IP Library Granted Patent US 9,489,515
Granted Patent B2
US 9,489,515 · App. 13/156,952 · Granted Nov 8, 2016

System and method for blocking the transmission of sensitive data using dynamic data tainting

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,489,515
App. No.
13/156,952
Granted
Nov 8, 2016
Kind
B2
Abstract

Blocking transmission of tainted data using dynamic data tainting is described. For example, sensitive information is stored on a client device as tainted data. The client device generates a data request for retrieving data from a non-trusted entity via a network. A gateway is communicatively coupled to the client device and the network. The gateway receives computer code from the non-trusted entity via the network. The gateway executes the computer code. The gateway tracks the execution of the computer code to determine whether the computer code attempts to access tainted data and transmit the tainted data to an outside entity. The gateway blocks the transmission of the tainted data to the outside entity responsive to determining that the computer code has attempted to access tainted data and transmit the tainted data to an outside entity.

Claims (46)

1. A computer-implemented method comprising:

in response to determining that a data structure object is a first type, tainting the data structure object by modifying a taint bit of a property field of the data structure object, the data structure object included in first data;

tracking, at a gateway device, execution of computer code received from a non-trusted entity via a network, the computer code received by the gateway when sent by the non-trusted entity to a client device in response to a request from the client device, the tracking including identifying that the computer code performs an operation on the tainted first data;

when the operation on the tainted first data results in second data, tainting the second data;

detecting that the computer code attempts a network transmission to the non-trusted entity; and

when the attempted network transmission includes at least one of the tainted first data or the tainted second data, blocking transmission of the at least one of the tainted first data or the tainted second data.

2. The computer-implemented method of claim 1 , further including:

generating a virtual container; and

storing the computer code in the virtual container prior to execution of the computer code, the execution of the computer code and the tracking of the executed computer code occurring while the computer code is stored in the virtual container.

3. The computer-implemented method of claim 2 , further including:

determining whether the computer code includes dynamic content; and

storing the computer code in the virtual container when the computer code includes the dynamic content.

4. The computer-implemented method of claim 3 , wherein the dynamic content includes at least one of JavaScript, Flash Application, HyperText Markup Language, Visual Basic Scripting Edition, Cascading Style Sheet, Extensible Markup Language, or Portable Document Format.

5. The computer-implemented method of claim 2 , wherein the virtual container blocks the computer code from accessing the network.

6. The computer-implemented method of claim 1 further including, analyzing a source of data requested by the computer code.

7. A tangible computer readable storage device or storage disc comprising instructions that, when executed, cause a gateway to at least:

in response to determining that a data structure object is a first type, taint the data structure object by modifying a taint bit of a property field of the data structure object, the data structure object included in first data

track execution of computer code received from a non-trusted entity via a network, the computer code sent by the non-trusted entity in response to a request from a client device, to track the execution of the computer code, the instructions cause the gateway to identify that the computer code performs an operation on the tainted first data;

when the operation on the tainted first data results in second data, taint the second data;

detect that the computer code attempts a network transmission to the non-trusted entity; and

when the attempted network transmission includes at least one of the tainted first data or the tainted second data, block transmission of the at least one of the tainted first data or the tainted second data.

8. The tangible computer readable storage device or storage disc of claim 7 , wherein the instructions further cause the gateway to:

generate a virtual container; and

store the computer code in the virtual container prior to execution of the computer code, the execution of the computer code and the tracking of the executed computer code occurring while the computer code is stored in the virtual container.

9. The tangible computer readable storage device or storage disc of claim 8 , wherein the instructions further cause the gateway to:

determine whether the computer code includes dynamic content; and

store the computer code in the virtual container when that the computer code includes the dynamic content.

10. A gateway comprising:

an initial tainting engine to, in response to determining that a data structure object is a first type, taint the data structure object by modifying a taint bit of a property field of the data structure object, the data structure object included in first data;

a content type engine to analyze computer code received from a web application, wherein the property field of the data structure object has been modified by the tainting engine prior to the content type engine analyzing the computer code;

a sandbox module to execute the received computer code; and

a detection engine to:

identify that the computer code performs an operation on the tainted first data;

when the operation on the tainted first data results in second data, taint the second data;

detect that the computer code attempts a network transmission to a non-trusted entity; and

when the attempted network transmission includes at least one of the tainted first data or the tainted second data, block transmission of the at least one of the tainted first data or the tainted second data.

11. The gateway of claim 10 , wherein the sandbox module is to generate a virtual container and store the computer code in the virtual container prior to executing the computer code, the sandbox module to execute the computer code in the virtual container and the detection engine to detect the the attempted network transmission while the computer code is in the virtual container.

12. The gateway of claim 11 , wherein the content type engine is to determine whether the computer code includes dynamic content and the sandbox module is to store the computer code in the virtual container if the computer code includes dynamic content.

13. The gateway of claim 12 , wherein the dynamic content includes at least one of JavaScript, Flash Application, HyperText Markup Language, Visual Basic Scripting Edition, Cascading Style Sheet, Extensible Markup Language, or Portable Document Format.

14. The gateway of claim 11 , wherein the virtual container is to block the computer code from accessing a network.

15. The computer-implemented method of claim 1 , wherein the first type is at least one of a form object, a document object, an input element object, a history object, an image object, and option object, a location object, a link object, a plug-in object, or a window object.

16. The computer-implemented method of claim 1 , further including, when the attempted network transmission includes the at least one of the first data or the second data, determining the computer code is malicious.

17. The tangible computer readable storage device or storage disc of claim 7 , wherein the first type is at least one of a form object, a document object, an input element object, a history object, an image object, and option object, a location object, a link object, a plug-in object, or a window object.

18. The tangible computer readable storage device or storage disc of claim 7 , wherein the instructions further cause the gateway to determine that the computer code is malicious when the attempted network transmission includes the at least one of the first data or the second data.

19. The gateway of claim 10 , wherein the first type is at least one of a form object, a document object, an input element object, a history object, an image object, and option object, a location object, a link object, a plug-in object, or a window object.

20. The gateway of claim 10 , wherein the detection engine is to determine that the computer code is malicious when the attempted network transmission includes the at least one of the first data or the second data.

Assignments (14)
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
MERGER Recorded Feb 14, 2024
From: TW SECURITY CORP.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 066584/0338 →
SECURITY INTEREST Recorded Feb 14, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066584/0330 →
MERGER Recorded Mar 12, 2015
From: M86 SECURITY, INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 035147/0632 →
SECURITY AGREEMENT Recorded Aug 30, 2012
From: TRUSTWAVE HOLDINGS, INC.; TW SECURITY CORP.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 028885/0090 →
MERGER Recorded Aug 9, 2012
From: M86 SECURITY, INC.
To: TW SECURITY CORP.
Reel/Frame 028761/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2011
From: YERMAKOV, ALEXANDER; KAPLAN, MARK
To: M86 SECURITY, INC.
Reel/Frame 026420/0178 →