TCP Packet Source User Identity for Network Data Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network data leakage prevention systems struggle to differentiate between legitimate and illegitimate user access, often blocking legitimate transmissions due to their inability to distinguish between users sharing the same IP address, leading to disruptions in business operations.
Innovation Solution
A method and system that authenticate and authorize users by including source user-based information in TCP data packets, using shared secrets and message authentication codes to verify user identity and enforce network policies, allowing or blocking sensitive information transmissions based on user authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network DLP inspects data traffic to detect and prevent illegal transmission of sensitive data, then data leakage prevention capability is improved, but legitimate access to sensitive data may be blocked
Solution Approach 1:
The patent segments the user identification process by introducing source user information fields in TCP packet headers, separating the IP address identification from the actual user identity. This allows the system to distinguish between different users sharing the same IP address, enabling precise differentiation between legitimate and illegitimate access patterns.
Solution Approach 2:
The patent uses source user information as an intermediary element between the IP address and the actual user identity. This intermediary field carries authentication tokens or user identifiers that mediate the decision-making process, allowing the DLP system to make informed decisions about whether to allow or block data transmission based on verified user identity rather than just IP address.
2Device complexity
If network DLP associates user identity with IP address, then implementation simplicity is improved, but ability to distinguish legitimate access from illegal leakage deteriorates
Solution Approach 1:
The patent adds another dimension to the user identification process by introducing source user information fields alongside the existing IP address fields in TCP packet headers. This dimensional expansion allows the system to distinguish between multiple users sharing the same IP address by examining the additional user identity dimension carried in the packet header.
Solution Approach 2:
The patent performs preliminary authentication by requiring users to provide source user information (such as authentication tokens or user identifiers) before data transmission occurs. This preliminary action verifies user identity in advance, allowing the DLP system to make accurate distinctions between legitimate and illegitimate access patterns before data leakage prevention decisions are made.
3Reliability
If network DLP blocks transmissions without source user information, then security is improved, but business operation continuity deteriorates
Solution Approach 1:
The patent implements a feedback mechanism where the DLP system requests source user information from users when it detects sensitive data transmission without proper identification. This feedback loop allows the system to verify user identity and authorization status, enabling security decisions based on authenticated information rather than blocking all transmissions indiscriminately.
Solution Approach 2:
The patent changes the parameter used for identification from IP address alone to IP address combined with source user information fields. This parameter change enables the system to maintain security by verifying user identity while allowing business operations to continue by making more accurate differentiation between legitimate and illegitimate transmissions.
Data Source
AI summary
Systems and methods are directed towards network data leakage prevention (DLP). More specifically, the systems and methods are directed towards using TCP (Transmission Control Protocol) data packets in conjunction with the DLP monitor. The network DLP utilizes TCP data packets to carry source user identity. With the source user identity, the DLP monitor can determine if sensitive data can be transmitted based on the provided user information and corresponding DLP policies for each user. Furthermore, the DLP monitor can determine if sensitive data can also be transmitted for particular users in situations where multiple users share the same IP address.


