IP Library Granted Patent US 8,645,340
Granted Patent B2
US 8,645,340 · App. 13/437,885 · Granted Feb 4, 2014

System and method of monitoring and controlling application files

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,645,340
App. No.
13/437,885
Granted
Feb 4, 2014
Kind
B2
Abstract

A system and method for updating, monitoring, and controlling applications on a workstation. The workstation includes a workstation management module configured to detect the launch or request to access a network by an application. A workstation application server receives data associated with the application from the workstation. The application server module can determine one or more policies or categories to associate with the application by referencing an application inventory database. Once the application server module has the category or policy, it forwards a hash/policy table to the workstation management module. Upon receipt of the hash/policy table, the workstation management module applies the policy that is associated with the application to control network access by the application.

Claims (30)

1. A system, including one or more processors, for collecting network access data for use in updating a monitoring system which controls programs accessing a network, comprising:

a workstation management module configured to detect a program on a workstation accessing a network, determine whether the program is in a network access database, send program data associated with the program to an application server module if the program is not in the network access database, and apply one or more policies that are associated with the program, wherein the network access database includes a protocol that is associated with the program;

the application server module being configured to receive the program data from the workstation management module if the program was not in the network access database, determine whether the program is operating in a predetermined manner, wherein said predetermined manner means the program is operating in a manner determined by past network activity involving the same or relevant programs, if the program is not operating in a predetermined manner, then send the program data to an application database factory, if the program is operating in a predetermined manner, then provide the one or more policies associated with the program to the workstation management module, wherein the application server module is further configured to analyze the program data for a data characteristic that is indicative of whether the program is operating in the predetermined manner, and to associate one or more indicators with the program; and

wherein analyzing the program data is performed on text strings that are associated with the program;

a classification user interface configured to provide an interface for a network administrator to select the one or more policies that are associated with the program; and

an upload/download manager module configured to send the program data to the application database factory and to receive the one or more policies from the application database factory.

2. The system of claim 1 wherein the application database factory is configured to receive the program data from the application server module if the program is not operating in a predetermined manner, determine whether the program was previously analyzed by the application database factory, if the program was not previously analyzed, then determine one or more policies to associate with the program and provide the one or more policies to the application server module, if the program was previously analyzed, then provide the one or more policies that were previously associated with the program data to the application server module.

3. The system of claim 1 , wherein the protocol is a transport protocol.

4. The system of claim 3 , wherein the transport protocol is transmission control protocol (TCP).

5. The system of claim 3 , wherein the transport protocol is user database protocol (UDP).

6. The system of claim 1 , wherein the network access database comprises hash values.

7. The system of claim 1 , wherein the network access database comprises one or more categories and one or more policies associated with the program.

8. The system of claim 1 , wherein the workstation management module comprises an application digest generator configured to determine the program data to associate with the program.

9. The system of claim 1 , wherein the program data includes a source IP address.

10. The system of claim 1 , wherein the program data includes a destination IP address.

11. The system of claim 1 , wherein the one or more policies include allowing the program to access the network based on the one or more policies associated with the program and the user.

12. The system of claim 1 , wherein the one or more policies include not allowing the program to access the network based on the one or more policies associated with the program and the user.

13. A system, including one or more processors, for collecting network access data for use in updating a monitoring system which controls a program on a computer from accessing a network based at least in part on information collected from another computer over the network, the system comprising:

a first workstation management module configured to detect a program on a first workstation accessing a network, determine whether the program is in a first network access database, send program data associated with the program to an application server module if the program is not in the first network access database, and apply one or more policies that are associated with the program;

the application server module being configured to receive the program data from the first workstation management module if the program was not in the first network access database, determine whether the program is operating in a predetermined manner, wherein said predetermined manner means the program is operating in a manner determined by past network activity involving the same or relevant programs, if the program is not operating in a predetermined manner, then send the program data to an application database factory, if the program is operating in a predetermined manner, then provide the one or more policies associated with the program to at least a second workstation; wherein the application server module is further configured to analyze the program data for a data characteristic that is indicative of whether the program is operating in the predetermined manner, and to associate one or more indicators with the program; and

wherein analyzing the program data is performed on text strings that are associated with the program; and

a second workstation management module being configured to receive the one or more policies from the application server module and update a second network access database resident on the second workstation.

14. The system of claim 13 , wherein the one or more indicators includes a category flag.

15. The system of claim 13 , wherein the application server module uses the one or more indicators to screen the program prior to sending the program data to the application database factory.

16. A system, including one or more processors, for collecting network access data for use in updating a monitoring system which controls programs accessing a network, comprising:

a workstation management module configured to detect a program on a workstation accessing a network, determine whether the program is in a network access database, send program data associated with the program to an application server module if the program is not in the network access database, and apply one or more policies that are associated with the program, wherein the network access database includes a protocol that is associated with the program;

the application server module being configured to receive the program data from the workstation management module if the program was not in the network access database, analyze the program data for a data characteristic that is indicative of whether the program is operating in a predetermined manner and to associate one or more indicators with the program, wherein said predetermined manner means the program is operating in a manner determined by past network activity involving the same or relevant programs, if the program is not operating in a predetermined manner, then send the program data and the data characteristic to an application database factory, if the program is operating in a predetermined manner, then provide the one or more policies associated with the program to the workstation management module; and

wherein the application server module is further configured to analyze the program data for a data characteristic that is indicative of whether the program is operating in the predetermined manner, and to associate one or more indicators with the program; and

wherein analyzing the program data is performed on text strings that are associated with the program.

17. The system of claim 16 , wherein the one or more indicators includes a category flag.

Assignments (19)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2015
From: KESTER, HAROLD M.; DIMM, JOHN ROSS; ANDERSON, MARK RICHARD; PAPA, JOSEPH
To: WEBSENSE, INC.
Reel/Frame 037253/0844 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME 032677/0038 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035796/0881 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME; 032677/0071 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0734 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
SECURITY INTEREST Recorded Apr 15, 2014
From: PORTAUTHORITY TECHNOLOGIES, INC., AS PLEDGOR; WEBSENSE, INC., AS PLEDGOR
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 032677/0038 →
SECURITY INTEREST Recorded Apr 15, 2014
From: PORT AUTHORITY TECHNOLOGIES, INC., AS PLEDGOR; WEBSENSE, INC., AS PLEDGOR
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 032677/0071 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →