TCP Packet Source User Identity for Network Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network data leakage prevention systems struggle to differentiate between legitimate and illegitimate user access, often blocking legitimate transmissions due to their inability to distinguish between users sharing the same IP address, leading to disruptions in business operations.

Innovation Solution

A method and system that authenticate and authorize users by including source user-based information in TCP data packets, using shared secrets and message authentication codes to verify user identity and enforce network policies, allowing or blocking sensitive information transmissions based on user authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network DLP inspects data traffic to detect and prevent illegal transmission of sensitive data, then data leakage prevention capability is improved, but legitimate access to sensitive data may be blocked

Engineering Contradiction:
Improvedata leakage prevention capabilityVSAvoidlegitimate access to sensitive data
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the user identification process by introducing source user information fields in TCP packet headers, separating the IP address identification from the actual user identity. This allows the system to distinguish between different users sharing the same IP address, enabling precise differentiation between legitimate and illegitimate access patterns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses source user information as an intermediary element between the IP address and the actual user identity. This intermediary field carries authentication tokens or user identifiers that mediate the decision-making process, allowing the DLP system to make informed decisions about whether to allow or block data transmission based on verified user identity rather than just IP address.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If network DLP associates user identity with IP address, then implementation simplicity is improved, but ability to distinguish legitimate access from illegal leakage deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidability to distinguish legitimate access from illegal leakage
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent adds another dimension to the user identification process by introducing source user information fields alongside the existing IP address fields in TCP packet headers. This dimensional expansion allows the system to distinguish between multiple users sharing the same IP address by examining the additional user identity dimension carried in the packet header.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent performs preliminary authentication by requiring users to provide source user information (such as authentication tokens or user identifiers) before data transmission occurs. This preliminary action verifies user identity in advance, allowing the DLP system to make accurate distinctions between legitimate and illegitimate access patterns before data leakage prevention decisions are made.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network DLP blocks transmissions without source user information, then security is improved, but business operation continuity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidbusiness operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where the DLP system requests source user information from users when it detects sensitive data transmission without proper identification. This feedback loop allows the system to verify user identity and authorization status, enabling security decisions based on authenticated information rather than blocking all transmissions indiscriminately.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the parameter used for identification from IP address alone to IP address combined with source user information fields. This parameter change enables the system to maintain security by verifying user identity while allowing business operations to continue by making more accurate differentiation between legitimate and illegitimate transmissions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10015145B2Unified source user checking of TCP data packets for network data leakage prevention
Publication Date: 2018.07.03 QUEST SOFTWARE INC
  • US10015145B2 patent drawing
  • US10015145B2 patent drawing
  • US10015145B2 patent drawing

AI summary

Systems and methods are directed towards network data leakage prevention (DLP). More specifically, the systems and methods are directed towards using TCP (Transmission Control Protocol) data packets in conjunction with the DLP monitor. The network DLP utilizes TCP data packets to carry source user identity. With the source user identity, the DLP monitor can determine if sensitive data can be transmitted based on the provided user information and corresponding DLP policies for each user. Furthermore, the DLP monitor can determine if sensitive data can also be transmitted for particular users in situations where multiple users share the same IP address.