IP Library Patent Application 12410731
Patent Application
App. No. 12/410,731

METHOD AND SYSTEM FOR PREVENTING DATA LEAKAGE FROM A COMPUTER FACILTY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/410,731
Abstract

In embodiments of the present invention improved capabilities are described for the steps of identifying, through a monitoring module of a security software component, a data extraction behavior of a software application attempting to extract data from an endpoint computing facility; and in response to a finding that the data extraction behavior is related to extracting sensitive information and that the behavior is a suspicious behavior, causing the endpoint to perform a remedial action. The security software component may be a computer security software program, a sensitive information compliance software program, and the like.

Claims (22)

1 . A computer program product embodied in a computer readable medium that, when executing on one or more computers, performs the steps of:

identifying, through a monitoring module of a security software component, a data extraction behavior of a software application attempting to extract data from an endpoint computing facility; and

in response to a finding that the data extraction behavior is related to extracting sensitive information and that the behavior is a suspicious behavior, causing the endpoint to perform a remedial action.

2 . The computer program product of claim 1 , wherein the security software component is a computer security software program.

3 . The computer program product of claim 1 , wherein the security software component is a sensitive information compliance software program.

4 . The computer program product of claim 1 , wherein the remedial action is to ID the software application as malware.

5 . The computer program product of claim 1 , wherein the remedial action is alerting the user.

6 . The computer program product of claim 1 , wherein the remedial action is alerting the user and initiate a request for DLP action.

7 . The computer program product of claim 1 , wherein the remedial action is to add the software application to a blacklist.

8 . The computer program product of claim 1 , wherein the suspicious behavior is an attempt to extract contacts from an address book.

9 . The computer program product of claim 1 , wherein the suspicious behavior is an attempt to extract credit card information.

10 . The computer program product of claim 1 , wherein the suspicious behavior is an attempt to extract personal information.

11 . The computer program product of claim 1 , wherein the suspicious behavior is an attempt to extract confidential information.

12 . The computer program product of claim 11 , wherein the confidential information is from a registry.

13 . The computer program product of claim 11 , wherein the confidential information is from local files.

14 . The computer program product of claim 11 , wherein the confidential information is from a honeypot.

15 . The computer program product of claim 11 , wherein the suspicious behavior is scanning the whole disk for confidential data.

16 . The computer program product of claim 1 , wherein a central policy maintains application categories, including a white and a black list, and disseminates the application categories to the endpoint computing facility.

17 . The computer program product of claim 1 , wherein the step of identifying the data extraction behavior is only initiated if the software application is not on either a white or black list.

18 . The computer program product of claim 1 , wherein the step of identifying the data extraction behavior is only initiated if the software application is on a grey list.

19 . The computer program product of claim 1 , wherein a black list prevents the application from running.

20 . The computer program product of claim 1 , wherein a black list allows the application to run while preventing it from leaking any data.

Assignments (5)
ASSIGNMENT OF SECURITY INTEREST Recorded Feb 3, 2014
From: JPMORGAN CHASE BANK, N.A.
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 032152/0883 →
CHANGE OF NAME Recorded Apr 11, 2013
From: SOPHOS PLC
To: SOPHOS LIMITED
Reel/Frame 030194/0299 →
SECURITY INTEREST Recorded May 11, 2012
From: RBC EUROPE LIMITED, AS EXISTING ADMINISTRATION AGENT AND COLLATERAL AGENT
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 028198/0285 →
SECURITY AGREEMENT Recorded Aug 8, 2011
From: SOPHOS LIMITED F/K/A SOPHOS PLC
To: ROYAL BANK OF CANADA EUROPE LIMITED, AS COLLATERAL AGENT
Reel/Frame 026717/0424 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2009
From: GRANT, CALUM A. M.
To: SOPHOS PLC
Reel/Frame 022495/0122 →