Data leak protection

US9319417B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9319417-B2
Application numberUS-201213536062-A
CountryUS
Kind codeB2
Filing dateJun 28, 2012
Priority dateJun 28, 2012
Publication dateApr 19, 2016
Grant dateApr 19, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for Data Leak Prevention (DLP) in an enterprise network are provided. According to one embodiment a data leak protection method is provided. A network device receives information regarding a watermark filtering rule, including a sensitivity level and an action to be applied to files observed by the network device matching the watermark filtering rule. The network device scans a file attempted to be passed through the network device by locating a watermark embedded within the file and comparing a sensitivity level associated with the watermark to the sensitivity level of the watermark filtering rule. If the sensitivity levels match, then the network device performs the action specified by the watermark filtering rule.

First claim

Opening claim text (preview).

What is claimed is: 1. A data leak protection method comprising: receiving, by a network filtering device, via a graphical user interface (GUI) of the network filtering device information regarding a watermark filtering rule, including a plurality of filtering parameters, including a file size threshold, an indication regarding one or more file types and a sensitivity level, and an action to be taken by the network filtering device when files observed by the network device satisfy the plurality of filtering parameters of the watermark filtering rule; scanning, by the network filtering device, a file attempted to be passed through the network filtering device, by locating a watermark embedded within the file and identifying a file type and a size of the file; comparing (i) a sensitivity level associated with the watermark to the sensitivity level of the watermark filtering rule; (ii) the identified file size to the file size threshold of the watermark filtering rule; and (iii) the identified file type to the indication regarding one or more file types of the watermark filtering rule, wherein the sensitivity level is selected from a group comprising critical sensitivity, high sensitivity, medium sensitivity and low sensitivity; and if the comparing results in a determination that all of the plurality of filtering parameters are satisfied by the file and the watermark embedded therein, then performing, by the network filtering device, the action specified by the watermark filtering rule. 2. The method of claim 1 , wherein the information regarding the watermark filtering rule includes a company identifier. 3. The method of claim 1 , further comprising, prior to said scanning, a separate client program, embedding the watermark into the file responsive to the file being identified as a file to be protected. 4. The method of claim 3 , further comprising receiving, by the separate client program, watermark content, including information regarding a sensitivity level of the file and a company identifier. 5. The method of claim 4 , further comprising: identifying, by the separate client program, a file type of the file; and wherein said embedding the watermark into the file is based upon the file type. 6. The method of claim 4 , further comprising generating, by the separate client program, the watermark based on the watermark content. 7. The method of claim 6 , wherein the watermark comprises a hash value or a message digest of the watermark content. 8. The method of claim 6 , wherein the watermark comprises a plain text representation of the watermark content. 9. The method of claim 1 , wherein the network filtering device comprises a gateway. 10. The method of claim 5 , wherein the file type is one of a text document, a Portable Document Format (PDF) document, a Microsoft Windows Office document, an open office document, and a Macintosh OS document. 11. The method of claim 1 , wherein the action specified by the watermark filtering rule comprises blocking the file at the network filtering device. 12. The method of claim 1 , wherein the action specified by the watermark filtering rule comprises passing the file through the network filtering device. 13. The method of claim 1 , wherein the file is attached to an electronic mail (email) message or is being transferred via a file transfer protocol from a source device to a destination device. 14. The method of claim 13 , wherein the action specified by the watermark filtering rule comprises logging information regarding one or more of a user associated with the source device, an Internet Protocol (IP) address associated with the source device, a time, a date and an interface of the network filtering device on which the file was received. 15. A non-transitory program storage device readable by a network filtering device, tangibly embodying a program of instructions executable by one or more computer processors of the network filtering device to perform a method of data leak protection, the method comprising: receiving, via a graphical user interface (GUI) of the network filtering device, information regarding a watermark filtering rule, including a plurality of filtering parameters, including a file size threshold, an indication regarding one or more file types and a sensitivity level, and an action to be taken by the network filtering device when files observed by the network device satisfy the plurality of filtering parameters of the watermark filtering rule; scanning a file attempted to be passed through the network filtering device, by locating a watermark embedded within the file and identifying a file type and a size of the file; comparing (i) a sensitivity level associated with the watermark to the sensitivity level of the watermark filtering rule; (ii) the identified file size to the file size threshold of the watermark filtering rule; and (iii) the identified file type to the indication regarding one or more file types of the watermark filtering rule, wherein the sensitivity level is selected from a group comprising critical sensitivity, high sensitivity, medium sensitivity and low sensitivity; and if the comparing results in a determination that all of the plurality of filtering parameters are satisfied by the file and the watermark embedded therein, then performing, by the network filtering device, the action specified by the watermark filtering rule. 16. The program storage device of claim 15 , wherein the information regarding the watermark filtering rule includes a company identifier. 17. The program storage device of claim 15 , wherein prior to said scanning, a separate client program, embeds the watermark into the file responsive to the file being identified as a file to be protected. 18. The program storage device of claim 17 , wherein the separate client program, receives watermark content, including information regarding a sensitivity level of the file and a company identifier. 19. The program storage device of claim 18 , wherein the separate client program: identifies a file type of the file; and embeds the watermark into the file is based upon the file type. 20. The program storage device of claim 19 , wherein the separate client program generates the watermark based on the watermark content. 21. The program storage device of claim 20 , wherein the watermark comprises a hash value or a message digest of the watermark content. 22. The program storage device of claim 20 , wherein the watermark comprises a plain text representation of the watermark content. 23. The program storage device of claim 15 , wherein the network filtering device comprises a gateway. 24. The program storage device of claim 19 , wherein the file type is one of a text document, a Portable Document Format (PDF) document, a Microsoft Windows Office document, an open office document, and a Macintosh OS document. 25. The program storage device of claim 15 , wherein the action specified by the watermark filtering rule comprises blocking the file at the network filtering device. 26. The program storage device of claim 15 , wherein the action specified by the watermark filtering rule comprises passing the file through the network filtering device. 27. The program storage device of claim 15 , wherein the file is attached to an electronic mail (email) message or is being transferred via a file transfer protocol from a source device to a destination devi

Assignees

Inventors

Classifications

  • Program or content traceability, e.g. by watermarking · CPC title

  • H04L63/12Primary

    Applying verification of the received information (cryptographic mechanisms or cryptographic arrangements for data integrity or data verification H04L9/32) · CPC title

  • Filtering by information in the payload · CPC title

  • Multiple levels of security · CPC title

  • Watermarking · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9319417B2 cover?
Methods and systems for Data Leak Prevention (DLP) in an enterprise network are provided. According to one embodiment a data leak protection method is provided. A network device receives information regarding a watermark filtering rule, including a sensitivity level and an action to be applied to files observed by the network device matching the watermark filtering rule. The network device scan…
Who is the assignee on this patent?
Nelson Michael D, Xie Michael, Fortinet Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/12. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 19 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).