High-performance network content analysis platform
First Claim
Patent Images
1. A method comprising:
- receiving network data;
processing the network data at one or more decoders to create input data for applying at least multi-dimensional content profiling;
preventing, by a processor, through the network data, leaks of information by at least applying the multi-dimensional content profiling; and
wherein the multi-dimensional content profiling comprises;
loading one or more profiles, wherein the one or more profiles each comprise an expected set of statistical characteristics of data;
continuously receiving the input data from the one or more decoders;
determining a probabilistic measure of membership of the input data relative to the one or more profiles;
comparing the probabilistic measure with a threshold requirement for each of the one or more profiles; and
preventing leaks of the information if the probabilistic measure meets the threshold requirement.
11 Assignments
0 Petitions
Accused Products
Abstract
One implementation of a method reassembles complete client-server conversation streams, applies decoders and/or decompressors, and analyzes the resulting data stream using multi-dimensional content profiling and/or weighted keyword-in-context. The method may detect the extrusion of the data, for example, even if the data has been modified from its original form and/or document type. The decoders may also uncover hidden transport mechanisms such as, for example, e-mail attachments. The method may further detect unauthorized (e.g., rogue) encrypted sessions and stop data transfers deemed malicious. The method allows, for example, for building 2 Gbps (Full-Duplex)-capable extrusion prevention machines.
234 Citations
18 Claims
-
1. A method comprising:
-
receiving network data; processing the network data at one or more decoders to create input data for applying at least multi-dimensional content profiling; preventing, by a processor, through the network data, leaks of information by at least applying the multi-dimensional content profiling; and wherein the multi-dimensional content profiling comprises; loading one or more profiles, wherein the one or more profiles each comprise an expected set of statistical characteristics of data; continuously receiving the input data from the one or more decoders; determining a probabilistic measure of membership of the input data relative to the one or more profiles; comparing the probabilistic measure with a threshold requirement for each of the one or more profiles; and preventing leaks of the information if the probabilistic measure meets the threshold requirement. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A machine-readable storage medium having encoded information, which when read and executed by a machine causes a method comprising:
-
receiving network data; processing the network data at one or more decoders to create input data for applying at least multi-dimensional content profiling; preventing, through the network data, leaks of information by at least applying multi-dimensional content profiling; and wherein the multi-dimensional content profiling comprises; loading one or more profiles, wherein the one or more profiles each comprise an expected set of statistical characteristics of data; continuously receiving the input data from the one or more decoders; determining a probabilistic measure of membership of the input data relative to the one or more profiles; comparing the probabilistic measure with a threshold requirement for each of the one or more profiles; and preventing leaks of the information if the probabilistic measure meets the threshold requirement. - View Dependent Claims (12, 13, 14, 15, 16)
-
-
17. An apparatus comprising:
-
a receiver to receive network data; a processor, coupled to the receiver, to prevent, through the network data, leaks of information by at least applying multi-dimensional content profiling, wherein the processor processes the network data at one or more decoders to create input data for applying at least the multi-dimensional content profiling; the multi-dimensional content profiling comprising; loading one or more profiles, wherein the one or more profiles each comprise an expected set of statistical characteristics of data; continuously receiving the input data from the one or more decoders; determining a probabilistic measure of membership of the input data relative to the one or more profiles; comparing the probabilistic measure with a threshold requirement for each of the one or more profiles; and preventing leaks of the information if the probabilistic measure meets the threshold requirement. - View Dependent Claims (18)
-
Specification