypted sensitive information traveling inside the network deteriorates
Solution Approach 1:
The patent segments the network monitoring function by deploying sampling agents at multiple points throughout the network interior rather than relying solely on border devices. Each sampling agent independently monitors local traffic segments, enabling comprehensive internal monitoring while maintaining the layered security architecture.
Solution Approach 2:
The patent introduces sampling agents as intermediary components between the network traffic and the central data collector. These agents act as mediators that capture traffic samples from various network locations and forward them to the data collector for analysis, enabling internal monitoring without requiring continuous traffic inspection at border devices.
2Measurement precision
If all outgoing data passes through security devices for monitoring, then detection accuracy is improved, but network throughput and performance deteriorate
Solution Approach 1:
The patent extracts only the essential monitoring function from the complete data inspection process. By using packet sampling agents that capture only representative samples of network traffic rather than all traffic, the system maintains detection accuracy for sensitive data while minimizing the impact on overall network throughput.
Solution Approach 2:
The patent applies partial action by sampling a subset of network packets rather than inspecting all traffic. The sampling agents monitor a representative portion of data flow, providing sufficient detection capability without the performance penalty of complete traffic inspection at every device.
3Productivity
If packet sampling is used to monitor network traffic, then network throughput is maintained, but detection precision for sensitive data deteriorates
Solution Approach 1:
The patent implements feedback mechanisms where the data collector receives and analyzes traffic samples from multiple sampling agents, then provides feedback information about detected sensitive data patterns. This feedback loop enables continuous refinement of detection algorithms to improve precision while maintaining the throughput benefits of sampling.
Solution Approach 2:
The patent adds the dimension of centralized analysis by collecting samples from multiple network points to a central data collector that performs comprehensive analysis. This dimensional shift from distributed sampling to centralized processing enables sophisticated pattern recognition that compensates for the inherent limitations of packet sampling.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and systems for detecting suspected date leakage in a network [hat includes a plurality of networked devices is described herein, A packet is received from a networked device of the plurality of networked devices. It is determined that the packet includes sampled traffic data. The sampled traffic data includes a sample of a packet constituting network traffic through the networked device, and the sample includes payload data from the packet constituting network traffic. The payload data of the sampled traffic data is analyzed. It Is determined whether sensitive data is detected in the payload data of the sampled traffic data.