IP Library Granted Patent US 9,015,842
Granted Patent B2
US 9,015,842 · App. 12/051,579 · Granted Apr 21, 2015

Method and system for protection against information stealing software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,015,842
App. No.
12/051,579
Granted
Apr 21, 2015
Kind
B2
Abstract

A system and method for identifying infection of unwanted software on an electronic device is disclosed. A software agent configured to generate a bait and is installed on the electronic device. The bait can simulate a situation in which the user performs a login session and submits personal information or it may just contain artificial sensitive information. Parameters may be inserted into the bait such as the identity of the electronic device that the bait is installed upon. The output of the electronic device is monitored and analyzed for attempts of transmitting the bait. The output is analyzed by correlating the output with the bait and can be done by comparing information about the bait with the traffic over a computer network in order to decide about the existence and the location of unwanted software. Furthermore, it is possible to store information about the bait in a database and then compare information about a user with the information in the database in order to determine if the electronic device that transmitted the bait contains unwanted software.

Claims (36)

1. A method for monitoring a plurality of electronic devices to detect infection by unwanted software, the method comprising:

installing, using a management unit executing on a processor and in communication with the plurality of electronic devices, a software agent on each of the plurality of electronic devices, each of the software agents configured to perform a login session using a bait that contains artificial sensitive information, and configured to insert parameters into the bait prior to transmission of an electronic output of the plurality of electronic devices;

monitoring, using a traffic analyzer executing on an electronic device, the electronic output; and

analyzing, using a decision system executing on a processor and in communication with the traffic analyzer, the electronic output in response to the bait to determine the existence of unwanted software based on the electronic output including a transmission of the bait unrelated to the login session to another electronic device.

2. The method of claim 1 , wherein the electronic output is analyzed by correlating the output with the bait.

3. The method of claim 2 , wherein the correlation is performed by comparing information of the bait with traffic over a computer network in order to decide about the existence and the location of unwanted software.

4. The method of claim 1 , further comprising:

storing information about the bait in a database; and

comparing information from a user with the information in the database in order to determine if the electronic device that transmitted the bait contains unwanted software.

5. The method of claim 1 , further comprising:

providing the artificial sensitive information with the bait to a target site;

configuring the artificial sensitive information to identify the electronic device; and

monitoring the target site for detection of the artificial sensitive information to determine the existence of unwanted software on the electronic device.

6. A system for monitoring a plurality of electronic devices to detect infection by unwanted software, the system comprising:

an electronic processor operably coupled to a memory, the memory storing processor instructions implementing a management unit that is in communication with the plurality of electronic devices, the management unit configured to install a software agent on each of the plurality of electronic devices, wherein each of the software agents are configured to perform a login session using a bait that contains artificial sensitive information and insert parameters into the bait before transmission of an electronic output of the plurality of electronic devices;

an electronic processor operably coupled to a memory, the memory storing processor instructions implementing a traffic analyzer and in communication with the computer network, the traffic analyzer configured to monitor the electronic output of the plurality of electronic devices; and

an electronic processor operably coupled to a memory, the memory storing processor instructions implementing a decision system that is in communication with the traffic analyzer, the decision system configured to determine the existence of unwanted software based on a transmission of the bait unrelated to the login session by one of the plurality of electronic devices to another electronic device.

7. The system of claim 6 , further comprising a network gateway in communication with the computer network wherein the traffic analyzer is installed on the network gateway.

8. A method for monitoring a first group of electronic devices to detect infection by unwanted software, the method comprising:

installing a software agent on each of the electronic devices of the first group, the software agent being configured to perform a login session using a bait that contains artificial sensitive information for each one of the electronic devices of the first group, wherein the software agent is further configured to insert parameters into the bait prior to transmission of a first electronic output of the first group of electronic devices;

monitoring, using a first electronic device, the first electronic output to a network from at least one electronic device of the first group;

monitoring, using the first electronic device, a second electronic output to the network from at least one of the electronic devices of a second group of electronic devices; and

analyzing the first and second electronic output to identify that the first electronic output includes a transmission of the bait unrelated to the login session to a third electronic device to determine the existence of unwanted software within the first group.

9. The method of claim 8 , wherein the second group of electronic devices is used as a baseline for analyzing the first electronic output in order to determine the existence of unwanted software.

10. A system for monitoring a first group of electronic devices to detect infection by unwanted software, the system comprising:

an electronic processor operably coupled to a memory, the memory storing processor instructions implementing a management unit for installing a software agent on each of the electronic devices of the first group, the software agent being configured to perform a login session using a bait that contains artificial sensitive information on each of the electronic devices of the first group, and to insert parameters into the bait prior to transmission of an electronic output by the first group of electronic devices;

an electronic processor operably coupled to a memory, the memory storing processor instructions implementing a traffic analyzer executing on a first electronic device and in communication with the first group and a second group of electronic devices by a computer network, the traffic analyzer configured to analyze the electronic output from the first group and an electronic output from the second group of electronic devices; and

an electronic processor operably coupled to a memory, the memory storing processor instructions implementing a decision system in communication with the traffic analyzer, the decision system configured to compare the output of the first group of electronic devices with the output from the second group of electronic devices in order to identify that the electronic output of the first group of electronic devices includes a transmission of the bait unrelated to the login session to a third electronic device to determine the existence of unwanted software within the first group.

11. The system of claim 10 , further comprising a gateway wherein the traffic analyzer is installed on the gateway.

12. The method of claim 1 , wherein the software agent performs a login session by inputting a sequence of keystrokes.

13. The system of claim 6 , wherein the software agent performs a login session by inputting a sequence of keystrokes.

14. The system of claim 6 , wherein the software agent performs a login session on a website.

15. The method of claim 1 , wherein the parameters are keywords included in the bait.

16. The system of claim 6 , wherein the parameters are keywords included in the bait.

17. The method of claim 8 , wherein the parameters are keywords included in the bait.

18. The system of claim 10 , wherein the parameters are keywords included in the bait.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: WEBSENSE, INC.
Reel/Frame 030693/0424 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 16, 2010
From: WEBSENSE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 025503/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2008
From: TROYANSKY, LIDROR; BRUCKNER, SHARON; HUBBARD, DANIEL LYLE
To: WEBSENSE, INC.
Reel/Frame 021442/0622 →