发明名称 UNIFIED SOURCE USER CHECKING OF TCP DATA PACKETS FOR NETWORK DATA LEAKAGE PREVENTION
摘要 Systems and methods are directed towards network data leakage prevention (DLP). More specifically, the systems and methods are directed towards using TCP (Transmission Control Protocol) data packets in conjunction with the DLP monitor. The network DLP utilizes TCP data packets to carry source user identity. With the source user identity, the DLP monitor can determine if sensitive data can be transmitted based on the provided user information and corresponding DLP policies for each user. Furthermore, the DLP monitor can determine if sensitive data can also be transmitted for particular users in situations where multiple users share the same IP address.
申请公布号 US2017041297(A1) 申请公布日期 2017.02.09
申请号 US201514819104 申请日期 2015.08.05
申请人 Dell Software Inc. 发明人 Ling Hui;Chen Zhong;Yu Cuiping;Cheng Zun Ping
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method for data leakage prevention (DLP) by checking TCP data packets, the method comprising: establishing user information for a user with a network, the user information including secret keys for authenticating source user identity for TCP data packets being sent by the user; intercepting, via a processor, a transmitted TCP data packet from the user containing sensitive information, wherein the transmitted TCP data packet is being transmitted out of the network; determining, via the processor, that the transmitted TCP data packet from the user does not contain source user-based information; requesting, via the processor, source user-based information from the user; receiving, via the processor, a retransmitted TCP data packet from the user containing source user-based information, wherein the source user-based information includes information used to authenticate source user identity; evaluating, via the processor, that the source user-based information included in the retransmitted TCP data packet matches the user information established with the network thereby authenticating the identity of the user; evaluating, via the processor, corresponding policies associated with the authenticated user; and processing, via the processor, the transmitted TCP data packet containing sensitive information based on the evaluated policies for the authenticated user.
地址 Round Rock TX US