IP Library Granted Patent US 8,407,784
Granted Patent B2
US 8,407,784 · App. 12/051,670 · Granted Mar 26, 2013

Method and system for protection against information stealing software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,407,784
App. No.
12/051,670
Granted
Mar 26, 2013
Kind
B2
Abstract

A system and method for identifying infection of unwanted software on an electronic device is disclosed. A software agent configured to generate a bait and is installed on the electronic device. The bait can simulate a situation in which the user performs a login session and submits personal information or it may just contain artificial sensitive information. Parameters may be inserted into the bait such as the identity of the electronic device that the bait is installed upon. The output of the electronic device is monitored and analyzed for attempts of transmitting the bait. The output is analyzed by correlating the output with the bait and can be done by comparing information about the bait with the traffic over a computer network in order to decide about the existence and the location of unwanted software. Furthermore, it is possible to store information about the bait in a database and then compare information about a user with the information in the database in order to determine if the electronic device that transmitted the bait contains unwanted software.

Claims (24)

1. A computer-implemented method for reducing exposure to a dictionary attack on an organizational password file comprising a plurality of passwords, the plurality of passwords configured for use by users to access sensitive resources, while verifying whether data transmitted over a computer network is one of the plurality of passwords, the method comprising:

performing, using an electronic processor, a first encoding, of the plurality of passwords with a Bloom filter;

searching, using an electronic processor, outgoing traffic from at least one computerized device within an organizational perimeter to a site outside the organizational perimeter, by performing a second encoding of the outgoing traffic with the Bloom filter;

performing, using an electronic processor, a weak validation based on a result of the first encoding and a result of the second encoding;

determining, using an electronic processor, the existence of one of the plurality of passwords in the outgoing traffic based only on the weak validation;

determining, using an electronic processor, whether to block, alert, or quarantine the outgoing traffic based at least in part on the existence of one of the plurality of passwords in the outgoing traffic; and

enforcing, using an electronic processor, the determination of whether to block, alert, or quarantine the outgoing traffic.

2. The method of claim 1 , wherein the searching of the outgoing traffic is performed by a traffic analyzer in communication with the computer network.

3. The method of claim 2 , wherein the traffic analyzer is configured to block the data from being transmitted over the network if the data is one of the plurality of passwords.

4. The method of claim 1 , wherein a percent of false positives provided by the Bloom Filter is tunable.

5. A system for reducing exposure of an organizational password file comprising a plurality of passwords to a dictionary attack, wherein the passwords in the password file are configured for use by users to access sensitive resources, while verifying whether data transmitted over a computer network is one of the plurality of passwords, the system comprising:

a management unit configured to perform a first encoding of the plurality of passwords in the organizational password file using a Bloom filter;

a processor configured to execute computer instructions, wherein the computer instructions implement a traffic analyzer in communication with the computer network, the traffic analyzer being configured to search outgoing traffic from at least one computerized device within an organizational perimeter to a site outside the organizational perimeter by performing a second encoding using the Bloom filter and perform a weak validation based on a result of the first encoding and a result of the second encoding, determining the existence of one of the plurality of passwords in the outgoing traffic based only on the weak validation; and

a decision system configured to make a decision whether to do at least one of “block”, “alert” or “quarantine” the traffic based at least in part on the existence of one of the plurality of passwords in the outgoing traffic, and enforce the decision on the traffic.

6. The system of claim 5 , further comprising a gateway configured to receive instructions from the decision system.

7. The system of claim 6 , wherein the traffic analyzer is installed on the gateway.

8. The system of claim 5 , wherein a percent of false positives provided by the Bloom Filter is tunable.

9. A system for reducing exposure of an organizational password file comprising a plurality of passwords to a dictionary attack, wherein the passwords in the password file are configured for use by users to access sensitive resources, while verifying whether data transmitted over a computer network is one of the plurality of passwords, the system comprising:

means for performing a first encoding of the plurality of passwords in the organizational password file using a Bloom filter;

a processor configured to execute computer instructions, wherein the computer instructions include data traffic analyzer means in communication with the computer network, the traffic analyzer means for searching outgoing traffic from at least one computerized device within an organizational perimeter to a site outside the organizational perimeter by performing a second encoding using the Bloom filter and for performing a weak validation based on a result of the first encoding and a result of the second encoding and determining the existence of one of the plurality of passwords in the outgoing traffic based only on the weak validation;

decision means for making a decision whether to do at least one of “block”, “alert” or “quarantine” the outgoing traffic based at least in part on the existence of one of the plurality of passwords in the outgoing traffic; and

enforcing means for enforcing the decision on the outgoing traffic.

10. The system of claim 9 , wherein the traffic analyzer means blocks the data from being transmitted over the network if the data is one of the plurality of passwords.

11. The system of claim 9 , wherein a percent of false positives provided by the Bloom Filter is tunable.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: WEBSENSE, INC.
Reel/Frame 030693/0424 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 16, 2010
From: WEBSENSE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 025503/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2008
From: TROYANSKY, LIDROR
To: WEBSENSE, INC.
Reel/Frame 021442/0679 →