IP Library Granted Patent US 8,463,892
Granted Patent B2
US 8,463,892 · App. 11/485,537 · Granted Jun 11, 2013

Method and system for information leak prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,463,892
App. No.
11/485,537
Granted
Jun 11, 2013
Kind
B2
Abstract

A method for mitigating false positive type errors while applying an information leak prevention policy, the method comprising the computer implemented steps of: defining at least one positive criterion for a positive set, wherein the positive criterion comprises at least one indicator of a possible breach of the information leak prevention policy; defining at least one negative criterion for a negative set, wherein the negative criterion comprises at least one indicator of benign traffic; establishing an ambiguity set in association with an intersection between the positive set and the negative set, such that information items in the intersection enter the ambiguity set; defining at least one ambiguity resolution criterion for resolving the ambiguity; monitoring and analyzing electronic traffic, where each information item in the traffic is searched for matches with the positive set; checking for membership of each item in the positive set in the ambiguity set; resolving ambiguities using one of the ambiguity resolution criterion for each member of the ambiguity set and removing items from the positive set accordingly, and applying information leak prevention policy for all items remaining in the positive set following the removal of items using ones of the ambiguity resolution criteria.

Claims (34)

1. A method for mitigating false positive type errors while applying an information leak prevention policy to identify important information that it is desired to protect and to prevent said important information from leaking outwardly of an organization, the method comprising the computer implemented steps of:

defining at least one positive criterion for a positive set, wherein said positive criterion comprises at least one indicator that a corresponding item contains information the distribution of which may be a possible breach of said information leak prevention policy;

defining at least one negative criterion for a negative set, wherein said negative criterion comprises at least one indicator of benign traffic;

establishing an ambiguity set defined by an intersection between said positive set and said negative set, said intersection containing items showing indications for both said positive set and said negative set, such that information items in said intersection, being all of the information items that belong simultaneously to said positive set and to said negative set, enter said ambiguity set;

defining at least one ambiguity resolution criterion for resolving ambiguity of all members of said ambiguity set, thereby to positively place in or to remove said member from said positive set accordingly;

monitoring and analyzing electronic traffic, where each information item in said traffic is searched for matches with said positive set;

checking each item in said positive set for membership in said ambiguity set;

resolving ambiguities of items in said ambiguity set using one of said ambiguity resolution criterion for each member of the ambiguity set and removing items from the positive set accordingly, said resolving being carried out on the items in all said items in said ambiguity set, being said items which are simultaneously members of said positive set and said negative set; and

applying information leak prevention policy for all items remaining in said positive set following said removal of items using ones of said ambiguity resolution criteria, thereby identifying important information that it is desired to protect and to prevent said important information from leaking outwardly of said organization;

the method further comprising entering into said positive set social security numbers and entering into said negative set CUISP identifiers that are numbers valid for the set of social security numbers.

2. A method according to claim 1 wherein said criterion for said positive set is provided by checking for a membership in a pre-defined list.

3. A method according to claim 1 wherein said criterion for said positive set is provided from matching with a regular expression.

4. A method according to claim 1 wherein said criterion for said positive set is provided by measuring a similarity to at least one document.

5. A method according to claim 1 , wherein said resolving said ambiguity comprises finding searched for terms predetermined to relate to the positive set, said ambiguity being resolved as positive when the predetermined terms are in proximity to said matches to said positive set, and said ambiguity being resolved as negative otherwise, said proximity being defined by a predetermined threshold.

6. A method according to claim 1 , wherein said resolving said ambiguity comprises finding searched for terms predetermined to relate to the negative set, said ambiguity being determined as negative when the predetermined terms are in proximity to said matches to said positive set, said proximity being defined by a predetermined threshold.

7. A method according to claim 1 , wherein said resolving said ambiguity comprises applying an additional validation criterion.

8. A method according to claim 1 , wherein said information leak prevention policy comprises applying at least one of the following actions:

block the message;

quarantine the message;

encrypt the message;

archive the message;

notify an authorized person about the message, and

log the message.

9. A method according to claim 1 wherein where each item is validated using a validation filter, said validation filter being configured to assert with a predetermined level of certainty that a non-validated finding belongs to a negative set, said validation filter utilizing a condition for validation requiring a match with a regular expression.

