IP Library Granted Patent US 10,728,239
Granted Patent B2
US 10,728,239 · App. 15/449,569 · Granted Jul 28, 2020

Mediated access to resources

Inventors: Jackie Anne Maylor (Wiltshire, GB); Simon Paul Tyler (Wiltshire, GB); Steven Malone (Berkshire, GB); Wayne Van Ry (London, GB); Francisco Ribeiro (London, GB); Nathaniel S. Borenstein (Greenbush, MI)
Assignee: Mimecast Services Ltd.
H04L63/083G06F21/6245H04L51/046H04L51/12H04L63/0254H04L63/0281H04L63/101H04L63/1433H04L63/1441H04L63/1466H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,728,239
App. No.
15/449,569
Granted
Jul 28, 2020
Kind
B2
Abstract

Today's user is facing an ever increasing number of cyber threats from infectious software to scam artist phishing for their passwords and other personal information. Accordingly, a technique is provided to mediate a user's access to electronic resources, which can include malware and sites that trick the user into giving their password. Based on information known about the resource at the time the user accesses it, the technique can warn the user that the resources is suspicious and it is not safe to provide their password. Even if the resource is safe, the technique can warn the user not reuse their password, thereby promoting good password hygiene.

Claims (44)

1. A method for mediating a user's access to a resource, the method comprising:

provided with a resource that has been rewritten by a pre-delivery threat analysis and intervention system, the resource rewritten as a protected resource prior to being delivered to a user based on information known about the resource at the time of delivery, querying for updated information about the resource in response to the user accessing the protected resource, wherein querying for the updated information includes comparing a suspicion score associated with the protected resource to a threshold value; and

mediating the user's access to the protected resource based on the updated information and the comparison, wherein mediating the user's access comprises:

creating an intermediary page that: i) warns the user which user action is allowed or banned with respect to the protected resource or ii) warns the user that the protected resource is suspicious based on the updated information; and

returning the intermediary page to the user prior to connecting the user to the protected resource.

2. The method of claim 1 , wherein mediating the user's access includes blocking the user's access to the protected resource based on the updated information.

3. The method of claim 1 , wherein querying for the updated information includes looking up a list of known resources in which each resource is associated with an allowed user action and/or banned user action.

4. The method of claim 1 , wherein querying for the updated information includes looking up the updated information about the protected resource using a wildcard.

5. The method of claim 1 , wherein querying for the updated information includes looking up the updated information about the protected resource using subdomain matching.

6. The method of claim 1 further comprising:

graphically comparing a screen image of the protected resource to screen images of trusted resources; and

determining the suspicion score based, at least in part, on the graphical comparison.

7. The method of claim 1 , in an event the protected resource is a form from a site asking the user to provide a password, the method further comprising:

determining whether the password entered by the user is allowed or banned for the site; and

blocking the user from submitting the password to the resource when the entered password is banned for the site.

8. The method of claim 7 , wherein determining whether the password entered by the user is allowed or banned includes determining whether the entered password is associated with a known resource; and

based on the determination, identifying the entered password as a banned password.

9. The method of claim 1 , wherein the protected resource is delivered to the user in an electronic message.

10. The method of claim 1 , wherein the resource is a reference to a resource.

11. A system for mediating a user's access to a resource, the system comprising:

a decoder for decoding a resource that has been rewritten by a pre-delivery threat analysis and intervention system prior to being delivered to a user, the resource rewritten as a protected resource based on information known about the resource at the time of delivery;

a mediation mechanism communicatively coupled to the decoder, the mediation mechanism configured to:

query a database for updated information about the resource in response to the user accessing the protected resource by comparing a suspicion score associated with the protected resource to a threshold value;

mediate the user's access to the protected resource based on the updated information and the comparison;

create an intermediary page that: i) warns the user which user action is allowed or banned with respect to the protected resource or ii) warns the user that the protected resource is suspicious based on the updated information; and

return the intermediary page to the user prior to connecting the user to the protected resource.

12. The system of claim 11 , wherein the mediation mechanism mediates the user access by blocking the user's access to the protected resource based on the updated information.

13. The system of claim 11 , wherein the mediation mechanism queries the database by looking up a list of known resources in which each resource is associated with an allowed user action and/or banned user action.

14. The system of claim 11 , wherein the mediation mechanism queries the database by looking up the updated information about the protected resource using a wildcard.

15. The system of claim 11 , wherein the mediation mechanism queries the database by looking up the updated information about the protected resource using subdomain matching.

16. The system of claim 11 , wherein the mediation mechanism is further configured to:

graphically compare a screen image of the protected resource to known screen images of trusted resources; and

determine the suspicion score based, at least in part, on the graphical comparison.

17. The system of claim 11 , in an event the protected resource is a form from a site asking the user to provide a password, the mediation mechanism is further configured to:

determine whether the password entered by the user is allowed or banned for the site;

and block the user from submitting the password to the resource when the entered password is banned for the site.

18. The system of claim 17 , wherein the mediation mechanism determines whether the password entered by the user is allowed or banned by determining whether the entered password is associated with a known resource, and based on the determination, identify the entered password as a banned password.

19. The system of claim 11 , wherein the protected resource is delivered to the user in an electronic message.

20. The system of claim 11 , wherein the resource is a reference to a resource.

21. A non-transitory computer readable medium storing instructions executable by at least one processor to execute a method for mediating a user's access to a resource, the instructions being coded to instruct the at least one processor to:

provided with a resource that has been rewritten by a pre-delivery threat analysis and intervention system, the resource rewritten as a protected resource prior to being delivered to a user based on information known about the resource at the time of delivery, query for updated information about the resource in response to the user accessing the protected resource, wherein querying for the updated information includes comparing a suspicion score associated with the protected resource to a threshold value; and

mediate the user's access to the protected resource based on the updated information and the comparison, wherein mediating the user's access comprises:

creating an intermediary page that: i) warns the user which user action is allowed or banned with respect to the protected resource or ii) warns the user that the protected resource is suspicious based on the updated information; and

returning the intermediary page to the user prior to connecting the user to the protected resource.

Assignments (5)
SECURITY INTEREST Recorded May 20, 2022
From: MIMECAST NORTH AMERICA, INC.; MIMECAST SERVICES LIMITED
To: ARES CAPITAL CORPORATION
Reel/Frame 060132/0429 →
RELEASE OF SECURITY INTEREST Recorded May 19, 2022
From: JPMORGAN CHASE BANK, N.A.
To: MIMECAST SERVICES LTD.; ETORCH INC.
Reel/Frame 059962/0294 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2019
From: MAYLOR, JACKIE ANNE; TYLER, SIMON PAUL; MALONE, STEVEN; VAN RY, WAYNE; RIBEIRO, FRANCISCO; BORENSTEIN, NATHANIEL S.
To: MIMECAST SERVICES LTD.
Reel/Frame 051018/0872 →
SECURITY AGREEMENT Recorded Jul 23, 2018
From: MIMECAST SERVICES LIMITED
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 046616/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2017
From: MIMECAST NORTH AMERICA, INC.
To: MIMECAST SERVICES LTD.
Reel/Frame 042821/0798 →
Continuity (3)
Continuation In Part 15010023 · Jan 29, 2016
Continuation In Part 14855200 · Sep 15, 2015
Related Publication 20170180378A1 · Jun 22, 2017
Cited By (6)
US 12,238,101 US 12,341,813 US 12,417,253 US 12,438,909 US 12,450,424 US 12,580,960