IP Library Granted Patent US 9,130,986
Granted Patent B2
US 9,130,986 · App. 12/051,616 · Granted Sep 8, 2015

Method and system for protection against information stealing software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,130,986
App. No.
12/051,616
Granted
Sep 8, 2015
Kind
B2
Abstract

A system and method for identifying infection of unwanted software on an electronic device is disclosed. A software agent configured to generate a bait and is installed on the electronic device. The bait can simulate a situation in which the user performs a login session and submits personal information or it may just contain artificial sensitive information. Parameters may be inserted into the bait such as the identity of the electronic device that the bait is installed upon. The output of the electronic device is monitored and analyzed for attempts of transmitting the bait. The output is analyzed by correlating the output with the bait and can be done by comparing information about the bait with the traffic over a computer network in order to decide about the existence and the location of unwanted software. Furthermore, it is possible to store information about the bait in a database and then compare information about a user with the information in the database in order to determine if the electronic device that transmitted the bait contains unwanted software.

Claims (28)

1. A computer-implemented method of controlling dissemination of sensitive information over an electronic network to a destination, the method comprising:

analyzing traffic on the electronic network to detect an attempt to transmit a password to the destination, wherein the destination is an external site on the Internet;

determining a strength of the password based on one or more of a length of the password, a similarity of the password to a set of other passwords, and an entropy score of the password;

determining a sensitivity of information protected by the password based on the strength of the password, wherein the sensitivity is positively correlated with the strength of the password such that a stronger password results in a determination of higher sensitivity and a weaker password result in a determination of lower sensitivity;

in response to the attempt to transmit the password to the destination, classifying content at the destination to determine a category of the content by executing computer instructions on a processor, wherein the category denotes whether the destination node is malicious;

assessing a risk level incurred if the password leaves the electronic network and is passed to the destination based at least in part on the category and the sensitivity of information protected by the password; and

determining a required action based on the risk level, wherein the required action includes one or more of blocking, quarantining, or alerting, wherein relatively stronger passwords receive relatively stronger protection from being passed in clear-text over a non-secure connection.

2. The method of claim 1 , wherein the risk level is further assessed based on at least one of geolocation, analysis of a recipient URL identifying content at the destination, and previous knowledge about the destination.

3. The method of claim 1 , wherein the required action is based, at least in part, on parameters settable by an operator.

4. The method of claim 1 , further comprising determining longer passwords are stronger than shorter passwords.

5. The method of claim 1 , further comprising determining less similar passwords are stronger than more similar passwords.

6. The method of claim 1 , further comprising determining higher entropy passwords are stronger than lower entropy passwords.

7. The method of claim 1 , further comprising determining a higher level of risk with a stronger password than with a weaker password.

8. A system for controlling dissemination of sensitive information over an electronic network to a destination, the system comprising:

a processor configured to execute computer instructions, wherein the computer instructions implement a traffic analyzer, the traffic analyzer in communication with the electronic network and configured to detect an attempt to transmit a password to the destination, wherein the destination is an external site on the Internet;

the traffic analyzer configured to, in response to the attempt to transmit the password to the destination:

determine a strength of the password based on one or more of a length of the password, a similarity of the password to a set of other passwords, and an entropy score of the password;

determine a sensitivity of information protected by the password based on the strength of the password, wherein the sensitivity is positively correlated with the strength of the password such that a stronger password results in a determination of higher sensitivity and a weaker password result in a determination of lower sensitivity,

classify content at the destination to determine a category of the content,

assess a risk level incurred if the password leaves the electronic network and is passed to the destination based at least in part on the category and the sensitivity of the information protected by the password, and to

determine a required action in response to the risk level, wherein the required action includes one or more of blocking, quarantining, or alerting, wherein relatively stronger passwords receive relatively stronger protection from being passed in clear-text over a non-secure connection.

9. The system of claim 8 , wherein the risk level is further assessed based on at least one of geolocation, analysis of a URL identifying content at the destination, and previous knowledge about the destination.

10. The system of claim 8 , wherein the traffic analyzer is configured to block transmission of the password over the network in response to the risk level.

11. The system of claim 8 , wherein the required action is based, at least in part, on parameters settable by an operator.

12. The system of claim 8 , wherein the traffic analyzer is further configured to, in response to the attempt to transmit the password to the destination, determine longer passwords are stronger than shorter passwords.

13. The system of claim 8 , wherein the traffic analyzer is further configured to, in response to the attempt to transmit the password to the destination determine less similar passwords are stronger than more similar passwords.

14. The system of claim 8 , wherein the traffic analyzer is further configured to, in response to the attempt to transmit the password to the destination, determine higher entropy passwords are stronger than lower entropy passwords.

15. The system of claim 8 , wherein the traffic analyzer is further configured to, in response to the attempt to transmit the password to the destination, determine a higher level of risk with a stronger password than with a weaker password.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: WEBSENSE, INC.
Reel/Frame 030693/0424 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 16, 2010
From: WEBSENSE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 025503/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2008
From: TROYANSKY, LIDROR
To: WEBSENSE, INC.
Reel/Frame 021442/0666 →