Protection Mechanism Against Internal Data Leakage Based on Scitags

Che-Yu Huang, Ting‐Yu Lin, Hsiang-Ming Hung, Meng‐Hsun Tsai, Chia-Heng Tu · 2025

Privacy and security in data transmission have become essential concerns for modern research institutions. Prior studies have rarely focused on using the data packet itself, specifically those that contain confidential information, as the basis for detection and filtering. When a connection shares the same 5 -tuple, traditional firewalls are incapable of determining whether the packets contain confidential content, which may lead to unintentional data leakage from within the organization. This study proposes a solution based on the Scitags packet marking mechanism. By tagging IPv6 packets that carry internal institutional data with Scitags and parsing packet headers in programmable switches, the system can filter out packets marked with specific Scitags to prevent them from being forwarded externally. Even when the packet’s 5 -tuple remains identical, the mechanism enables Layer 2 switches to identify and block packets carrying confidential data. Experimental results demonstrate that the switch can successfully block packets marked with specific Scitags from reaching external networks. Additionally, real-time network flow can be visualized through dashboards, offering effective monitoring of packet transmissions.

Read the paper · More papers on PaperTik