IP Library Granted Patent US 9,652,464
Granted Patent B2
US 9,652,464 · App. 14/609,074 · Granted May 16, 2017

Systems and methods for continuous active data security

Inventor: Stuart Ogawa (Los Gatos, CA)
Assignee: Nasdaq, Inc.
G06F17/30091G06F21/554H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,652,464
App. No.
14/609,074
Granted
May 16, 2017
Kind
B2
Abstract

Systems and methods are provided for active continuous data security. An active receiver module, an active marker module, an active transmitter module and an active profiler module work together to monitor data requests, detect suspicious activity and characteristics, and responds to hinder the suspicious activity. A method includes: obtaining a request for data; obtaining a characteristic associated with the request for data; comparing the characteristic with a database of known patterns and characteristics to determine if the request is suspicious; storing the request and the characteristic in the database for future comparison; and initiating a response to hinder the request for the data when the request is determined to be suspicious. Markers embedded in data are used to track the data, including data that is exposed to a security risk. Pattern detection is used to uncover suspicious activity and the systems are able self-learn as more data is provided.

Claims (34)

1. A method performed by one or more computing devices for providing data security, comprising:

obtaining a request for data;

obtaining a characteristic associated with the request for data, the characteristic including a set of actions initiated by a computing device attempting to access the data;

comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the computing device uses a same IP address to log into at least a predetermined number of multiple different accounts;

comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when root numbers of the IP address match other root numbers of a known suspicious IP address;

storing the request and the characteristic in the database for future comparison; and

initiating a response to hinder the request for the data when the request is determined to be suspicious.

2. The method of claim 1 , further comprising comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the IP address matches a known suspicious IP address.

3. The method of claim 1 , the method further comprising comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when a predetermined number of accesses or attempts to access the predetermined number of data files or objects occurs in a sequential manner.

4. The method of claim 1 , the method further comprising comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when download of a predetermined number of multiple data files or objects occurs.

5. The method of claim 1 , the method further comprising comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when a predetermined number of search terms are submitted within less than a predetermined period of time.

6. The method of claim 1 , the method further comprising comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the computing device submits a search term that includes more than at least one of the predetermined number of characters and a predetermined number of keywords.

7. The method of claim 1 , further comprising comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the computing device makes more than a predetermined number of searches related to a same topic.

8. The method of claim 1 , wherein the set of actions further includes the computing device submitting other data into a form, and the method further comprises comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when a format of the other data does not match an expected format associated with the form.

9. The method of claim 1 , further comprising inserting a marker into the data, the marker configured to at least destroy the data.

10. The method of claim 9 , further comprising, when the data has been sent from the server to another computing device, detecting if a signal from the marker has been received, and if not, initiating the response.

11. The method of claim 1 , wherein the response includes terminating a communication channel between a server storing the data and a computing device requesting access to the data.

12. The method of claim 1 , wherein the response includes deleting the data from a server that originally stored the data, and storing a copy of the data in a secondary server.

13. The method of claim 1 , wherein the response includes powering off a server storing the data.

14. A server system configured to provide data security, comprising:

a processor;

a communication device;

a memory device including computer-executable instructions for at least:

obtaining a request for data;

obtaining a characteristic associated with the request for data, the characteristic including a set of actions initiated by a computing device attempting to access the data;

comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the computing device uses a same IP address to log into at least a predetermined number of multiple different accounts;

comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when root numbers of the IP address match other root numbers of a known suspicious IP address;

storing the request and the characteristic in the database for future comparison; and

initiating a response to hinder the request for the data when the request is determined to be suspicious.

15. The server system of claim 14 , wherein the memory device includes computer-executable instructions comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the accesses or attempts to access at least the predetermined number of data files or objects occurs in a sequential manner.

16. The server system of claim 14 , wherein the memory device includes computer-executable instructions for comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the at least a predetermined number of data files or objects is downloaded.

17. The server system of claim 14 , wherein the memory device includes computer-executable instructions for comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when a predetermined number of search terms are submitted within less than a predetermined period of time.

18. The server system of claim 14 , wherein the memory device includes computer-executable instructions for comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the computing device submits the search term that includes more than at least one of a predetermined number of characters and a predetermined number of keywords.

19. The server system of claim 14 , wherein the memory device includes computer-executable instructions for comparing the characteristic with a database of known patterns and characteristics to determine that the request is suspicious when the computing device makes more than a predetermined number of searches related to a same topic.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2017
From: NASDAQ CORPORATE SOLUTIONS CANADA ULC
To: NASDAQ, INC.
Reel/Frame 041874/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2016
From: MARKETWIRED L.P.
To: NASDAQ CORPORATE SOLUTIONS CANADA ULC
Reel/Frame 039213/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2015
From: OGAWA, STUART
To: MARKETWIRE L.P.
Reel/Frame 034847/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2015
From: MARKETWIRED HOLDING L.P.
To: MARKETWIRED L.P.
Reel/Frame 034847/0395 →
CHANGE OF NAME Recorded Jan 29, 2015
From: MARKETWIRE L.P.
To: MARKETWIRED HOLDING L.P.
Reel/Frame 034859/0318 →
Continuity (2)
Provisional Application 61933434 · Jan 30, 2014
Related Publication 20150215325A1 · Jul 30, 2015