IP Library Granted Patent US 8,938,773
Granted Patent B2
US 8,938,773 · App. 12/022,838 · Granted Jan 20, 2015

System and method for adding context to prevent data leakage over a computer network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,938,773
App. No.
12/022,838
Granted
Jan 20, 2015
Kind
B2
Abstract

Systems and methods for adding context to prevent data leakage over a computer network are disclosed. Data is classified and contextual information of the data is determined. A transmission policy is determined in response to the classification and contextual information. The data is either transmitted or blocked in response to the classification and the contextual information.

Claims (41)

1. A system for preventing unauthorized transmission of data over a computer network, the system comprising:

a network gateway device in communication with the computer network, the network gateway device configured to receive data in transit between a source and a destination, wherein the network gateway device comprises:

a classification module configured to determine whether the data in transit includes prohibited content;

a context information module configured to generate sender contextual information related to the source of the received data and destination contextual information related to the destination of the received data, wherein the destination contextual information comprises a categorization of the Internet Protocol (IP) address of the destination, and wherein the categorization of the IP address of the destination is based at least in part on website content stored at the destination; and

a transmission policy module configured to determine a transmission policy based on the determination of the classification module and the sender contextual information and the destination contextual information.

2. The system of claim 1 further comprising a database of internet protocol addresses sorted by categories, wherein the categorization of the destination is further based on a comparison of an internet protocol address associated with the destination to the database of internet protocol addresses.

3. The system of claim 1 wherein the destination contextual information is further based on a reputation of the destination.

4. The system of claim 1 wherein the destination contextual information is further based on a geographic location of the destination.

5. The system of claim 4 wherein the sender contextual information comprises an IP address of the data source, a user name or a group of users.

6. The system of claim 4 wherein the destination contextual information further comprises an IP address of the destination, a network of the destination or a category of the destination.

7. The system of claim 4 wherein the transmission policy module is further configured to determine whether the network gateway transmits the data or blocks transmission of the data.

8. The system of claim 7 wherein the transmission policy module is further configured to report that the data source is attempting to transmit data.

9. The system of claim 1 wherein the data source is an electronic device.

10. The system of claim 9 wherein the electronic device is selected from the group consisting of:

a PDA;

a computer; and

a cell phone.

11. The system of claim 1 wherein the computer network is the Internet.

12. The system of claim 1 wherein the network gateway further comprises an enforcement module configured to transmit or block the data in response to data received from the transmission policy module.

13. A method of preventing an unauthorized transmission of data over a computer network, the method comprising:

receiving at a network gateway device connected to a network, data in transit between a source and a destination, wherein the source and the destination are in communication with the network;

classifying the data to determine whether the data includes prohibited content;

generating sender contextual information related to the source of the data;

generating destination contextual information related to the destination of the data, wherein the destination contextual information comprises a categorization of the Internet Protocol (IP) address of the destination, wherein the categorization of the IP address of the destination is based on website content stored at the destination; and

determining a transmission policy for the data in response to the classification of the data and the sender contextual information and the destination contextual information.

14. The method of claim 13 wherein the destination contextual information is further based on a reputation of the destination.

15. The method of claim 14 wherein the destination contextual information is further based on a based on a geographic location of the destination.

16. The method of claim 13 further comprising storing a database of internet protocol addresses sorted by categories, wherein the categorization of the destination is further based on a comparison of an internet protocol address associated with the destination to the database of internet protocol addresses.

17. The method of claim 13 wherein the sender contextual information comprises an IP address of the sender, a user name of the sender or a group name of the user.

18. The method of claim 13 wherein the destination contextual information comprises an IP address of the destination, a network of the destination or a category of the destination.

19. The method of claim 13 further comprising the step of reporting that the data is to be transmitted.

20. The method of claim 13 wherein the step of classifying the data is performed by a classification module.

21. The method of claim 13 wherein the step of determining the contextual information of the data is performed by a context information module.

22. The method of claim 13 wherein the step of determining a transmission policy for the data is performed by a policy/reporting module.

23. The method of claim 13 further comprising the step of sending the data to a network gateway prior to classifying the data.

24. The method of claim 23 wherein the step of sending the data is performed with an electronic device connected to a network.

25. The method of claim 24 , wherein the electronic device is selected from the group consisting of:

a PDA;

a computer; and

a cell phone.

26. The method of claim 24 wherein the network is the Internet.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: WEBSENSE, INC.
Reel/Frame 030693/0424 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 16, 2010
From: WEBSENSE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 025503/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2008
From: HUBBARD, DANIEL LYLE
To: WEBSENSE, INC.
Reel/Frame 021413/0349 →