IP Library Granted Patent US 9,426,179
Granted Patent B2
US 9,426,179 · App. 12/405,642 · Granted Aug 23, 2016

Protecting sensitive information from a secure data store

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,426,179
App. No.
12/405,642
Granted
Aug 23, 2016
Kind
B2
Abstract

In embodiments of the present invention improved capabilities are described for the steps of receiving an indication that a computer facility has access to a secure data store, causing a security parameter of a storage medium local to the computer facility to be assessed, determining if the security parameter is compliant with a security policy relating to computer access of the remote secure data store, and in response to an indication that the security parameter is non-compliant, cause the computer facility to implement an action to prevent further dissemination of information, to disable access to network communications, to implement an action to prevent further dissemination of information, and the like.

Claims (31)

1. A computer program product embodied in a non-transitory computer readable medium that, when executing on a threat management facility, performs steps comprising:

storing a security policy for controlling access by a network endpoint to an encrypted remote secure data store, the security policy requiring a removable data store locally connected to the network endpoint through an external port to meet one or more security requirements for identification as a secure data store, wherein the one or more security requirements include a requirement that the removable data store be encrypted;

receiving an indication at the threat management facility that an endpoint has access to the encrypted remote secure data store;

auditing the endpoint to determine whether a security parameter of a first removable data store locally connected to the endpoint through the external port is compliant with the one or more requirements for identification as a secure data store; and

causing the endpoint to implement an action to regulate dissemination by the endpoint of data from the encrypted remote secure data store in response to a determination that the security parameter of the first removable data store locally connected to the endpoint through the external port is non-compliant, the action comprising disabling network communications other than communication between the threat management facility and the endpoint, including at least communications between the endpoint and the encrypted remote secure data store.

2. The computer program product of claim 1 wherein the action to regulate dissemination of data from the encrypted remote secure data store further includes preventing further dissemination of information from the encrypted remote secure data store.

3. The computer program product of claim 1 wherein the action to regulate dissemination of data from the encrypted remote secure data store further includes preventing further dissemination of information through a network from the first removable data store locally connected to the to the endpoint through the external port.

4. The computer program product of claim 1 wherein the action to regulate dissemination of data from the encrypted remote secure data store further includes implementing an action independent of network access to prevent further dissemination of information through a network from the endpoint.

5. The computer program product of claim 1 wherein the action to regulate dissemination of data from the encrypted remote secure data store further includes disabling write capabilities to all data stores associated with the endpoint.

6. The computer program product of claim 1 wherein the action to regulate dissemination of data from the encrypted remote secure data store further includes disabling all local port communications.

7. The computer program product of claim 6 wherein the local port communications include one or more of Bluetooth and Universal Serial Bus (USB).

8. The computer program product of claim 1 wherein the security policy is for access to a password protected secure data store.

9. The computer program product of claim 1 wherein the security policy further requires that endpoint software on the endpoint is up to date before permitting access by the endpoint to the encrypted remote secure data store.

10. The computer program product of claim 1 wherein the threat management facility is a threat management facility associated with an enterprise.

11. A system, comprising:

a processor; and

a non-transitory computer readable medium comprising instructions that when executed on the processor cause the processor to perform steps comprising:

storing a security policy for controlling access by a network endpoint to an encrypted remote secure data store, the security policy requiring a removable data store locally connected to the network endpoint through an external port to meet one or more security requirements for identification as a secure data store, wherein the one or more security requirements include a requirement that the removable data store be encrypted;

receiving an indication at a threat management facility that an endpoint has access to the encrypted remote secure data store;

auditing the endpoint to determine whether a security parameter of a first removable data store locally connected to the endpoint through the external port is compliant with the one or more requirements of the security policy for identification as a secure data store; and

in response to a determination that the security parameter of the first removable data store locally connected to the endpoint through the external port is non-compliant, causing the endpoint to implement an action to regulate dissemination by the endpoint of data from the encrypted remote secure data store, the action comprising disabling network communications other than communication between the threat management facility and the endpoint, including at least communications between the endpoint and the encrypted remote secure data store.

12. The system of claim 11 wherein the instructions further cause the processor to implement the action to regulate dissemination of data from the encrypted remote secure data store by implementing an action independent of network access to prevent further dissemination of information through a network from the endpoint.

13. A system, comprising:

a network device; and

a threat management facility, the threat management facility comprising:

a processor; and

a non-transitory computer readable medium comprising instructions, the instructions when executed by the processor cause the processor to perform steps comprising:

storing a security policy for controlling access by a network endpoint to an encrypted remote secure data store, the security policy requiring a removable data store connected to the network device through an external port to meet one or more security requirements for identification as a secure data store, wherein the one or more security requirements include a requirement that the removable data store be encrypted;

receiving an indication at the threat management facility that a network device has access to the encrypted remote secure data store;

causing the network device toperform an audit to determine whether a security parameter of a first removable data store locally connected to the network device through the external port is compliant with the one or more requirements of the security policy for identification as the secure data store; and

in response to a determination that the security parameter of the removable data store is non-compliant, causing the network device to implement an action to regulate dissemination by the network device of data from the encrypted remote secure data store, the action comprising disabling network communications other than communication between the threat management facility and the endpoint, including at least communications between the endpoint and the encrypted remote secure data store.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
RELEASE OF SECURITY INTEREST Recorded Jul 28, 2020
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: SOPHOS LIMITED
Reel/Frame 053334/0220 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF SECURITY INTEREST Recorded Feb 3, 2014
From: JPMORGAN CHASE BANK, N.A.
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 032152/0883 →
CHANGE OF NAME Recorded Apr 11, 2013
From: SOPHOS PLC
To: SOPHOS LIMITED
Reel/Frame 030194/0299 →
SECURITY INTEREST Recorded May 11, 2012
From: RBC EUROPE LIMITED, AS EXISTING ADMINISTRATION AGENT AND COLLATERAL AGENT
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 028198/0285 →
SECURITY AGREEMENT Recorded Aug 8, 2011
From: SOPHOS LIMITED F/K/A SOPHOS PLC
To: ROYAL BANK OF CANADA EUROPE LIMITED, AS COLLATERAL AGENT
Reel/Frame 026717/0424 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2009
From: KEENE, DAVID P.; DONLEY, DARYL E.
To: SOPHOS PLC
Reel/Frame 022409/0224 →