IP Library Granted Patent US 9,230,098
Granted Patent B2
US 9,230,098 · App. 14/622,598 · Granted Jan 5, 2016

Real time lockdown

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,230,098
App. No.
14/622,598
Granted
Jan 5, 2016
Kind
B2
Abstract

A system and method that trusts software executables existent on a machine prior to activation for different types of accesses e.g. execution, network, and registry. The system detects new executables added to the machine as well as previously existent executables that have been modified, moved, renamed or deleted. In certain embodiments, the system will tag the file with a flag as modified or newly added. Once tagged, the system intercepts particular types of file accesses for execution, network or registry. The system determines if the file performing the access is flagged and may apply one or more policies based on the requested access. In certain embodiments, the system intercepts I/O operations by file systems or file system volumes and flags metadata associated with the file. For example, the NT File System and its extended attributes and alternate streams may be utilized to implement the system.

Claims (76)

1. A method of applying an access policy to a computer file, comprising:

receiving, via an electronic hardware processor, a request to modify a computer file, the computer file comprising file user data and file meta data associated with the user data;

writing a first indicator to the file meta data in response to the request;

receiving, via an electronic hardware processor, a second request to execute the computer file;

determining, via an electronic hardware processor, in response to receiving the second request, the file meta data includes the first indicator;

selecting, in response to the determining, a first policy from a plurality of policies based on the file meta data including the first indicator; and

applying, via an electronic hardware processor, the selected policy to the second request.

2. The method of claim 1 , further comprising

receiving a third request to execute a second computer file;

performing a second determining that the file meta-data of the second computer file does not include the first indicator in response to receiving the third request;

selecting, in response to the second determining, a second policy from the plurality of policies based on the file meta-data of the second computer not including the first indicator; and

applying the second policy to the request.

3. The method of claim 1 , wherein the selected policy is for restricted executables.

4. The method of claim 2 , wherein the second policy is for trusted or unrestricted files.

5. The method of claim 1 , further comprising:

hashing the file meta data; and

selecting the first policy based at least in part on the hash of the file meta data.

6. The method of claim 1 , further comprising:

performing a third determining of whether the first indicator is associated with restricted files; and

selecting the first policy based at least in part on the third determining.

7. The method of claim 6 , further comprising:

applying a policy for restricted executables in response to the first indicator being associated with restricted files; and

applying a policy for trusted or unrestricted executables in response to the first indicator not being associated with restricted files.

8. An apparatus for applying an access policy to a computer file, comprising:

an electronic processor;

a memory, operably connected to the electronic processor, and storing instructions that configure the electronic processor to:

receive a request to modify a computer file, the computer file comprising file user data and file meta data associated with the user data;

write a first indicator to the file meta data in response to the request;

receive a second request to execute the computer file;

determine, in response to receiving the second request, the file meta data includes the first indicator;

select, in response to the determining, a first policy from a plurality of policies based on the file meta data including the first indicator; and

apply the selected policy to the second request.

9. The apparatus of claim 8 , wherein the memory stores further instructions that further configure the electronic processor to:

receive a third request to execute a second computer file;

perform a second determination that the file meta-data of the second computer file does not include the first indicator in response to receiving the third request;

select, in response to the second determining, a second policy from the plurality of policies based on the file meta-data of the second computer not including the first indicator; and

apply the second policy to the request.

10. The apparatus of claim 8 , wherein the selected policy is for restricted executables.

11. The apparatus of claim 9 , wherein the second policy is for trusted or unrestricted files.

12. The apparatus of claim 8 , wherein the memory further stores instructions that configure the electronic processor to:

hash the file meta data; and

select the first policy based at least in part on the hash of the file metadata.

13. The apparatus of claim 8 , wherein the memory further stores instructions that configure the electronic processor to:

determine whether the first indicator is associated with restricted files; and

select the first policy based at least in part on whether the first indicator is associated with restricted files.

14. The apparatus of claim 8 , wherein the memory further stores instructions that configure the electronic processor to:

apply a policy for restricted executables in response to the first indicator being associated with restricted files; and

apply a policy for trusted or unrestricted executables in response to the first indicator not being associated with restricted files.

15. A non-transitory computer readable storage medium comprising instructions that when executed cause an electronic processor to apply an access policy to a computer file by:

receiving a request to modify a computer file, the computer file comprising file user data and file meta data associated with the user data;

writing a first indicator to the file meta data in response to the request;

receiving a second request to execute the computer file;

determining, in response to receiving the second request, the file meta data includes the first indicator;

selecting, in response to the determining, a first policy from a plurality of policies based on the file meta data including the first indicator; and

applying the selected policy to the second request.

16. The computer readable storage medium of claim 15 , further comprising instructions that when executed cause the electronic processor to apply the access policy to a computer file by

receiving a third request to execute a second computer file;

performing a second determination that the file meta-data of the second computer file does not include the first indicator in response to receiving the third request;

selecting, in response to the second determining, a second policy from the plurality of policies based on the file meta-data of the second computer not including the first indicator; and

applying the second policy to the request.

17. The computer readable storage medium of claim 15 , further comprising instructions that when executed cause the electronic processor to apply the access policy to a computer file by:

hashing the file meta data; and

selecting the first policy based at least in part on the hash of the file metadata.

18. The computer readable storage medium of claim 15 , further comprising instructions that when executed cause the electronic processor to apply the access policy to a computer file by:

determining whether the first indicator is associated with a restricted file; and

selecting the first policy based at least in part on whether the first indicator is associated with a restricted file.

19. The computer readable storage medium of claim 18 , further comprising instructions that when executed cause the electronic processor to apply the access policy to a computer file by:

applying a policy for restricted executables in response to the first indicator being associated with restricted files; and

applying a policy for trusted or unrestricted executables in response to the first indicator not being associated with restricted files.

20. An apparatus for applying an access policy to a computer file comprising:

means for receiving a request to modify a computer file, the computer file comprising file user data and file meta data associated with the user data;

means for writing a first indicator to the file meta data in response to the request;

means for receiving a second request to execute the computer file;

means for determining, in response to receiving the second request, the file meta data includes the first indicator;

means for selecting, in response to the determining that the file metadata includes the first indicator, a first policy from a plurality of policies based on the file meta data including the first indicator; and

means for applying the selected policy to the second request.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2015
From: SHARMA, RAJESH KUMAR; LO, WINPING; PAPA, JOSEPH
To: WEBSENSE, INC.
Reel/Frame 035811/0302 →