IP Library Granted Patent US 9,455,981
Granted Patent B2
US 9,455,981 · App. 14/846,538 · Granted Sep 27, 2016

Method and system for protection against information stealing software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,455,981
App. No.
14/846,538
Granted
Sep 27, 2016
Kind
B2
Abstract

A system and method for identifying infection of unwanted software on an electronic device is disclosed. A software agent configured to generate a bait and is installed on the electronic device. The bait can simulate a situation in which the user performs a login session and submits personal information or it may just contain artificial sensitive information. The output of the electronic device is monitored and analyzed for attempts of transmitting the bait. The output is analyzed by correlating the output with the bait and can be done by comparing information about the bait with the traffic over a computer network in order to decide about the existence and the location of unwanted software.

Claims (35)

1. A system for controlling dissemination of sensitive information from an electronic network to an electronic device on the Internet, the system comprising:

an electronic hardware processor configured to execute computer instructions, wherein the computer instructions implement a traffic analyzer, the traffic analyzer in communication with the electronic network and configured to:

detect an electronic message on the electronic network, the electronic message including a password to be transmitted to the electronic device on the Internet,

determine a strength of the password based on one or more of a length of the password and an entropy score of the password,

determine a sensitivity of information protected by the password based on the strength, wherein the sensitivity is positively correlated with the strength of the password such that a stronger password results in a determination of higher sensitivity and a weaker password results in a determination of lower sensitivity,

determine a category of content at the electronic device by classifying website content at the electronic device,

determine a risk level based at least in part on the category and the sensitivity of the information protected by the password,

determine a required action in response to the risk level, wherein the required action includes one or more of blocking, quarantining, or alerting, and

block the electronic message destined for the electronic device and including the password in response to the required action including blocking.

2. The system of claim 1 , wherein the traffic analyzer is further configured to quarantine the electronic message including the password in response to the determined required action including quarantining.

3. The system of claim 1 , wherein the traffic analyzer is further configured to generate an alert in response to the required action including alerting.

4. The system of claim 1 , wherein, for any particular category of the content, the traffic analyzer is configured to determine the risk level is higher with a higher sensitivity of information than with a lower sensitivity of information.

5. The system of claim 1 , wherein the traffic analyzer is further configured to determine the risk level based on analysis of a recipient URL identifying content at the electronic device.

6. The system of claim 1 , wherein the traffic analyzer is further configured to determine longer passwords are stronger than shorter passwords.

7. The system of claim 1 , wherein the traffic analyzer is further configured to determine passwords less similar to other passwords are stronger than passwords that are more similar to the other passwords.

8. The system of claim 1 , wherein the traffic analyzer is further configured to determine higher entropy passwords are stronger than lower entropy passwords.

9. The system of claim 1 , wherein the traffic analyzer is further configured to determine a higher level of risk with a stronger password than with a weaker password.

10. The system of claim 1 , wherein the traffic analyzer is further configured to determine the required action based, at least in part, on parameters settable by an operator.

11. A computer-implemented method of controlling dissemination of sensitive information from an electronic network to an electronic device on the Internet, the method comprising

analyzing, via an electronic hardware processor, traffic on the electronic network to detect an electronic message including a password to be transmitted to the electronic device on the Internet;

determining, via the electronic hardware processor a strength of the password based on one or more of a length of the password, and an entropy score of the password;

determining, via the electronic hardware processor, a sensitivity of information protected by the password based on the strength of the password, wherein the determined sensitivity is positively correlated with the strength of the password such that a stronger password results in a determination of higher sensitivity and a weaker password results in a determination of lower sensitivity;

determining, via the electronic hardware processor a category of content at the electronic device by classifying website content at the electronic device,

determining, via the electronic hardware processor, a risk level incurred if the password leaves the electronic network and is passed to the electronic device based at least in part on the category and the sensitivity of information protected by the password;

determining, via the electronic hardware processor, a required action based on the determined risk level, wherein the required action includes one or more of blocking, quarantining, or alerting; and

blocking, via the electronic hardware processor, the electronic message destined for the electronic device and including the password in response to the determined required action including blocking.

12. The method of claim 11 , further comprising quarantining the electronic message in response to the determined required action including quarantining.

13. The method of claim 11 , further comprising generating an alert in response to the required action including alerting.

14. The method of claim 11 , wherein, for any particular category of the content, the determined risk level is higher with a higher sensitivity of information than with a lower sensitivity of information.

15. The method of claim 11 , wherein the risk level is further determined based on analysis of a recipient URL identifying content at the electronic device.

16. The method of claim 11 , further comprising determining longer passwords are stronger than shorter passwords.

17. The method of claim 11 , further comprising determining passwords less similar to other passwords are stronger than passwords that are more similar to the other passwords.

18. The method of claim 11 , further comprising determining higher entropy passwords are stronger than lower entropy passwords.

19. The method of claim 11 , further comprising determining a higher level of risk with a stronger password than with a weaker password.

20. The method of claim 11 , wherein the required action is based, at least in part, on parameters settable by an operator.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2016
From: TROYANSKY, LIDROR
To: WEBSENSE, INC.
Reel/Frame 038004/0770 →