IP Library Granted Patent US 8,959,634
Granted Patent B2
US 8,959,634 · App. 13/849,377 · Granted Feb 17, 2015

Method and system for protection against information stealing software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,959,634
App. No.
13/849,377
Granted
Feb 17, 2015
Kind
B2
Abstract

Methods and systems reduce exposure to a dictionary attack while verifying whether data transmitted over a computer network is a password. In one aspect, a method includes performing a search of network traffic based, at least in part, on a weak validation using a Bloom filter based on an organizational password file, determining the existence of a password in the network traffic based only on the weak validation, and determining whether to block, alert, or quarantine the network traffic based at least in part on the existence of the password in the network traffic.

Claims (22)

1. A computer-implemented method for reducing exposure to a dictionary attack while verifying whether data transmitted over a computer network is any organizational password of a plurality of organizational passwords, wherein each organizational password may be used to accessing an account or other sensitive resources inside the organization, the method comprising:

performing, using an electronic processor, a search of outgoing network traffic from at least one computerized device within an organizational perimeter to a site outside the organizational perimeter based, at least in part, on a weak validation, the weak validation produced using a Bloom filter, wherein the Bloom filter generates a probabilistic indication of an existence of an organizational password in the searched outgoing network traffic;

determining, using an electronic processor, the existence based only on the weak validation; and

determining, using an electronic processor, whether to block, alert, or quarantine the network traffic based at least in part on the existence; and

enforcing, using an electronic processor, the determination of whether to block, alert, or quarantine the searched outgoing network traffic.

2. The method of claim 1 , further comprising encoding an organization password file storing the plurality of organizational passwords with the Bloom filter.

3. The method of claim 1 , wherein a traffic analyzer in communication with the computer network is configured to block the searched data from being transmitted over the network if the probabilistic indication is greater than zero.

4. The method of claim 1 , wherein a percent of false positives provided by the Bloom Filter is tunable.

5. A system for reducing exposure to a dictionary attack while verifying whether data transmitted over a computer network is any organizational password of a plurality of organizational passwords, wherein each organizational password may be used to access an account or other sensitive resources inside the organization, the system comprising:

an electronic processor configured to execute computer instructions, wherein the computer instructions include a traffic analyzer in communication with the computer network, the traffic analyzer being configured to perform a search of outgoing network traffic from at least one computerized device within an organizational perimeter to a site outside the organizational perimeter based at least in part on a weak validation indicating whether the outgoing network traffic includes an organizational password, the weak validation produced using a Bloom filter, wherein the Bloom filter generates a probabilistic indication of an existence of an organizational password in the searched outgoing network traffic, and determining the existence based only on the weak validation; and

a decision system configured to decide whether to do at least one of block, alert or quarantine the searched outgoing network traffic based at least in part on the existence; and

enforcing the determination of whether to block, alert, or quarantine the searched outgoing network traffic.

6. The system of claim 5 , further comprising a gateway configured to receive instructions from the decision system.

7. The system of claim 6 , wherein the traffic analyzer is installed on the gateway.

8. The system of claim 5 , wherein a percent of false positives provided by the Bloom Filter is tunable.

9. A system for reducing exposure to a dictionary attack while verifying whether data transmitted over a computer network is any organizational password of a plurality of organizational passwords, wherein each organizational password may be used to access an account or other sensitive resources inside the organization, the system comprising:

an electronic processor configured to execute computer instructions, wherein the computer instructions include data traffic analyzer means in communication with the computer network,

the data traffic analyzer means configured to perform a search of outgoing network traffic from at least one computerized device within an organizational perimeter to a site outside the organizational perimeter based, at least in part, on a weak validation indicating whether the outgoing network traffic includes an organizational password, the weak validation produced using a Bloom filter, wherein the Bloom filter generates a probabilistic indication of an existence of an organization password in the searched outgoing network traffic, and configured to determine the existence based only on the weak validation;

decision means for deciding whether to do at least one of block, alert or quarantine the searched outgoing network traffic based at least in part on the existence; and

means for enforcing the determination of whether to block, alert, or quarantine the searched outgoing network traffic.

10. The system of claim 9 , wherein the data traffic analyzer means blocks the data from being transmitted over the network if the probabilistic indication is greater than zero.

11. The system of claim 9 , wherein a percent of false positives provided by the Bloom Filter is tunable.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 30704/0374 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0689 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME: 030694/0615 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035858/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2014
From: TROYANSKY, LIDROR
To: WEBSENSE, INC.
Reel/Frame 033490/0474 →
ASSIGNMENT OF SECURITY INTEREST Recorded Apr 10, 2014
From: JPMORGAN CHASE BANK, N.A., AS EXISTING COLLATERAL AGENT
To: ROYAL BANK OF CANADA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 032716/0916 →
SECOND LIEN SECURITY AGREEMENT Recorded Jun 27, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 030704/0374 →
FIRST LIEN SECURITY AGREEMENT Recorded Jun 26, 2013
From: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 030694/0615 →