Process for searching for sensitive data in at least one data packet, associated device and system
A method for identifying sensitive data in at least one data packet emitted by at least one terminal connected to a network, items of identification information relating to an identity and/or environment of an entity to which the at least one terminal belongs being able to be determined from sensitive data having been inserted into the at least one packet before it reaches a destination equipment item. The method includes steps implemented by a searching device, including: receiving the at least one data packet, searching for sensitive data in the at least one data packet, and, where applicable, providing the entity with items of information about the detected sensitive data.
1 . A method comprising:
searching for sensitive data in at least one data packet emitted by at least one terminal connected to a network, said at least one data packet having as destination a destination equipment item accessible via said network, the sensitive data having been inserted into said at least one packet before the at least one packet reaches the destination equipment item, wherein:
the sensitive data comprises data enabling items of identification information relating to an identity and/or environment of an entity to which said at least one terminal belongs to be determined from the sensitive data,
the searching is implemented by a searching device separate from said destination equipment item and separate from said at least one terminal,
the searching device is located on a route for routing said at least one data packet to said destination equipment item or is connected to said at least one terminal using at least one tunnel, and
the searching comprises:
receiving said at least one data packet;
searching for sensitive data in said at least one data packet; and
in response to sensitive data being detected in said at least one packet, providing said entity with items of information about said detected sensitive data.
2 . The method as claimed in claim 1 , wherein the searching device is located on a route for routing said at least one data packet to said destination equipment item, said method further including a transmitting step implemented by said searching device and comprising, once the search for sensitive data has been carried out, relaying said at least one data packet to the destination equipment item.
3 . The method as claimed in claim 1 , wherein said searching device is connected to the at least one terminal using at least one tunnel, said at least one data packet received by the searching device being a copy of an original data packet transmitted to the destination equipment item, said copy being transmitted via said at least one tunnel and not being relayed by said searching device to the destination equipment item.
4 . The method as claimed in claim 1 , wherein the searching step includes:
comparing data contained in said at least one packet with a filtering list associated with said at least one terminal, and/or
comparing the data contained in said at least one packet with a dictionary associated with said searching device, and/or
executing an automatic learning algorithm to detect recurring data patterns contained in said at least one data packet.
5 . The method as claimed in claim 1 , wherein the providing step includes, in response to an alert criterion being satisfied, emitting an alert message configured to allow access of the entity to said items of information about the detected sensitive data.
6 . The method as claimed in claim 1 , wherein sensitive data are inserted into said at least one packet by at least any one of the components from among:
an operating system equipping said at least one terminal,
a software application installed on said at least one terminal,
an access network to which said at least one terminal is connected, and connected to the network via which said destination equipment item is accessible,
a local network to which said at least one terminal is connected, and connected to said access network.
7 . The method as claimed in claim 1 , wherein the sensitive data comprises a sensitive datum selected from a group consisting of:
a datum of location of said at least one terminal,
an International Mobile Subscriber Identity (IMSI) or a Mobile Station International Subscriber Directory Number (MSISDN) or an International Mobile Equipment Identity (IMEI) number associated with said at least one terminal,
a Subscriber Identity Module (SIM) card number equipping said at least one terminal,
at least one of an identifier of an access network connected to the network via which said destination equipment item is accessible or an identifier of an operator in charge of managing said access network,
at least one of an identifier of said local network to which the at least one terminal is connected or a persistent identifier of a destination equipment item making a connection between the local network and an access network connected to the network via which the destination equipment item is accessible,
an Internet Protocol (IP) address or a hardware address of said at least one terminal,
an IP address or a hardware address of at least one other terminal positioned in a neighborhood of said at least one terminal having emitted said at least one packet, and
a persistent identifier associated with said at least one terminal.
8 . The method as claimed in claim 1 , wherein said entity is any of the items from among:
a user or an administrator of said at least one terminal,
an access network to which said at least one terminal is connected or a local network to which said at least one terminal is connected.
9 . The method as claimed in claim 1 , wherein the searching step is implemented in response to a criterion of authorization to search for sensitive data for said at least one terminal being satisfied.
10 . A searching device comprising:
at least one processor; and
at least one non-transitory computer readable medium comprising instructions stored thereon which when executed by the at least one processor configure the searching device to search for sensitive data in at least one data packet emitted by at least one terminal connected to a network, said at least one data packet having as destination a destination equipment item accessible via said network, the sensitive data having been inserted into said at least one packet before the at least one packet reaches the destination equipment item, wherein:
the sensitive data comprises data enabling items of identification information relating to an identity and/or environment of an entity to which said at least one terminal belongs to be determined from the sensitive data,
the searching device is separate from said destination equipment item and separate from said at least one terminal,
the searching device is configured to be located on a route for routing said at least one data packet to said destination equipment item or connected to said at least one terminal using at least one tunnel, and
the search comprises:
receiving said at least one data packet,
detecting sensitive data inserted into said at least one data packet,
providing said entity, in response to said sensitive data being detected in said at least one packet, with items of information about said detected sensitive data.
11 . The searching device as claimed in claim 10 , said searching device being deployed in:
the network via which said destination equipment item is accessible,
an access network connected to the network via which said destination equipment item is accessible, or
a local network to which said at least one terminal is connected, the local network being connected to an access network, which is connected to the network via which said destination equipment item is accessible.
12 . A sensitive data managing system including:
the searching device as claimed in claim 10 ; and
the at least one terminal, each of the at least one terminal comprising:
at least one processor; and
at least one non-transitory computer readable medium comprising instructions stored thereon which when executed by the at least one processor of the terminal configure the terminal to:
emit the at least one data packet in the network,
access the items of information about sensitive data detected in said at least one data packet.
13 . An aggregating device including:
at least one processor; and
at least one non-transitory computer readable medium comprising instructions stored thereon which when executed by the at least one processor configure the aggregating device to:
receive, coming from a plurality of searching devices, sensitive data detected by said searching devices in at least one data packet emitted by at least one terminal connected to a network, said at least one data packet having as destination a destination equipment item accessible via said network, and the sensitive data having been inserted into said at least one packet before the at least one packet reaches the destination equipment item, wherein:
the sensitive data comprising data enabling items of identification information relating to an identity and/or environment of an entity to which said at least one terminal belongs to be determined from the sensitive,
the plurality of searching devices are separate from said destination equipment item and separate from said at least one terminal, and
the plurality of searching devices are located on a route for routing said at least one data packet to said destination equipment item or connected to said at least one terminal by a tunnel; and
provide said entity with items of information about the sensitive data received from said plurality of searching devices.
14 . A communication terminal including:
at least one processor; and
at least one non-transitory computer readable medium comprising instructions stored thereon which when executed by the at least one processor configure the communication terminal to:
emit at least one data packet in a network, said at least one data packet having as destination a destination equipment item accessible via said network,
duplicate the at least one data packet and transmit said duplicate at least one data packet to at least one searching device, wherein:
said at least one searching device is separate from said destination equipment item and separate from said communication terminal,
said at least one searching device is located on a route for routing said duplicate at least one data packet to said destination equipment item or connected to said communication terminal by a tunnel,
access items of information about sensitive data inserted before the at least one data packet reaches said destination equipment item and detected in said duplicate at least one data packet by the at least one searching device, wherein:
the items of information comprise items of identification information relating to an identity and/or environment of an entity to which said communication terminal belongs, and
the sensitive data comprises data enabling the items of identification information to be determined from the sensitive data.