Automated Version Control Data Leakage Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in identifying and preventing data leakage to version control services, as conventional methods require significant manual investigation and are hindered by encrypted data uploads, making it difficult to detect and address sensitive information leaks.

Innovation Solution

A system that monitors internal network traffic for outgoing data destined for version control systems, associates it with endpoint devices, collects historical information, and identifies user accounts to detect and remediate potential data leaks by searching external servers for sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If manual investigation methods are used to identify data leakage, then detection accuracy may be maintained, but significant manual investigation time and resources are required

Engineering Contradiction:
Improveinvestigation timeVSAvoiddetection efficiency
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The patent introduces an automated detection system that acts as an intermediary between network traffic and security analysts. This system monitors outgoing traffic, identifies patterns indicative of data leakage, and generates alerts, thereby reducing the time and manual effort required for investigation while maintaining detection effectiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical investigation processes with automated computational methods. The system uses automated traffic analysis, pattern recognition, and alert generation mechanisms to substitute human investigators for routine detection tasks, significantly reducing investigation time and improving productivity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If encrypted tunnel connections are used for version control uploads, then data security during transmission is improved, but the ability to inspect and detect sensitive data leakage is prevented

Engineering Contradiction:
Improvedata transmission securityVSAvoiddata leakage detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary actions by establishing baseline profiles of normal encrypted traffic patterns before data leakage occurs. The system learns characteristics of legitimate version control communications and can identify anomalies that deviate from these baselines, enabling detection of sensitive data uploads through encrypted tunnels without compromising transmission security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes detection parameters by moving from content-based inspection (which requires decryption) to metadata-based and behavioral analysis. The system monitors parameters such as traffic volume, timing patterns, destination addresses, and communication frequencies to detect data leakage while preserving the encryption of actual data payloads

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated detection systems are implemented, then detection speed and efficiency are improved, but system complexity increases

Engineering Contradiction:
Improvedetection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the automated detection system into distinct functional modules: traffic capture, pattern recognition, anomaly detection, and alert generation. Each module performs a specific function, making the overall complex system manageable through modular design and enabling independent optimization of each component

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal detection framework that can identify multiple types of data leakage patterns across different version control systems and communication protocols. The system uses generalizable algorithms that adapt to various encrypted tunnel configurations, reducing complexity by avoiding the need for separate specialized detectors for each scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11003790B2Preventing data leakage via version control systems
Publication Date: 2021.05.11 CISCO TECHNOLOGY INC
  • US11003790B2 patent drawing
  • US11003790B2 patent drawing
  • US11003790B2 patent drawing

AI summary

A computer system prevents data leakage via version control systems. Outgoing traffic that is destined for an external server hosting a version control system is identified. The outgoing traffic is associated with an endpoint device corresponding to an individual who is a member of the organization. Historical information is collected about the individual, and a user account of the version control system that is associated with the identified individual is identified. The external server hosting the version control system is searched to determine whether potentially sensitive information has been uploaded. Embodiments may further include a method and program product for preventing data leakage via version control systems in substantially the same manner described above.