IP Library Granted Patent US 9,609,001
Granted Patent B2
US 9,609,001 · App. 14/599,967 · Granted Mar 28, 2017

System and method for adding context to prevent data leakage over a computer network

Inventor: Daniel Lyle Hubbard (Carlsbad, CA)
Assignee: Websense, LLC
H04L63/123H04L12/585H04L51/12H04L63/0245H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,609,001
App. No.
14/599,967
Granted
Mar 28, 2017
Kind
B2
Abstract

Systems and methods for adding context to prevent data leakage over a computer network are disclosed. Data is classified and contextual information of the data is determined. A transmission policy is determined in response to the classification and contextual information. The data is either transmitted or blocked in response to the classification and the contextual information.

Claims (32)

1. A system for preventing unauthorized transmission of data over a computer network, the system comprising:

a network gateway device in communication with the computer network, the network gateway device configured to receive data in transit between a source and a destination, wherein the network gateway device comprises:

a classification module configured to determine whether the data in transit includes prohibited content,

a context information module configured to generate destination contextual information related to the destination of the received data, wherein the destination contextual information comprises a categorization of an Internet Protocol (IP) address of the destination, and wherein the categorization of the IP address of the destination is based at least in part on website content stored at the destination, and

a transmission policy module configured to determine a transmission policy based on the determination of the classification module and the destination contextual information.

2. The system of claim 1 , further comprising a database of IP addresses sorted by categories, wherein the categorization of the destination is further based on a comparison of the IP address of the destination to the database of internet protocol addresses.

3. The system of claim 1 , wherein the destination contextual information is further based on a geographic location of the destination.

4. The system of claim 1 , wherein the context information module is further configured to generate sender contextual information related to the source of the received data, and the transmission policy module is further configured to determine the transmission policy based on the sender contextual information.

5. The system of claim 4 , wherein the sender contextual information comprises a user name or a group of users.

6. The system of claim 1 , wherein the destination contextual information further comprises an IP address of the destination, a network of the destination or a category of the destination.

7. The system of claim 1 , wherein the transmission policy module is further configured to determine whether the network gateway transmits the data or blocks transmission of the data.

8. The system of claim 1 , wherein the transmission policy module is further configured to report that the source is attempting to transmit data.

9. The system of claim 1 , wherein the data source is an electronic device connected to the computer network, and one of:

a personal digital assistant (PDA);

a computer; and

a cell phone.

10. The system of claim 1 , wherein the network gateway further comprises an enforcement module configured to transmit or block the data in response to data received from the transmission policy module.

11. A method of preventing an unauthorized transmission of data over a computer network, the method comprising:

receiving, at a network gateway device connected to the computer network, data in transit between a source and a destination;

classifying, using one or more electronic processing circuits, the data to determine whether the data includes prohibited content;

generating, using the one or more electronic processing circuits, destination contextual information related to the destination of the data, wherein the destination contextual information comprises a categorization of an Internet Protocol (IP) address of the destination, wherein the categorization of the IP address of the destination is based on website content stored at the destination; and

determining, using the one or more electronic processing circuits, a transmission policy for the data in response to the classification of the data and the destination contextual information.

12. The method of claim 11 , further comprising transmitting or blocking the data based on the transmission policy.

13. The method of claim 12 , further comprising reporting that the data is to be transmitted.

14. The method of claim 11 , wherein the destination contextual information is further based on a geographic location of the destination.

15. The method of claim 11 , further comprising storing a database of IP addresses sorted by categories, wherein the categorization of the destination is further based on a comparison of the IP address of the destination to the database of IP addresses.

16. The method of claim 11 , further comprising generating sender contextual information related to the source of the data, wherein the determining of a transmission policy for the data further based on the sender contextual information.

17. The method of claim 16 , wherein the sender contextual information comprises an IP address of the sender, a user name of a sender of the data in transit or a group name of a sender of the data in transit.

18. The method of claim 11 , wherein the source of the data is an electronic device connected to the computer network, wherein the electronic device is one of:

a personal digital assistant (PDA);

a computer; and

a cell phone.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
Continuity (3)
Continuation 12022838 · Jan 30, 2008
Provisional Application 60887908 · Feb 2, 2007
Related Publication 20150143476A1 · May 21, 2015