IP Library Granted Patent US 8,959,642
Granted Patent B2
US 8,959,642 · App. 13/900,954 · Granted Feb 17, 2015

Real time lockdown

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,959,642
App. No.
13/900,954
Granted
Feb 17, 2015
Kind
B2
Abstract

A system and method that trusts software executables existent on a machine prior to activation for different types of accesses e.g. execution, network, and registry. The system detects new executables added to the machine as well as previously existent executables that have been modified, moved, renamed or deleted. In certain embodiments, the system will tag the file with a flag as modified or newly added. Once tagged, the system intercepts particular types of file accesses for execution, network or registry. The system determines if the file performing the access is flagged and may apply one or more policies based on the requested access. In certain embodiments, the system intercepts I/O operations by file systems or file system volumes and flags metadata associated with the file. For example, the NT File System and its extended attributes and alternate streams may be utilized to implement the system.

Claims (36)

1. A method of managing access to a computer file stored by a computer file system, the computer file comprising file data and file meta data, the method comprising:

generating, via an electronic processor, a hash based at least in part on the file meta data;

writing the hash to the file meta data;

writing a first indicator to the file meta data in response to detecting an attempt to modify the computer file; and

applying, via an electronic processor, an access policy to the computer file based at least partially on the hash in the file meta data.

2. The method of claim 1 , wherein the hash is not based on the file data.

3. The method of claim 1 , wherein the computer file system is a Windows NT file system (NTFS), and the file meta data comprises extended attributes and alternate streams.

4. The method of claim 1 , further comprising writing a second indicator to the file meta data in response to an attempt to create the computer file.

5. An apparatus for managing access to a computer file stored by a computer file system, the computer file comprising file data and file meta data, the apparatus comprising:

An electronic processor;

a memory, operably connected to the electronic processor, the memory configured to store instructions that configure the processor to:

generate a hash based at least in part on the file meta data,

write the hash to the file meta data,

write a first indicator to the file meta data in response to detecting an attempt to modify the computer file, and

apply an access policy to the computer file based at least partially on the hash in the file meta data.

6. The apparatus of claim 5 , wherein the memory further stores instructions that configure the electronic processor to write a second indicator to the file meta data in response to a creation of the computer file.

7. The apparatus of claim 5 , wherein the hash is not based on the file data.

8. The method of claim 5 , wherein the computer file system is a Windows NT file system (NTFS), and the file meta data comprises extended attributes and alternate streams.

9. An apparatus for managing access to a computer file stored by a computer file system, the computer file comprising file data and file meta data, the apparatus comprising:

an electronic processor;

a memory, operably connected to the electronic processor;

means for generating a hash based at least in part on the file meta data;

means for writing the hash to the file meta data;

means for writing a first indicator to the file meta data in response to an attempt to modify the computer file; and

means for applying an access policy to the computer file based at least partially on the hash in the file meta data.

10. The apparatus of claim 9 , further comprising means for writing a second indicator to the file meta data in response to a creation of the computer file.

11. The apparatus of claim 9 , wherein the means for writing a first indicator to the file meta data is a file system filter driver executing on the electronic processor.

12. The apparatus of claim 9 , wherein the means for storing the file meta data in the memory is a file system filter driver executing on the electronic processor.

13. The apparatus of claim 9 , wherein the means for applying an access policy to the file based at least partially on the first indicator is a file system filter driver executing on the electronic processor.

14. A non-transitory computer-readable storage medium comprising instructions that when executed cause an electronic processor to perform a method of managing access to a computer file stored by a computer file system, the computer file comprising file data and file meta data, the method comprising:

generating a hash based at least in part on the file meta data;

writing the hash to the file meta data;

writing a first indicator to the file meta data in response to detecting an attempt to modify the computer file; and

applying an access policy to the computer file based at least partially on the hash in the file meta data.

15. The computer-readable storage medium of claim 14 , wherein the hash is not based on the file data.

16. The computer-readable storage medium of claim 14 , the method further comprising writing a second indicator to the file meta data in response to detecting an attempt to create the computer file.

Assignments (15)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2015
From: SHARMA, RAJESH KUMAR; LO, WINPING; PAPA, JOSEPH
To: WEBSENSE, INC.
Reel/Frame 035810/0343 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME 032677/0038 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035796/0881 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME; 032677/0071 Recorded May 29, 2015
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: WEBSENSE, INC.; PORT AUTHORITY TECHNOLOGIES, INC.
Reel/Frame 035801/0734 →
SECURITY INTEREST Recorded Apr 15, 2014
From: PORTAUTHORITY TECHNOLOGIES, INC., AS PLEDGOR; WEBSENSE, INC., AS PLEDGOR
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 032677/0038 →
SECURITY INTEREST Recorded Apr 15, 2014
From: PORT AUTHORITY TECHNOLOGIES, INC., AS PLEDGOR; WEBSENSE, INC., AS PLEDGOR
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 032677/0071 →