Personal Information Protection Agent for Cross-OS Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing personal information protection systems are inadequate in detecting and protecting personal information across multiple operating systems and network storage areas, particularly due to advanced hacking techniques that disguise remote commands as normal HTTP traffic, and they can only check specific directory areas for data files associated with web servers.

Innovation Solution

A personal information protection apparatus and system that includes an agent installed on terminals running Windows, Linux, or Unix, which checks for monitoring information in local and network storage areas using a Network File System (NFS) scheme, and a management server that provides security policies and monitors databases for unencrypted information, enabling comprehensive protection measures such as encryption and deletion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a personal information protection system checks only specific directory areas associated with web server homepages, then the system can reduce checking scope and improve efficiency, but it fails to detect personal information in other storage areas such as network storage and databases

Engineering Contradiction:
Improvechecking efficiencyVSAvoiddetection completeness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The protection system is designed to perform multiple checking functions across different storage types (local file systems, network storage via NFS, and databases) using a unified architecture. The agent can switch between different checking modes depending on the storage type, making the system universal and adaptable to various environments while maintaining comprehensive detection coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The checking system is divided into specialized modules for different storage types: a first check unit for local files, a second check unit for network storage, and a database check unit for databases. Each module is optimized for its specific storage type, allowing efficient parallel operation while ensuring complete coverage across all storage areas

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If advanced hacking techniques disguise remote commands as normal HTTP traffic, then the hacking method becomes more隐蔽 and difficult to detect, but existing firewall and IDS security functions become insufficient to protect personal information

Engineering Contradiction:
Improvehacking detection difficultyVSAvoidsecurity protection effectiveness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system performs preliminary scanning and detection of personal information in files and databases before they can be accessed or exfiltrated by hackers. By proactively identifying and protecting sensitive data in advance, the system prevents potential data leaks even when advanced hacking techniques are used

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The protection agent acts as an intermediary layer between the file system/database and external access points. It monitors and controls access to personal information, detecting abnormal access patterns that may indicate hacking attempts disguised as normal HTTP traffic, and can block suspicious operations before data exfiltration occurs

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a protection system implements comprehensive checking across all storage areas, then detection coverage is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts its checking behavior based on the type of storage being accessed. When accessing local files, it uses one checking strategy; when accessing network storage via NFS, it uses another optimized strategy; and when checking databases, it employs yet another approach. This dynamic adaptation reduces unnecessary complexity while maintaining comprehensive coverage

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different checking methods and parameters are applied to different storage types based on their specific characteristics. Local files receive full-content scanning, network storage receives structured directory traversal, and databases receive query-based extraction. This localized optimization ensures efficient checking tailored to each storage type's properties

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8949984B2Personal information protection system for providing specialized function for host terminal based on Unix and Linux
Publication Date: 2015.02.03 SOMANSA
  • US8949984B2 patent drawing
  • US8949984B2 patent drawing
  • US8949984B2 patent drawing

AI summary

Provided are an information protection apparatus and system. The information protection apparatus based on Windows, Unix, or Linux includes a first check unit, a second check unit, and a security measure unit. The first check unit checks whether there is a file including monitoring information among a plurality of check target files in a local storage area, according to a predetermined check policy. The second check unit checks whether there is a file including the monitoring information among the check target files in a sharing storage area of a file system that is shared in a network drive type in an NFS scheme. The security measure unit performs a security measure conforming to a predetermined security policy for the file including the monitoring information.