IP Library Granted Patent US 9,811,674
Granted Patent B2
US 9,811,674 · App. 14/858,349 · Granted Nov 7, 2017

Data leakage prevention system, method, and computer program product for preventing a predefined type of operation on predetermined data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,811,674
App. No.
14/858,349
Granted
Nov 7, 2017
Kind
B2
Abstract

A data leakage prevention system, method, and computer program product are provided for preventing a predefined type of operation on predetermined data. In use, an attempt to perform an operation on predetermined data that is protected using a data leakage prevention system is identified. Additionally, it is determined whether a type of the operation attempted includes a predefined type of operation. Furthermore, the operation on the predetermined data is conditionally prevented based on the determination to prevent circumvention of the protection of the data leakage prevention system.

Claims (41)

1. A system comprising:

a processor; and

a computer memory on which are store instructions, comprising instructions that when executed cause the processor to:

identify a first data and a signature of the first data;

monitor requests to perform an operation on the first data made through an application programming interface;

detect, responsive to the monitoring, a first operation to be performed upon first data by the application programming interface, before the first operation is performed; and

prevent leakage of the first data by causing the application programming interface to drop the request to perform the first operation on the first data,

wherein the first operation includes transforming the first data, wherein a data signature of the first data is no longer accurate of the first data.

2. The system of claim 1 wherein a type of the first operation includes an encryption type operation, an encoding type operation, or a compression type operation.

3. The system of claim 1 wherein the first data is confidential to a person or entity.

4. The system of claim 1 wherein the first data is predetermined by a person or entity.

5. The system of claim 1 wherein the first operation has been predetermined to create a security risk to the first data.

6. A non-transitory computer-readable medium on which are stored instructions, comprising instructions that when executed on a processor configure the processor to:

identify a first data and a signature of the first data;

monitor requests to perform operations on the first data made through an application programming interface;

detect, responsive to the monitoring, a first operation requested to be performed upon the first data by the application programming interface, before the first operation is performed; and

prevent leakage of the first data by causing the application programming interface to drop the request to perform the first operation on the first data depending upon a type of the first operation, wherein the first operation includes (1) modifying the data signature of the first data or (2) transforming a format of the first data.

7. The non-transitory computer-readable medium of claim 6 wherein the first data is predetermined by a person or entity.

8. The non-transitory computer-readable medium of claim 6 wherein the first data is confidential to a person or entity.

9. The non-transitory computer-readable medium of claim 8 wherein the first operation has been predetermined to create a security risk to the first data.

10. The non-transitory computer-readable medium of claim 6 further comprising instructions that when executed configure the processor to monitor all operations to be performed on the first data.

11. A non-transitory machine readable storage medium having instructions stored thereon, comprising instructions that when executed on a machine cause the machine to:

identify a first data is a type of data that has been predetermined for data leakage protection;

identify a data signature representative of the first data;

monitor requests to perform operations on the first data made through an application programming interface;

detect, responsive to the monitoring, a first operation requested to be performed upon the first data by the application programming interface, before allowing the first operation;

determine whether the first operation is a type of operation that modifies the data signature of the first data or transforms a format of the first data; and

conditionally prevent leakage of the first data by causing the application programming interface to drop the request to perform the first operation on the first data.

12. The machine readable storage medium of claim 11 wherein the first data is of a data type predetermined for application of data leakage protection because the first data is confidential to a person or entity.

13. The machine readable storage medium of claim 11 wherein the first data is of a data type predetermined for application of data leakage protection due to a policy of a person or entity.

14. The machine readable storage medium of claim 11 wherein the instructions that when executed cause the machine to determine whether the first operation is a type of operation that modifies the data signature of the first data or transforms a format of the first data comprise instructions that when executed cause the machine to compare the type of the first operation to a first group of operation types wherein each operation type in the first group of operation types has been previously associated with a risk of data leakage.

15. The machine readable storage medium of claim 14 wherein the first group of operation types includes at least one of a delete type operation, an archiving type operation, an encryption type operation, or a transforming type operation.

16. The machine readable storage medium of claim 11 wherein the instructions that when executed cause the machine to determine whether the first operation is a type of operation that modifies the data signature of the first data or transforms a format of the first data comprise instructions that when executed cause the machine to compare the type of the first operation to a second group of operation types wherein each operation type in the second group of operation types has not previously been associated with a risk of data leakage.

17. The machine readable storage medium of claim 16 wherein the second group of operation types includes at least one type of operation previously determined to be associated with non-malicious software.

18. A method, comprising:

identifying a first set of data and a signature of the first set of data;

monitoring requests to perform operations on the first data made through an application programming interface;

detecting, responsive to the monitoring, by a computing device, an attempt to perform an operation by the application programming interface on the first set of data, the detection occurring prior to the performance of the operation; and

preventing the attempted operation from occurring by causing the application programming interface to drop the request to perform the attempted operation responsive to a determination that the attempted operation includes (1) modifying the data signature of the first set of data or (2) transforming a format of the first set of data.

19. The method of claim 18 wherein the attempted operation comprises an encryption operation, and encoding operation, and a compression operation.

20. The method of claim 18 wherein the attempted operation has been predetermined to create a security risk to the first set of data.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →