IP Library Granted Patent US 12,526,255
Granted Patent B2
US 12,526,255 · App. 17/293,330 · Granted Jan 13, 2026

Method and device for monitoring data output by a server

Inventors: Mirit Kagarlitsky (Ramat Hasharon, IL); Tal Steinherz (Ramat Hasharon, IL)
Assignee: F5, Inc.
H04L63/0245H04L63/0227H04L63/12H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,526,255
App. No.
17/293,330
Granted
Jan 13, 2026
Kind
B2
Abstract

A computer implemented method of monitoring data output by a server over a network is provided, in which the server is arranged to store data. The method includes analysing, by a computing device, outgoing data from the server sent over the network; filtering, by the computing device, a portion of the outgoing data to determine a remaining portion of the outgoing data; analysing, by the computing device, the remaining portion of the outgoing data to determine the amount of information in the remaining portion of the outgoing data; and performing, by the computing device, a predetermined action if the amount of information in the remaining portion of the outgoing data is over a threshold.

Claims (98)

1 . A computer implemented method of monitoring data output by a server over a network, wherein the server is arranged to store data, the method comprising:

analyzing, by a computing device, outgoing data from the server sent over the network;

filtering, by the computing device, a portion of the outgoing data that is safe to output from the server, to obtain a remaining portion of the outgoing data whose safety to output from the server is unknown;

analyzing, by the computing device, the remaining portion of the outgoing data to determine a value indicating information complexity in the remaining portion of the outgoing data by applying an algorithm to the remaining portion of the outgoing data;

determining, by the computing device, when the remaining portion of the outgoing data is unsafe to output from the server based on the value indicating information complexity in the remaining portion of the outgoing data being over a threshold; and

performing, by the computing device, a predetermined action when the determination indicates the remaining portion of the outgoing data is unsafe.

2 . The method of claim 1 , wherein the filtering comprises filtering data of the server that has been sent over the network previously to obtain the remaining portion of the outgoing data,

wherein the filtering data of the server that has been sent over the network previously comprises at least one of: filtering data that has been sent before by the server to any recipient, filtering data that has been sent before by the server to an intended recipient of the outgoing data, and considering data that has been sent by the server in a predetermined time period.

3 . The method of claim 1 , further comprising:

analyzing, by the computing device, the server to categorize the data stored in the server into a plurality of data blocks;

storing, by the computing device, record data indicating which data blocks of the plurality of data blocks stored in the server are data blocks that have been sent over the network previously; and

wherein the filtering comprises filtering the data blocks that have been sent over the network previously to obtain the remaining portion of the outgoing data.

4 . The method of claim 1 , further comprising:

analyzing, by the computing device, the outgoing data to determine a data format of a portion of the outgoing data; and

changing, by the computing device, the data format of the portion of the outgoing data,

wherein the filtering comprises filtering the portion of the outgoing data with a changed data format to obtain the remaining portion of the outgoing data,

wherein the analyzing the outgoing data to determine the data format of the portion of the outgoing data comprises checking header information of the outgoing data, and

wherein the changing the data format of the portion of the outgoing data comprises altering at least part of the portion of the outgoing data.

5 . The method of claim 1 , further comprising:

analyzing, by the computing device, the outgoing data to determine a portion of the outgoing data that comprises protocol header values,

wherein the filtering comprises filtering the portion of the outgoing data that comprises protocol header values to obtain the remaining portion of the outgoing data.

6 . The method of claim 1 , further comprising:

analyzing, by the computing device, the outgoing data to determine a portion of the outgoing data that is safe to output from the server by using an external trusted model, wherein the portion of the outgoing data that is safe to output from the server is associated with a genuine response to a verified user request for data.

7 . The method of claim 1 , wherein the analyzing the remaining portion of the outgoing data to determine the value indicating information complexity in the remaining portion of the outgoing data comprises:

applying, by the computing device, a compression algorithm to the remaining portion of the outgoing data to obtain a compressed remaining portion of the outgoing data;

comparing, by the computing device, the compressed remaining portion of the outgoing data to a predetermined threshold; and

performing, by the computing device, the predetermined action if a size of the compressed remaining portion of the outgoing data is over the predetermined threshold,

wherein the value indicating information complexity in the remaining portion of the outgoing data is determined based on the size of the compressed remaining portion of the outgoing data,

wherein the predetermined threshold comprises an absolute number determined based on a threshold related to an amount of human digestible information, and

wherein the predetermined threshold is determined based on a ratio of the size of the compressed remaining portion of the outgoing data and a total size of the data stored in the server, or a ratio of the size of the compressed remaining portion of the outgoing data and a compressed size of the data stored in the server.

8 . The method of claim 1 , wherein the predetermined action comprises:

providing, by the computing device, an alert that there is a potential data breach,

wherein the providing the alert comprises:

sending, by the computing device, information indicating the alert to an external device and/or displaying, on a display of a computing device, information indicating the alert.

9 . The method of claim 1 , wherein the computing device is arranged to be installed between the server and the network, the method further comprising:

receiving, by the computing device, outgoing data from the server that is intended to be sent over the network; and

sending, by the computing device, the outgoing data to the network if the predetermined action is not performed,

wherein the predetermined action comprises not sending the outgoing data to the network.

10 . A non-transitory computer-readable medium having computer-executable instructions to cause one or more processors of a computing device to:

analyze outgoing data from a server sent over a network;

filter a portion of the outgoing data that is safe to output from the server, to obtain a remaining portion of the outgoing data whose safety to output from the server is unknown;

analyze the remaining portion of the outgoing data to determine a value indicating information complexity in the remaining portion of the outgoing data by applying an algorithm to the remaining portion of the outgoing data;

determine when the remaining portion of the outgoing data is unsafe to output from the server based on the value indicating information complexity in the remaining portion of the outgoing data being over a threshold; and

perform a predetermined action when the determination indicates the remaining portion of the outgoing data is unsafe.

11 . The non-transitory computer-readable medium of claim 10 , wherein the computer-executable instructions further comprise instructions to cause the one or more processors to:

filter data of the server that has been sent over the network previously to obtain the remaining portion of the outgoing data, wherein the filtering the data of the server that has been sent over the network previously comprises at least one of:

filtering data that has been sent before by the server to any recipient,

filtering data that has been sent before by the server to an intended recipient of the outgoing data, and

considering data that has been sent by the server in a predetermined time period.

12 . The non-transitory computer-readable medium of claim 10 , wherein the computer-executable instructions further comprise instructions to cause the one or more processors to:

analyze the outgoing data to determine a portion of the outgoing data that is safe to output from the server by using an external trusted model, wherein the portion of the outgoing data that is safe to output from the server is associated with a genuine response to a verified user request for data.

13 . The non-transitory computer-readable medium of claim 10 , wherein the computer-executable instructions further comprise instructions to cause the one or more processors to:

apply a compression algorithm to the remaining portion of the outgoing data to obtain a compressed remaining portion of the outgoing data;

compare the compressed remaining portion of the outgoing data to a predetermined threshold and

perform the predetermined action if a size of the compressed remaining portion of the outgoing data is over the predetermined threshold,

wherein the value indicating information complexity in the remaining portion of the outgoing data is determined based on the size of the compressed remaining portion of the outgoing data,

wherein the predetermined threshold comprises an absolute number determined based on a threshold related to an amount of human digestible information, and

wherein the predetermined threshold is determined based on a ratio of the size of the compressed remaining portion of the outgoing data and a total size of the data stored in the server, or a ratio of the size of the compressed remaining portion of the outgoing data and a compressed size of the data stored in the server.

14 . A computing device comprising:

one or more processors; and

a memory operable to store data output by a server over a network, the memory being further operable to store operating instructions to control the one or more processors to:

analyze outgoing data from the server sent over the network;

filter a portion of the outgoing data that is safe to output from the server, to obtain a remaining portion of the outgoing data whose safety to output from the server is unknown;

analyze the remaining portion of the outgoing data to determine a value indicating information complexity in the remaining portion of the outgoing data by applying an algorithm to the remaining portion of the outgoing data;

determine when the remaining portion of the outgoing data is unsafe to output from the server based on the value indicating information complexity in the remaining portion of the outgoing data being over a threshold; and

perform a predetermined action when the determination indicates the remaining portion of the outgoing data is unsafe.

15 . The computing device of claim 14 , wherein the operating instructions further control the one or more processors to:

filter data of the server that has been sent over the network previously to obtain the remaining portion of the outgoing data, wherein the filtering the data of the server that has been sent over the network previously comprises at least one of:

filtering data that has been sent before by the server to any recipient,

filtering data that has been sent before by the server to an intended recipient of the outgoing data, and

considering data that has been sent by the server in a predetermined time period.

16 . The computing device of claim 14 , wherein the operating instructions further control the one or more processors to:

analyze the outgoing data to determine a portion of the outgoing data that is safe to output from the server by using an external trusted model, wherein the portion of the outgoing data that is safe to output from the server is associated with a genuine response to a verified user request for data.

17 . The computing device of claim 14 , wherein the operating instructions further control the one or more processors to:

apply a compression algorithm to the remaining portion of the outgoing data to obtain a compressed remaining portion of the outgoing data;

compare the compressed remaining portion of the outgoing data to a predetermined threshold; and

perform the predetermined action if a size of the compressed remaining portion of the outgoing data is over the predetermined threshold,

wherein the value indicating information complexity in the remaining portion of the outgoing data is determined based on the size of the compressed remaining portion of the outgoing data,

wherein the predetermined threshold comprises an absolute number determined based on a threshold related to an amount of human digestible information, and

wherein the predetermined threshold is determined based on a ratio of the size of the compressed remaining portion of the outgoing data and a total size of the data stored in the server, or a ratio of the size of the compressed remaining portion of the outgoing data and a compressed size of the data stored in the server.

18 . A system of monitoring data output by a server over a network, the system comprising memory comprising programmed instructions stored thereon and a processor configured to be capable of executing the stored programmed instructions to:

analyze outgoing data from the server sent over the network;

filter a portion of the outgoing data that is safe to output from the server, to obtain a remaining portion of the outgoing data whose safety to output from the server is unknown;

analyze the remaining portion of the outgoing data to determine a value indicating information complexity in the remaining portion of the outgoing data by applying an algorithm to the remaining portion of the outgoing data;

determine when the remaining portion of the outgoing data is unsafe to output from the server based on the value indicating information complexity in the remaining portion of the outgoing data being over a threshold; and

perform a predetermined action when the determination indicates the remaining portion of the outgoing data is unsafe.

19 . The system of claim 18 , wherein the processor is further configured to be capable of executing the stored programmed instructions to:

filter data of the server that has been sent over the network previously to obtain the remaining portion of the outgoing data, wherein the filtering the data of the server that has been sent over the network previously comprises at least one of:

filtering data that has been sent before by the server to any recipient,

filtering data that has been sent before by the server to an intended recipient of the outgoing data, and

considering data that has been sent by the server in a predetermined time period.

20 . The system of claim 18 , wherein the processor is further configured to be capable of executing the stored programmed instructions to:

apply a compression algorithm to the remaining portion of the outgoing data to obtain a compressed remaining portion of the outgoing data;

compare the compressed remaining portion of the outgoing data to a predetermined threshold; and

perform the predetermined action if a size of the compressed remaining portion of the outgoing data is over the predetermined threshold,

wherein the value indicating information complexity in the remaining portion of the outgoing data is determined based on the size of the compressed remaining portion of the outgoing data,

wherein the predetermined threshold comprises an absolute number determined based on a threshold related to an amount of human digestible information, and

wherein the predetermined threshold is determined based on a ratio of the size of the compressed remaining portion of the outgoing data and a total size of the data stored in the server, or a ratio of the size of the compressed remaining portion of the outgoing data and a compressed size of the data stored in the server.

