IP Library Granted Patent US 8,453,243
Granted Patent B2
US 8,453,243 · App. 11/319,678 · Granted May 28, 2013

Real time lockdown

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,453,243
App. No.
11/319,678
Granted
May 28, 2013
Kind
B2
Abstract

A system and method that trusts software executables existent on a machine prior to activation for different types of accesses e.g. execution, network, and registry. The system detects new executables added to the machine as well as previously existent executables that have been modified, moved, renamed or deleted. In certain embodiments, the system will tag the file with a flag as modified or newly added. Once tagged, the system intercepts particular types of file accesses for execution, network or registry. The system determines if the file performing the access is flagged and may apply one or more policies based on the requested access. In certain embodiments, the system intercepts I/O operations by file systems or file system volumes and flags metadata associated with the file. For example, the NT File System and its extended attributes and alternate streams may be utilized to implement the system.

Claims (44)

1. A method of protecting a computer workstation from a virus threat, the method comprising:

detecting a modification to an executable program file, the file comprising file data and file meta data;

creating a hash from the file meta data;

adding a flag to the file meta data in response to the modification;

storing the hash and the flag in a memory;

identifying a virus threat;

initiating a lock down mode in response to the identified virus threat, wherein policies are applied to files created or modified after the lock down mode is initiated;

identifying the executable program file as being associated with an operation performed after the lock down mode is initiated and

applying at least one of a policy for restricted files and a policy for unrestricted files based on at least the file meta data flag associated with the executable program file, the policy applied after detecting the modification to the executable program file.

2. The method of claim 1 , further comprising determining if the modified executable program file is a trusted file based on a digital signature of the modified executable program file.

3. The method of claim 1 , wherein the meta data comprises extended attributes and alternate streams.

4. The method of claim 1 , wherein the file meta data comprises permissions.

5. The method of claim 1 , further comprising updating a virus protection program to include information relating to the virus threat. program to include information relating to the software virus.

6. The method of claim 1 , further comprising:

creating a new file on the workstation;

identifying the new file with a flag, wherein the flag is a code added to the file meta data associated with the new file;

creating a hash for the new file, wherein the hash is created at least in part on the file meta data associated with the new file; and

storing the hash and the flag in a memory.

7. The method of claim 6 , wherein identifying the new file comprises inserting one or more bits of data into the file meta data, the bits identifying the file data as being new.

8. The method of claim 1 , wherein identifying a modified executable program file comprises receiving notifications regarding monitoring input and output operations from a file system.

9. The method of claim 1 , wherein creating a hash from the file meta data is performed before the lock down mode is initiated.

10. The method of claim 1 wherein, the file meta data comprises one or more of a filename, publisher, suite, hash, file size, and version.

11. The method of claim 5 , further comprising ending the lock down mode on the workstation after updating the virus protection program.

12. A non-transitory, computer-readable medium storing instructions that when executed by a computer perform the method of:

detecting a modification to an executable program file, the file comprising file data and file meta data;

creating a hash from the file meta data;

adding a flag to the file meta data in response to the file modification;

storing the hash and the flag in a memory;

identifying a virus threat;

initiating a lock down mode in response to the identified virus threat, wherein policies are applied to files created or modified after the lock down mode is initiated;

identifying the executable program file as being associated with an operation performed after the lock down mode is initiated;

retrieving the hash and the flag from the memory; and

applying at least one of a policy for restricted files and a policy for unrestricted files based on at least the file meta data flag associated with the executable program file, the policy applied after detecting the modification to the executable program file.

13. The non-transitory, computer-readable medium of claim 12 , wherein the file meta data comprises one or more of a filename, publisher, suite, hash, file size, and version.

14. The non-transitory, computer-readable medium of claim 12 , wherein adding a flag to the meta data comprises inserting one or more bits of data into the meta data, the bits identifying the file data as being modified.

15. The non-transitory, computer-readable medium of claim 12 , further comprising updating a virus protection program to include information relating to the virus threat.

16. The non-transitory, computer-readable medium of claim 12 , wherein applying the policy is performed at least in part by a kernel.

17. The non-transitory, computer-readable medium of claim 12 , further comprising:

creating a new file on a workstation, wherein the flag is a code added to the meta data associated with the new file;

creating a hash for the new file, wherein the hash is created at least in part on the file meta data associated with the new file; and

storing the hash and the flag in a memory.

18. The non-transitory, computer-readable medium of claim 17 , wherein identifying the new file comprises inserting one or more bits of data into the file meta data, the bits identifying the file data as being new.

19. The non-transitory, computer-readable medium of claim 12 , wherein the policies determine whether to execute the executable program file, deny execution of the executable program file, alert the user that the request to run the executable program file will be logged, and allowing the user a specific amount of time in which to run the executable program file.

20. The non-transitory, computer-readable medium of claim 15 , further comprising ending the lock down mode on the workstation after updating the virus protection program.

Assignments (23)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: WEBSENSE, INC.
Reel/Frame 030693/0424 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 16, 2010
From: WEBSENSE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 025503/0895 →
TERMINATION OF SECURITY INTEREST IN PATENTS Recorded Nov 19, 2010
From: BANK OF AMERICA, N.A., AS SENIOR COLLATERAL AGENT
To: PORTAUTHORITY TECHNOLOGIES, INC.; WEBSENSE, INC.
Reel/Frame 025408/0520 →
ASSIGNMENT OF SECURITY INTEREST Recorded Jul 3, 2008
From: MORGAN STANLEY & CO. INCORPORATED, IN ITS CAPACITY AS RESIGNING SENIOR COLLATERAL AGENT
To: BANK OF AMERICA, N.A., IN ITS CAPACITY AS SUCCESSOR SENIOR COLLATERAL AGENT
Reel/Frame 021185/0802 →
SENIOR PATENT SECURITY AGREEMENT Recorded Oct 19, 2007
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. INCORPORATED, AS SENIOR COLLATERAL AGENT
Reel/Frame 019984/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2005
From: SHARMA, RAJESH KUMAR; LO, WINPING; PAPA, JOSEPH
To: WEBSENSE, INC.
Reel/Frame 017424/0367 →