Network Traffic Sampling for Internal Data Leakage Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention solutions fail to effectively monitor and protect unencrypted sensitive information within a network, leaving vulnerabilities as it travels inside the network.

Innovation Solution

A method and system utilizing packet sampling to detect suspected data loss by analyzing sampled traffic data for sensitive information, which includes embedding sampling agents in network devices to generate and forward sampled traffic data to a data collector for analysis, and employing detection policies to identify and remediate sensitive data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DLP solutions are deployed at network borders (firewall/IDS), then data protection at network boundaries is improved, but monitoring capability for unencrypted sensitive information traveling inside the network deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidmonitoring capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the network monitoring function by deploying sampling agents at multiple points throughout the network interior rather than relying solely on border devices. Each sampling agent independently monitors local traffic segments, enabling comprehensive internal monitoring while maintaining the layered security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces sampling agents as intermediary components between the network traffic and the central data collector. These agents act as mediators that capture traffic samples from various network locations and forward them to the data collector for analysis, enabling internal monitoring without requiring continuous traffic inspection at border devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If all outgoing data passes through security devices for monitoring, then detection accuracy is improved, but network throughput and performance deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the essential monitoring function from the complete data inspection process. By using packet sampling agents that capture only representative samples of network traffic rather than all traffic, the system maintains detection accuracy for sensitive data while minimizing the impact on overall network throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by sampling a subset of network packets rather than inspecting all traffic. The sampling agents monitor a representative portion of data flow, providing sufficient detection capability without the performance penalty of complete traffic inspection at every device.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If packet sampling is used to monitor network traffic, then network throughput is maintained, but detection precision for sensitive data deteriorates

Engineering Contradiction:
Improvenetwork throughputVSAvoiddetection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the data collector receives and analyzes traffic samples from multiple sampling agents, then provides feedback information about detected sensitive data patterns. This feedback loop enables continuous refinement of detection algorithms to improve precision while maintaining the throughput benefits of sampling.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent adds the dimension of centralized analysis by collecting samples from multiple network points to a central data collector that performs comprehensive analysis. This dimensional shift from distributed sampling to centralized processing enables sophisticated pattern recognition that compensates for the inherent limitations of packet sampling.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2633646B1Methods and systems for detecting suspected data leakage using traffic samples
Publication Date: 2019.11.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • EP2633646B1 patent drawingFigure 1
  • EP2633646B1 patent drawingFigure 2
  • EP2633646B1 patent drawingFigure 3

AI summary

Methods and systems for detecting suspected date leakage in a network [hat includes a plurality of networked devices is described herein, A packet is received from a networked device of the plurality of networked devices. It is determined that the packet includes sampled traffic data. The sampled traffic data includes a sample of a packet constituting network traffic through the networked device, and the sample includes payload data from the packet constituting network traffic. The payload data of the sampled traffic data is analyzed. It Is determined whether sensitive data is detected in the payload data of the sampled traffic data.