IP Library Granted Patent US 10,454,948
Granted Patent B2
US 10,454,948 · App. 15/357,089 · Granted Oct 22, 2019

Method, system, and storage medium for adaptive monitoring and filtering traffic to and from social networking sites

Inventors: Cameron Blair Cooper (Lakeway, TX); Christopher Lee Richter (Cedar Park, TX)
Assignee: Proofpoint, Inc.
H04L63/1408G06Q50/01H04L43/14H04L51/32H04L67/02H04L67/20H04L63/0281H04L67/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,454,948
App. No.
15/357,089
Granted
Oct 22, 2019
Kind
B2
Abstract

Embodiments disclosed herein provide a system, method, and computer readable storage medium storing computer instructions for implementing a Socialware architecture encompassing a suite of applications for continuously and adaptively monitoring and filtering traffic to and from social networking sites, particularly useful in an enterprise computing environment. In some embodiments, an appliance may be coupled to a proxy server for providing a plurality of Socialware services, including analyzing, logging, and reporting on traffic to and from social networking sites. Some embodiments may allow a user to report, identify, and prevent malicious and potentially malicious content and/or activity by another user. Some embodiments may encrypt outgoing traffic to and decrypt incoming traffic from social networking sites. Some embodiments may provide an enterprise user to define and restrict certain social networking activities outside of the enterprise computing environment.

Claims (42)

1. A method for adaptively filtering network traffic to and from social networking sites, the method comprising:

receiving, by a first software component, content from a computing device associated with a user, the first software component embodied on a server machine communicatively connected to the computing device and to at least one social networking site, the first software component configured for monitoring network traffic between a browser application on the computing device and the at least one social networking site;

determining, by the first software component, whether the content from the computing device designates a social networking site of the at least one social networking site;

responsive to the content from the computing device not designating a social networking site of the at least one social networking site, communicating the content unmodified from the computing device to a designated destination;

responsive to the content from the computing device designating a social networking site of the at least one social networking site, communicating, by the first software component, the content from the computing device to a second software component over a network, the second software component external to the first software component, the second software component configured for application of data security;

receiving, by the first software component from the second software component, information relating to the application of data security to the content;

determining, by the first software component based on the information received from the second software component, whether to generate modified content from the content received from the computing device; and

communicating, by the first software component, one of the modified content and the content from the computing device to the social networking site of the at least one social networking site.

2. The method according to claim 1 , wherein the first software component is communicatively connected to a plurality of applications running on different operating systems, the plurality of applications including third-party applications running on machines external to the server machine.

3. The method according to claim 2 , wherein the first software component has no control over the plurality of applications and the at least one social networking site.

4. The method according to claim 2 , wherein the second software component is one of the plurality of applications.

5. The method according to claim 1 , wherein the first software component is further configured for trapping information from the computing device before the information is communicated to the at least one social networking site.

6. The method according to claim 1 , wherein the second software component is further configured for determining whether the content from the computing device is private, sensitive, or malicious based on a set of rules or via one or more scans.

7. The method according to claim 1 , wherein contents trapped by the first software component and determined by the second software component as malicious or potentially malicious are hosted independently of the first software component and of the second software component.

8. A computer program product for adaptively filtering network traffic to and from social networking sites, the computer program product comprising at least one non-transitory computer-readable storage medium storing computer instructions translatable by a server machine embodying a first software component to perform:

receiving content from a computing device associated with a user, the server machine communicatively connected to the computing device and to at least one social networking site, the first software component configured for monitoring network traffic between a browser application on the computing device and the at least one social networking site;

determining whether the content from the computing device designates a social networking site of the at least one social networking site;

responsive to the content from the computing device not designating a social networking site of the at least one social networking site, communicating the content unmodified from the computing device to a designated destination;

responsive to the content from the computing device designating a social networking site of the at least one social networking site, communicating the content from the computing device to a second software component over a network, the second software component external to the first software component, the second software component configured for application of data security;

receiving, from the second software component, information relating to the application of data security to the content;

determining, by the first software component based on the information received from the second software component, whether to generate modified content from the content received from the computing device; and

communicating one of the modified content and or the content from the computing device to the social networking site of the at least one social networking site.

9. The computer program product of claim 8 , wherein the first software component is communicatively connected to a plurality of applications running on different operating systems, the plurality of applications including third-party applications running on machines external to the server machine.

10. The computer program product of claim 9 , wherein the first software component has no control over the plurality of applications and the at least one social networking site.

11. The computer program product of claim 9 , wherein the second software component is one of the plurality of applications.

12. The computer program product of claim 8 , wherein the first software component is further configured for trapping information from the computing device before the information is communicated to the at least one social networking site.

13. The computer program product of claim 8 , wherein the second software component is further configured for determining whether the content from the computing device is private, sensitive, or malicious based on a set of rules or via one or more scans.

14. The computer program product of claim 8 , wherein contents trapped by the first software component and determined by the second software component as malicious or potentially malicious are hosted independently of the first software component and of the second software component.

15. A system for adaptively filtering network traffic to and from social networking sites, the system comprising:

a server machine embodying a first software component, the server machine having at least one processor, at least one non-transitory computer-readable storage medium, and stored computer instructions translatable by the at least one processor to perform:

receiving content from a computing device associated with a user, the server machine communicatively connected to the computing device and to at least one social networking site, the first software component configured for monitoring network traffic between a browser application on the computing device and the at least one social networking site;

determining whether the content from the computing device designates a social networking site of the at least one social networking site;

responsive to the content from the computing device not designating a social networking site of the at least one social networking site, communicating the content unmodified from the computing device to a designated destination;

responsive to the content from the computing device designating a social networking site of the at least one social networking site, communicating the content from the computing device to a second software component over a network, the second software component external to the first software component, the second software component configured for application of data security;

receiving, from the second software component, information relating to the application of data security to the content;

determining, by the first software component based on the information received from the second software component, whether to generate modified content from the content received from the computing device; and

communicating one of the modified content and the content from the computing device to the social networking site of the at least one social networking site.

16. The system of claim 15 , wherein the first software component is communicatively connected to a plurality of applications running on different operating systems, the plurality of applications including third-party applications running on machines external to the server machine.

17. The system of claim 16 , wherein the first software component has no control over the plurality of applications and the at least one social networking site.

18. The system of claim 15 , wherein the first software component is further configured for trapping information from the computing device before the information is communicated to the at least one social networking site.

19. The system of claim 15 , wherein the second software component is further configured for determining whether the content from the computing device is private, sensitive, or malicious based on a set of rules or via one or more scans.

20. The system of claim 15 , wherein contents trapped by the first software component and determined by the second software component as malicious or potentially malicious are hosted independently of the first software component and of the second software component.

Assignments (6)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2016
From: SOCIALWARE, INC.
To: PROOFPOINT, INC.
Reel/Frame 040730/0387 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2016
From: COOPER, CAMERON BLAIR; RICHTER, CHRISTOPHER LEE
To: SOCIALWARE, INC.
Reel/Frame 040392/0984 →
Continuity (4)
Continuation 13942558 · Jul 15, 2013
Continuation 12562032 · Sep 17, 2009
Provisional Application 61097698 · Sep 17, 2008
Related Publication 20170099303A1 · Apr 6, 2017