IP Library Granted Patent US 9,692,762
Granted Patent B2
US 9,692,762 · App. 14/845,816 · Granted Jun 27, 2017

Systems and methods for efficient detection of fingerprinted data and information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,692,762
App. No.
14/845,816
Granted
Jun 27, 2017
Kind
B2
Abstract

The disclosed embodiments provide systems, methods, and apparatus for efficient detection of fingerprinted content and relate generally to the field of information (or data) leak prevention. Particularly, a compact and efficient repository of fingerprint ingredients is used to analyze content and determine the content's similarity to previously fingerprinted content. Some embodiments employ probabilistic indications regarding the existence of fingerprint ingredients in the repository.

Claims (45)

1. A system for managing transmission of a plurality of electronic documents over a network, the system comprising:

a compact fingerprint repository storing a repository of compact fingerprints, the compact fingerprints based on hashes of electronic documents to which a transmission policy corresponding to the compact fingerprint is applied, the hashes of each of the compact fingerprints including a subset of a full set of hashes, the subset including only hashes that are evenly divisible by one or more specified numbers, the subset including fewer hashes than the full set of hashes;

one or more hardware electronic processors configured to:

determine probabilistic matches between fingerprints of an electronic document identified on the network and the compact fingerprints stored in the compact fingerprint repository, and

determine whether to transmit the identified electronic document over the electronic network based, at least in part, on a number of matching fingerprints.

2. The system of claim 1 , wherein the one or more hardware electronic processors are further configured to:

identify a compact fingerprint matching the fingerprints of the electronic document,

identify a policy associated with the identified compact fingerprint, and

determine whether to transmit the identified electronic document based on the identified policy.

3. The system of claim 1 , wherein the one or more hardware electronic processors are configured to determine a probabilistic match based on distances between portions of content of the electronic document corresponding to hashes matching a compact fingerprint in the repository.

4. The system of claim 3 , wherein the one or more hardware electronic processors are configured to determine no match exists between a compact fingerprint and the electronic document in response to the compact fingerprint failing to represent a fingerprint of the electronic document.

5. The system of claim 1 , wherein the one or more hardware electronic processors are configured to determine a first hash of the electronic document using a first hash function and determine a second hash of the electronic document using a second hash function.

6. The system of claim 5 , wherein the one or more hardware electronic processors are configured to determine whether the first and second hashes are represented by a compact fingerprint in the repository, and determine the compact fingerprint does not match the electronic document if either of the hashes is not represented by the compact fingerprint.

7. A method of transmitting electronic content over a network, the method comprising:

identifying electronic content on the network;

generating hashes of the electronic content identified on the network;

selecting a subset of the generated hashes, the selected including only hashes that are evenly divisible by one or more specified numbers, the subset including fewer hashes than the generated hashes; and

determining whether to transmit the electronic content identified on the network over the network, based at least in part on a transmission policy corresponding to a compact fingerprint stored in a compact fingerprint repository matching the selected hashes.

8. The method of claim 7 , wherein each compact fingerprint in the compact fingerprint repository is based on hashes of electronic documents to which the corresponding transmission policy is applied.

9. The method of claim 7 , further comprising:

identifying a compact fingerprint matching the fingerprints of the electronic document,

identifying a policy corresponding to the identified compact fingerprint; and

determining whether to transmit the identified electronic document based on the identified policy.

10. The method of claim 7 , further comprising determining a probabilistic match based on distances between portions of content of the electronic document corresponding to hashes matching a compact fingerprint in the repository.

11. The method of claim 9 , further comprising determining no match exists between a compact fingerprint and the electronic document in response to the compact fingerprint failing to represent a fingerprint of the electronic document.

12. The method of claim 7 , further comprising determining a first hash of the electronic document using a first hash function and determining a second hash of the electronic document using a second hash function.

13. The method of claim 12 , further comprising:

determining whether the first and second hashes are represented by a compact fingerprint in the repository; and

determining the compact fingerprint does not match the electronic document in response to either of the hashes not being represented by the compact fingerprint.

14. A non-transitory computer-readable medium comprising instructions that when executed cause one or more processors to perform a method of transmitting electronic content over a network, the method comprising:

identifying electronic content on the network;

generating hashes of the electronic content identified on the network;

selecting a subset of the generated hashes, the selected including only hashes that are evenly divisible by one or more specified numbers, the subset including fewer hashes than the generated hashes; and

determining whether to transmit the electronic content identified on the network over the network, based at least in part on a transmission policy corresponding to a compact fingerprint stored in a compact fingerprint repository matching the selected hashes.

15. The non-transitory computer-readable medium of claim 14 , wherein each compact fingerprint in the compact fingerprint repository is based on hashes of electronic documents to which the corresponding transmission policy is applied.

16. The non-transitory computer-readable medium of claim 14 , the method further comprising:

identifying a compact fingerprint matching the fingerprints of the electronic document;

identifying a policy corresponding to the compact fingerprint; and

determining whether to transmit the identified electronic document based on the identified policy.

17. The non-transitory computer-readable medium of claim 14 , the method further comprising determining a probabilistic match based on distances between portions of content of the electronic document corresponding to hashes matching a compact fingerprint in the repository.

18. The non-transitory computer-readable medium of claim 17 , the method further comprising determining no match exists between a compact fingerprint and the electronic document in response to the compact fingerprint failing to represent a fingerprint of the electronic document.

19. The non-transitory computer-readable medium of claim 14 , the method further comprising determining a first hash of the electronic document using a first hash function and determining a second hash of the electronic document using a second hash function.

20. The transitory computer-readable medium of claim 19 , the method further comprising:

determining whether the first and second hashes are represented by a compact fingerprint in the repository; and

determining the compact fingerprint does not match the electronic document in response to either of the hashes not being represented by the compact fingerprint.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →