IP Library Granted Patent US 8,370,948
Granted Patent B2
US 8,370,948 · App. 12/051,709 · Granted Feb 5, 2013

System and method for analysis of electronic information dissemination events

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,370,948
App. No.
12/051,709
Granted
Feb 5, 2013
Kind
B2
Abstract

A system and method for determining an intent of a sender in transmitting electronic information in order to prevent unauthorized dissemination of electronic information is disclosed. The system and method facilitate cost-effective handling of dissemination events and comprise a traffic analyzer configured to analyze descriptors of the electronic information and parameters of the transmission of the electronic information in order to determine the intent of the sender. By determining the intent of the sender, it is possible to effectively quarantine the electronic information before it is disseminated.

Claims (35)

1. A computerized system for determining an intent of a sender in transmitting electronic information in order to prevent unauthorized dissemination of the electronic information and to facilitate cost-effective handling of dissemination events, the system comprising:

computer hardware configured by instructions to determine whether a distribution list of the electronic information includes both a plurality of authorized addresses and one or more unauthorized addresses,

and configured by instructions to determine whether the distribution list of the electronic information includes an unauthorized address whose edit distance from another authorized address is below a threshold,

and configured by instructions to determine whether the sender replies to an original message using a reply to all feature to transmit the electronic information, and an original sender of the original message is authorized,

and configured to execute an intention assessment unit to determine if the intent in sending the electronic information is malicious or a mistake, wherein the sender's intent is determined to be a mistake if:

a distribution list of the electronic information includes both a plurality of authorized addresses and one or more unauthorized addresses, or

the distribution list of the electronic information includes an unauthorized address whose edit distance from another authorized address is below a threshold, or

the sender replies to an original message using a reply to all feature to transmit the electronic information, and an original sender of the original message is authorized.

2. The system of claim 1 , wherein the electronic information comprises descriptors, and wherein the descriptors comprise at least one of the content of the message, the sender of the message, and a recipient of the message.

3. The system of claim 1 , wherein the intention assessment unit is configured to determine whether the electronic information should be disseminated.

4. The system of claim 1 , wherein the intention assessment unit is configured to determine whether the decision about dissemination of the information should be made by the sender.

5. The system of claim 4 , wherein the intention assessment unit evaluates a confidence level based on previously defined confidential information and a severity based at least in part on the potential damage if the electronic information is disseminated.

6. The system of claim 1 , wherein the electronic information comprises descriptors and parameters and wherein the intention assessment unit compares the descriptors and parameters of the electronic information to predefined scenarios in order to determine whether the electronic information should be disseminated.

7. The system of claim 6 , wherein the predefined scenarios are generated from previous electronic information dissemination events.

8. A computer-implemented method for determining an intent of a sender in transmitting electronic information in order to prevent unauthorized dissemination of the electronic information, the method comprising:

receiving the electronic information from a computer network;

determining descriptors and parameters of the electronic information, wherein the descriptors and parameters include a message distribution list;

determining a first condition, based on the descriptors and parameters, of whether the message distribution list includes both a plurality of authorized addresses and one or more unauthorized addresses;

determining a second condition, based on the descriptors and parameters, of whether the distribution list of the electronic information includes an unauthorized address whose edit distance from another, authorized address is below a threshold, or

determining a third condition, based on the descriptors and parameters, of whether the sender replies to an original message using a reply to all feature to transmit the electronic information, and an original sender of the original message is authorized; and

determining the sender mistakenly transmitted the electronic information if at least one of the first condition, second condition, and third condition are true;

sending a network message to the sender if the sender mistakenly transmitted the electronic information.

9. The method of claim 8 , further comprising determining whether the intent of the sender is malicious.

10. The method of claim 8 , further comprising:

determining a confidence level based on a level of similarity of the electronic information to previously defined confidential information;

determining a severity based at least in part on the potential damage if the electronic information is disseminated; and

determining the intent of the sender based, at least in part, on the severity and the confidence level.

11. The method of claim 10 , further comprising determining whether the electronic information should be quarantined based, at least in part, on the determined intent of the sender.

12. The method of claim 11 , further comprising determining whether the decision about releasing the electronic information from the quarantine should be made by the sender based, at least in part, on the determined intent of the sender.

13. The method of claim 8 , further comprising comparing the descriptors and parameters of the electronic information to predefined scenarios in order to determine the intent of the sender.

14. The method of claim 13 , wherein comparing the descriptors and parameters of the electronic information to predefined scenarios comprises finding a nearest neighbor between the descriptors and parameters and the predefined scenarios.

15. The method of claim 8 , further comprising applying heuristics based on the email addresses of the sender and one or more recipients in the distribution list to assess the intention of the sender.

16. The method of claim 8 , further comprising determining whether the electronic information should be disseminated based, at least in part, on the determined intent of the sender.

17. The method of claim 8 , further comprising using the determined intent of the sender in determining whether the decision about dissemination of the information should be made by the sender.

18. The method of claim 11 , further comprising informing the sender of the actions required to release the message from quarantine.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2013
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: WEBSENSE, INC.
Reel/Frame 030693/0424 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 16, 2010
From: WEBSENSE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 025503/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2009
From: TROYANSKY, LIDROR
To: WEBSENSE, INC.
Reel/Frame 023618/0436 →