IP Library Granted Patent US 10,063,373
Granted Patent B2
US 10,063,373 · App. 15/360,591 · Granted Aug 28, 2018

Key management for compromised enterprise endpoints

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,063,373
App. No.
15/360,591
Granted
Aug 28, 2018
Kind
B2
Abstract

Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.

Claims (28)

1. A method comprising:

labeling processes on an endpoint with a labeling scheme in which the processes are either in, wherein the processes conform to a compliance policy administered for the endpoint from a remote threat management facility, or the processes are out, wherein the processes do not conform to the compliance policy, thereby providing a plurality of in processes and a plurality of out processes;

for in processes of the endpoint, providing access to encrypted files through a file system, with access to the encrypted files controlled by the file system and limited to processes in compliance with the compliance policy;

detecting a compromise of the endpoint based on a change of an in process to an out process when the in process falls out of compliance with the compliance policy; and

in response to detecting the compromise, deleting key material cached on the endpoint to prevent decryption of the encrypted files through the file system for the in processes, thereby revoking access to the encrypted files by the processes executing on the endpoint.

2. The method of claim 1 further comprising monitoring at least one of the processes for compliance with the compliance policy.

3. The method of claim 2 wherein monitoring for compliance includes monitoring a behavior of the at least one of the processes.

4. The method of claim 3 wherein the behavior includes an interaction with one or more other processes on the endpoint.

5. The method of claim 1 further comprising monitoring at least one of the encrypted files for compliance with the compliance policy.

6. The method of claim 1 wherein detecting the compromise of the endpoint includes receiving an indication of compromise (IOC).

7. The method of claim 1 wherein an external monitoring facility detects the compromise of the endpoint.

8. The method of claim 7 wherein the external monitoring facility sends a signal to the endpoint to set itself into a state of compromise when the compromise is detected.

9. The method of claim 1 wherein an internal monitoring facility on the endpoint detects the compromise of the endpoint.

10. The method of claim 1 wherein detecting the compromise of the endpoint includes receiving an IOC pattern from the endpoint indicative of a compromised state.

11. The method of claim 1 wherein detecting the compromise of the endpoint is based on at least one of: behavioral analysis, malware signature analysis, reputation, and access to a remote command and control resource.

12. The method of claim 1 wherein the compromise includes exposure of at least one of the plurality of in processes to an external process.

13. The method of claim 12 wherein the external process is known or suspected to be malicious.

14. The method of claim 12 wherein a security status of the external process is unknown.

15. A computer program product comprising non-transitory computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

labeling processes on an endpoint with a labeling scheme in which the processes are either in, wherein the processes conform to a compliance policy administered for the endpoint from a remote threat management facility, or the processes are out, wherein the processes do not conform to the compliance policy, thereby providing a plurality of in processes and a plurality of out processes;

for in processes of the endpoint, providing access to encrypted files through a file system, with access to the encrypted files controlled by the file system and limited to processes in compliance with the compliance policy;

detecting a compromise of the endpoint based on a change of an in process to an out process when the in process falls out of compliance with the compliance policy; and

in response to detecting the compromise, deleting key material cached on the endpoint to prevent decryption of the encrypted files through the file system for the in processes, thereby revoking access to the encrypted files by the processes executing on the endpoint.

16. The computer program product of claim 15 wherein the code further performs the step of monitoring at least one of the processes for compliance with the compliance policy.

17. The computer program product of claim 15 wherein the compromise includes exposure of at least one of the plurality of in processes to an external object.

18. A system comprising:

a threat management facility configured to manage threats to an enterprise, the threat management facility maintaining a compliance policy for endpoints in the enterprise; and

an endpoint associated with the enterprise having a memory and a processor, the memory storing a plurality of processes, and the processor configured to label the processes with a labeling scheme in which the processes are either in, wherein the processes conform to the compliance policy, or the processes are out, wherein the processes do not conform to the compliance policy, thereby providing a plurality of in processes and a plurality of out processes, to provide, to the in processes of the endpoint, access to encrypted files through a file system, with access to the encrypted files controlled by the file system and limited to processes in compliance with the compliance policy, to detect a compromise of the endpoint based on a change of an in process to an out process when the in process falls out of compliance with the compliance policy, and in response to detecting the compromise, to delete key material cached in the memory on the endpoint to prevent decryption of the encrypted files through the file system for the in processes, thereby revoking access to the encrypted files by the processes executing on the endpoint.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2016
From: SCHÜTZ, HARALD; THOMAS, ANDREW J.; RAY, KENNETH D.; SCHIAPPA, DANIEL SALVATORE
To: SOPHOS LIMITED
Reel/Frame 040424/0607 →
Cited By (1)
US 12,192,216