10. A method according to claim 1 , further comprising

assessing the potential severity of a given possible breach of said information leak prevention policy, to identify certain threats as potentially severe;

for threats identified as potentially severe:

assigning a default positive label, and

performing at least one test to validate said potential high severity cases as negative.

11. Apparatus for mitigating false positive type errors while applying an information leak prevention policy to identify important information that it is desired to protect and to prevent said important information from leaking outwardly of an organization, the apparatus comprising:

a criterion definer for defining at least one positive criterion for a positive set of items, wherein said positive criterion comprises at least one indicator of said important information and a possible breach of said information leak prevention policy, and further for defining at least one negative criterion for a negative set, wherein said negative criterion comprises at least one indicator of benign traffic;

said criterion definer configured to enter into said said positive set social security numbers and to enter into said negative set CUISP identifiers that are numbers valid for the set of social security numbers;

a disambiguator unit for establishing an ambiguity set in association with an intersection between said positive set and said negative set, such that all of said information items containing indicators for both said positive set and said negative set lie in said intersection and enter said ambiguity set, and for defining at least one ambiguity resolution criterion for resolving said ambiguity;

said apparatus being configured to monitor and analyzing electronic traffic, where each information item in said traffic is searched for matches with said positive set; to check each item in said positive set for membership in said ambiguity set; and to resolve ambiguities using one of said ambiguity resolution criterion for each member of the ambiguity set, said ambiguity resolving thus being carried out on all items which are simultaneously in said positive set and said negative set, and removing items from the positive set accordingly, thereby to allow said information leak prevention policy to be applied for all items remaining in said positive set following said removal of items using ones of said ambiguity resolution criteria, thus mitigating false positive type errors while applying an information leak prevention policy to identify important information that it is desired to protect and to prevent said important information from leaking outwardly of said organization.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: PORTAUTHORITY TECHNOLOGIES, LLC
To: FORCEPOINT LLC
Reel/Frame 043156/0759 →
CHANGE OF NAME Recorded Aug 8, 2016
From: PORTAUTHORITY TECHNOLOGIES, INC.
To: PORTAUTHORITY TECHNOLOGIES, LLC
Reel/Frame 039609/0877 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME 032677/0038 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035796/0881 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME; 032677/0071 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0734 →
SECURITY INTEREST Recorded Apr 15, 2014
From: PORTAUTHORITY TECHNOLOGIES, INC., AS PLEDGOR; WEBSENSE, INC., AS PLEDGOR
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 032677/0038 →
SECURITY INTEREST Recorded Apr 15, 2014
From: PORT AUTHORITY TECHNOLOGIES, INC., AS PLEDGOR; WEBSENSE, INC., AS PLEDGOR
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 032677/0071 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: PORTAUTHORITY TECHNOLOGIES, INC.
Reel/Frame 030692/0510 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 16, 2010
From: PORTAUTHORITY TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 025503/0919 →
TERMINATION OF SECURITY INTEREST IN PATENTS Recorded Nov 19, 2010
From: BANK OF AMERICA, N.A., AS SENIOR COLLATERAL AGENT
To: PORTAUTHORITY TECHNOLOGIES, INC.; WEBSENSE, INC.
Reel/Frame 025408/0520 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME AND ADDRESS, PREVIOUSLY RECORDED AT REEL 018059 FRAME 0701. Recorded Nov 9, 2010
From: TROYANSKY, LIDROR; LITAI, ASSAF; BRUCKNER, SHARON
To: PORTAUTHORITY TECHNOLOGIES INC.
Reel/Frame 025461/0611 →
ASSIGNMENT OF SECURITY INTEREST Recorded Jul 3, 2008
From: MORGAN STANLEY & CO. INCORPORATED, IN ITS CAPACITY AS RESIGNING SENIOR COLLATERAL AGENT
To: BANK OF AMERICA, N.A., IN ITS CAPACITY AS SUCCESSOR SENIOR COLLATERAL AGENT
Reel/Frame 021185/0802 →
SENIOR PATENT SECURITY AGREEMENT Recorded Oct 19, 2007
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. INCORPORATED, AS SENIOR COLLATERAL AGENT
Reel/Frame 019984/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2006
From: TROYANSKY, LIDROR; LITAI, ASSAF; BRUCKNER, SHARON
To: PORTAUTHORITY TECHNOLOGIES
Reel/Frame 018059/0701 →