IP Library Granted Patent US 8,392,992
Granted Patent B1
US 8,392,992 · App. 12/130,016 · Granted Mar 5, 2013

Method and apparatus for preventing sensitive data leakage due to input focus misappropriation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,392,992
App. No.
12/130,016
Granted
Mar 5, 2013
Kind
B1
Abstract

A method and apparatus for preventing sensitive data leakage due to input focus misappropriation is described. In one embodiment, a method for restricting a change in an input focus to protect sensitive data comprising identifying a visual representation component used to receive sensitive data, wherein the virtual representation component having an input focus of a computer and preventing a change in the input focus from the visual representation component.

Claims (31)

1. A method for restricting a change in an input focus to protect sensitive data, comprising:

identifying a visual representation component used to receive sensitive data, wherein the visual representation component has an input focus of a computer, wherein identifying the visual representation component comprises determining whether the visual representation component is used for receiving sensitive data, wherein determining whether the visual representation component is used for receiving sensitive data comprises determining whether a visual style of the visual representation component is associated with a password, wherein determining whether a visual style of the visual representation component is associated with a password comprises examining a style constant for the visual representation component; and

preventing a change in the input focus from the visual representation component.

2. The method of claim 1 , wherein the visual representation component is

associated with access to a resource.

3. The method of claim 1 , wherein preventing the change further comprising:

examining a plurality of computer window messages; and

determining a first computer window message that is configured to cause the change in the input focus.

4. The method of claim 3 , wherein the first computer window message is configured to invalidate a current computer window, wherein the current computer window comprises the visual representation component.

5. The method of claim 3 , wherein preventing the change further comprises disabling the first computer window message.

6. The method of claim 3 , wherein preventing the change further comprises invoking a hook associated with the visual representation component to block the change in the input focus in response to the first computer window message.

7. The method of claim 1 , wherein preventing the change further comprises monitoring a computer window message queue to detect the change in the input focus.

8. The method of claim 1 , wherein preventing the change further comprises disabling an ability of an application to change the input focus.

9. The method of claim 1 further comprising permitting the change the input focus based on computer user approval.

10. The method of claim 1 , wherein identifying the visual representation component further comprises examining a property of the visual representation component, wherein the property indicates that the visual representation component has the input focus.

11. The method of claim 1 , wherein determining whether the visual representation component is used for receiving sensitive data further comprises determining whether the visual representation component is used for receiving a social security number or a bank account number.

12. An apparatus for restricting a change in an input focus to protect sensitive data, comprising:

a detection module for recognizing a visual representation component associated with receiving sensitive data, wherein the visual representation component has an input focus of a computer, wherein recognizing the visual representation component comprises determining whether the visual representation component is used for receiving sensitive data, wherein determining whether the visual representation component is used for receiving sensitive data comprises determining whether a visual style of the visual representation component is associated with a password, wherein determining whether a visual style of the visual representation component is associated with a password comprises examining a style constant for the visual representation component; and;

a prevention module for blocking a change in the input focus away from visual representation component.

13. The apparatus of claim 12 , wherein the detection module determines the visual representation component is used for receiving a password.

14. The apparatus of claim 12 , wherein the prevention module examines a windows message queue to identify a message related to the change in the input focus.

15. The apparatus of claim 12 , wherein the detection module recognizes a visual style of the visual representation component that is associated with a password and identifies the visual representation component as a security risk.

16. The apparatus of claim 12 , wherein the prevention module generates a computer window for prompting a user for permission to permit the change the input focus.

17. An apparatus for restricting a change in an input focus to protect sensitive data, comprising:

a first application for processing sensitive data using a visual representation component, wherein the visual representation component has an input focus of a computer;

a second application for communicating a message that is configured to change the input focus;

a detection module for examining the visual representation component to determine that the visual representation component is associated with processing the sensitive data, wherein determining that the visual representation component is associated with processing the sensitive data comprises determining whether a visual style of the visual representation component is associated with a password, wherein determining whether a visual style of the visual representation component is associated with a password comprises examining a style constant for the visual representation component; and

a prevention module for handling the message communicated by the second application to block the change in the input focus away from visual representation component.

18. The apparatus of claim 17 , wherein the visual representation component invokes the prevention module in response to the message communicated by the second application.

19. The apparatus of claim 17 , wherein the prevention module generates a computer window for prompting a user for approval of the change in the input focus.

20. The apparatus of claim 17 , wherein the prevention module permits the message communicated by the second application to change the input focus based on an approval by the user.

Assignments (4)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2008
From: SPERTUS, MICHAEL
To: SYMANTEC CORPORATION
Reel/Frame 021021/0972 →