IP Library Granted Patent US 7,797,270
Granted Patent B2
US 7,797,270 · App. 11/624,635 · Granted Sep 14, 2010

System and method of monitoring and controlling application files

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,797,270
App. No.
11/624,635
Granted
Sep 14, 2010
Kind
B2
Abstract

A system and method for updating a system that controls applications requested for execution on a workstation. A workstation management module is configured to detect requested execution of an application. A workstation application server receives data associated with the application from the workstation. The application server module can determine one or more categories to associate with the application by referencing an application inventory database or requesting the category from an application database factory. The application database factory can receive applications from multiple application server modules. The application database factory determines whether the application was previously categorized and provides the category to the application server module; which forwards a hash/policy table to the workstation management module. Upon receipt of the hash/policy table, the workstation management module applies the policy to control access to the requested application on the workstation.

Claims (63)

1. A method of controlling operation of an application on a workstation, the method comprising:

detecting, with a processor, a launch of an application on the workstation;

determining whether the application is categorized, wherein a categorized application is associated with one or more policies;

if the application is locally categorized, then applying the one or more policies that are associated with the application;

if the application is not locally categorized, then

uploading data indicative of the application to an application server module; and

determining whether the application is identified in an application inventory database of categorized applications, wherein a categorized application is associated with one or more categories; and

if the application is not identified in the application inventory database, then posting the data indicative of the application to an uncategorized application database,

if the application is identified in the application inventory database, then applying one or more policies associated with the application.

2. The method of claim 1 , wherein the one or more policies include allowing or disallowing the application to run based on the one or more categories associated with the application and a user of the workstation.

3. The method of claim 1 further comprising: uploading the uncategorized application database to an application database factory;

determining whether each application has been previously categorized by the application database factory;

for each application that was not previously categorized, categorizing each application and/or data associated with the application by associating one or more categories with each application.

4. The method of claim 3 further comprising:

posting data indicative of each application along with its associated one or more categories into a database of categorized applications; and

downloading the database of categorized applications for incorporation into the application inventory database.

5. The method of claim 3 further comprising:

updating a request frequency in the application inventory database if the application is in the application inventory database; and

uploading the application inventory database request frequency and the associated application to the application database factory.

6. The method of claim 3 , wherein the one or more policies include allowing the application to run on the workstation based on the one or more categories associated with the application and a user of the workstation.

7. The method of claim 3 , wherein the logging database further includes additional data associated with the application.

8. The method of claim 7 , wherein the additional data includes a request frequency.

9. The method of claim 7 , wherein the additional data includes a suite.

10. The method of claim 7 , wherein the additional data includes a publisher.

11. The method of claim 7 , wherein the additional data includes a source directory.

12. The method of claim 1 further comprising:

analyzing the application and/or the additional data associated with the application for data characteristics that are indicative of the one or more categories; and

associating one or more indicators with the application.

13. The method of claim 12 , wherein the analyzing the application and/or additional data is performed on text strings that are associated with the application.

14. The method of claim 12 , wherein the one or more indicators can include a category flag.

15. The method of claim 14 , further comprising screening the application using the one or more indicators prior to uploading the uncategorized application database to the application database factory.

16. A method of controlling execution of programs on a workstation, the method comprising:

detecting with a processor a launch of a program at the workstation;

determining whether the program is identified in a table;

if the program is identified, applying a first rule that is associated with the program;

pre-filtering the program and/or data associated with the program for data characteristics that are indicative of one or more categories;

associating a second rule with the program based on at least in part the one or more categories indicated by the data characteristics;

if the program is not identified, posting data indicative of the program to a database.

17. A method of controlling programs on a workstation, the method comprising:

detecting, with a processor a launch of an application on the workstation;

generating a hash value for the launched application;

determining whether the application is categorized by comparing the generated hash value to one or more hash values in a hash/policy table, the hash/policy table including one or more policies associated with the one or more hash values;

if the generated hash value matches one or more of the hash values in the hash/policy table, then applying the one or more policies that are associated with the one or more hash values;

if the generated hash value does not match one or more hash values in the hash/policy table, then posting information about the application to a logging database;

uploading the logging database to an application server module;

determining whether the application from the logging database is in an application inventory database; and

if the application is not identified in the application inventory database, then posting information about the application to an uncategorized application database.

18. The method of claim 17 further comprising scanning the logging database to determine a frequency count for the application.

19. The method of claim 17 further comprising:

uploading the uncategorized application database to an application database factory;

determining whether the application has been previously categorized by the application database factory; and

for each application that was not previously categorized, categorizing each application by selecting one or more categories associated with that application.

20. The method of claim 19 , further comprising:

posting data indicative of each application along with its selected one or more categories into a database of categorized applications; and

downloading the database of categorized applications for incorporation into the application inventory database.

21. A method of controlling applications on a workstation, the method comprising:

detecting, with a processor, a running application on a workstation;

determining whether the running application is identified in a database;

if the running application is not identified in the database, then storing data indicative of the running application to the database;

associating one or more policies to the running application; and

controlling the running application based on the one or more policies;

pre-filtering the program and/or data associated with the program for data characteristics that are indicative of one or more categories;

associating a rule with the program based on at least in part the one or more categories indicated by the data characteristics.

Assignments (15)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: WEBSENSE, INC.
Reel/Frame 030693/0424 →