IP Library Granted Patent US 8,464,352
Granted Patent B2
US 8,464,352 · App. 13/205,478 · Granted Jun 11, 2013

Techniques for detecting and preventing unintentional disclosures of sensitive data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,464,352
App. No.
13/205,478
Granted
Jun 11, 2013
Kind
B2
Abstract

Protection is provided to prevent a computer user from unintentionally giving away sensitive data (e.g., security credentials, credit card number, PINs, personal data, or bank account number) to an illegitimate or unintended entity by means of a client application capable of communicating the sensitive data across a network to other computer users. To provide the protection, user input is monitored to detect a user entry of the sensitive data into the client application for communication to other users. When such an entry occurs, action is taken to reduce the likelihood of an unintentional giveaway of the sensitive data or to reduce the effects of an unintentional giveaway.

Claims (54)

1. A computer-implemented method of protecting against an unintentional release of sensitive data to an illegitimate or unintended entity, the method comprising:

monitoring data entered by a user into a client application, wherein the monitoring comprises at least one of:

determining whether an intended recipient of the data provided to the client application is globally trusted; and

determining whether the intended recipient of the data provided to the client application is personally trusted;

accessing a set of pattern generating functions;

generating a set of string matching patterns by applying the set of pattern generating functions to sensitive data;

determining, with a processor, that the data being entered into the client application matches one or more of the string matching patterns in the set of string matching patterns; and

in response to determining that the data being entered into the client application matches one or more of the string matching patterns in the set of string matching patterns, performing at least one of: requesting that the user confirm a communication of the data; warning the user that communicating the data might result in an unintentional release of sensitive data to an illegitimate or unintended entity;

preventing the client application from communicating the data; and logging a communication of the data by the client application.

2. The computer-implemented method of claim 1 wherein the client application includes a web page with an input form.

3. The computer-implemented method of claim 1 wherein the client application is an instant messaging application.

4. The computer-implemented method of claim 1 wherein the client application is an e-mail application.

5. The computer-implemented method of claim 1 further comprising:

determining whether the intended recipient of the data entered into the client application is known to be an illegitimate or unintended entity.

6. The computer-implemented method of claim 1 further comprising:

determining whether the intended recipient of the data entered into the client application is known to be a legitimate or intended entity.

7. The computer-implemented method of claim 1 further comprising:

passing the data entered into the client application to a matcher program or object; and

passing at least one of the string-matching patterns to the matcher program or object.

8. The computer-implemented method of claim 1 further comprising:

selecting at least one matcher program or object; and

detecting an entry or partial entry of a variation of the sensitive data by:

passing data entered into the client application to the selected matcher program or object;

passing the sensitive data to the matcher program or object; and

comparing the data entered to a variation of the sensitive data encoded in the matcher program or object.

9. The computer-implemented method of claim 1 further comprising:

determining whether a sequence of events preceding the entry of the data is known to be characteristic of an unintentional giveaway of sensitive data to an illegitimate or unintended entity.

10. The computer-implemented method of claim 1 further comprising:

determining whether a sequence of events preceding the entry of the data is known to be characteristic of a submission of sensitive data to a legitimate or intended entity.

11. The computer-implemented method of claim 1 wherein the action comprises preventing the client application from communicating the data.

12. The computer-implemented method of claim 1 wherein the action comprises warning the user that communicating the data might result in an unintentional giveaway of sensitive data to an illegitimate or unintended entity.

13. The computer-implemented method of claim 1 wherein the action comprises logging a communication of the data by the client application.

14. The computer-implemented method of claim 1 wherein the action comprises requesting that the user confirm a communication of the data.

15. The computer-implemented method of claim 1 wherein the data comprises security credentials.

16. The computer-implemented method of claim 15 wherein the security credentials comprise security credentials used to log onto an ISP's network.

17. The computer-implemented method of claim 15 wherein the security credentials comprise security credentials used to log onto a website.

18. The computer-implemented method of claim 1 wherein the data comprises a credit card number.

19. A non-transitory computer-usable medium storing a computer program for protecting against an unintentional release of sensitive data to an illegitimate or unintended entity, the computer program comprising instructions for causing at least one processor to:

monitor data being entered by a user into a client application, wherein the monitoring comprises at least one of:

determining whether an intended recipient of the data provided to the client application is globally trusted; and

determining whether the intended recipient of the data provided to the client application is personally trusted;

access a set of pattern generating functions;

generate a set of string matching patterns by applying the set of pattern generating functions to sensitive data;

determine that the data being entered into the client application matches one or more of the string matching patterns in the set of string matching patterns;

in response to determining that the data being entered into the client application matches one or more of the string matching patterns in the set of string matching patterns, perform at least one of: requesting that the user confirm a communication of the data; warning the user that communicating the data might result in an unintentional release of sensitive data to an illegitimate or unintended entity; preventing the client application from communicating the data; or logging a communication of the data by the client application.

20. A computer-implemented method of protecting against an unintentional release of sensitive data to an illegitimate or unintended entity, the method comprising:

monitoring data being entered by a user into a client application, wherein the monitoring comprises at least one of:

determining whether an intended recipient of the data provided to the client application is globally trusted; and

determining whether the intended recipient of the data provided to the client application is personally trusted;

accessing a set of pattern generating functions;

generating a set of string matching patterns by applying the set of pattern generating functions to sensitive data;

determining, with a processor, that the data being entered into the client application matches one or more of the string matching patterns in the set of string matching patterns;

in response to determining that the data being entered into the client application matches one or more of the string matching patterns in the set of string matching patterns, performing at least one of: requesting that the user confirm a communication of the data; warning the user that communicating the data might result in an unintentional giveaway of sensitive data to an illegitimate or unintended entity;

preventing the client application from communicating the data; or logging a communication of the data by the client application.

Assignments (4)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044101/0299 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2014
From: BRIGHT SUN TECHNOLOGIES
To: GOOGLE INC.
Reel/Frame 033488/0331 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2014
From: MARATHON SOLUTIONS LLC
To: BRIGHT SUN TECHNOLOGIES
Reel/Frame 031900/0494 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2012
From: AOL INC.
To: MARATHON SOLUTIONS LLC
Reel/Frame 028911/0969 →