Assignments (3)
CHANGE OF NAME Recorded Apr 9, 2025
From: WENSPIRE LTD.
To: WIB SECURITY LTD.
Reel/Frame 070793/0006 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: KAGARLITSKY, MIRIT; STEINHERZ, TAL
To: WENSPIRE
Reel/Frame 070270/0798 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2025
From: WIB SECURITY LTD.
To: F5, INC.
Reel/Frame 070098/0787 →
Continuity (2)
Provisional Application 62760294 · Nov 13, 2018
Related Publication 20220014501A1 · Jan 13, 2022
References Cited (28)
US 8219766B1 · Orcutt · 2012 [cited by examiner]
US 8776206B1 · Goldstein · 2014 [cited by examiner]
US 9565202B1 · Kindlund · 2017 [cited by examiner]
US 10079835B1 · Dodke · 2018 [cited by examiner]
US 10268836B2 · Ukil · 2019 [cited by examiner]
US 20050271207A1 · Frey · 2005 [cited by examiner]
US 20070041608A1 · Maeno · 2007 [cited by examiner]
US 20080307524A1 · Singh · 2008 [cited by examiner]
US 20090232000A1 · Watanabe · 2009 [cited by examiner]
US 20090300759A1 · Wang · 2009 [cited by examiner]
US 20130004090A1 · Kundu · 2013 [cited by examiner]
US 20150269386A1 · Khetawat · 2015 [cited by examiner]
US 20160149862A1 · Kilgallon · 2016 [cited by examiner]
US 20180123955A1 · Moore · 2018 [cited by examiner]
US 20180324146A1 · Meriac · 2018 [cited by examiner]
US 20190012476A1 · Dorogoy · 2019 [cited by examiner]
US 20230376581A1 · Shear · 2023 [cited by examiner]
US 20240223578A1 · McNelly · 2024 [cited by examiner]
US 20240378309A1 · Bhattacharya · 2024 [cited by examiner]
US 20240406210A1 · Sellars · 2024 [cited by examiner]
CN 106446707A · 2017 [cited by applicant]
Sankalpa et al., On Implementing a Client-Server setting to prevent the Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext (BREACH) Attacks, 2016, IEEE. [cited by examiner]
Allawi et al., MLDED: Multi-Layer Data Exfiltration Detection System, 2015, IEEE. [cited by examiner]
International Search Report, Application No. PCT/IB2019/059750, Mailed Dec. 24, 2019, 2 pages. [cited by applicant]
Durkota et al., “Optimal Strategies for Detecting Data Exfiltration by Internal and External Attackers” Oct. 4, 2017, Advances in Biometrics: International Conference, ICB 2007, Seoul, Korea, Aug. 27-29, 2007; XP0474505… [cited by applicant]
European Patent Office, Extended European Search Report, Application No. 19884623.0, mailed Sep. 19, 2022, 11 pages. [cited by applicant]
Sultan et al., “Detecting data semantic: A data leakage prevention approach” 2015 IEEE Trustcom/BigDataSE/ISPA, vol. 1, Aug. 20, 2015, XP032819745, DOI: 10.1109/TRUSTCOM.2015.464, 8 pages. [cited by applicant]
Yoshihama et al., “Web-based Data Leakage Prevention” Sep. 15, 2011, XP055234468, Retrieved from URL: http://citeseerx.ist.psu.edu/viewdoc/download;jsessionid=5A050A63CB61A931349DB6FACEE97D9E?doi=10.1.1.207..5902&rep=re… [cited by applicant]