IP Library Granted Patent US 10,318,729
Granted Patent B2
US 10,318,729 · App. 15/667,054 · Granted Jun 11, 2019

Privacy protection during insider threat monitoring

Inventors: Richard A. Ford (Austin, TX); Christopher B. Shirey (Leander, TX); Jonathan B. Knepher (La Mesa, CA); Lidror Troyansky (Givataim, IL)
Assignee: Forcepoint, LLC
G06F21/552G06F11/3438G06F21/577G06F21/602G06F21/6245G06F21/6254G06F21/84H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L63/20H04L67/025H04L67/141H04L67/146H04L67/22H04L67/306G06F2221/031G06F2221/032H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,318,729
App. No.
15/667,054
Granted
Jun 11, 2019
Kind
B2
Abstract

A method, system and computer-usable medium are disclosed for performing a privacy operation, comprising: monitoring user behavior via a data stream collector, the data stream collector capturing data streams resulting from user/device interactions between a user and a corresponding endpoint device; determining whether the data streams resulting from user/device interactions include sensitive personal information; obfuscating the sensitive personal information, the obfuscating preventing unauthorized viewing of the sensitive personal information; and, presenting the sensitive personal information as a sensitive personal information token indicating the data streams include sensitive personal information.

Claims (62)

1. A computer-implementable method for performing a privacy operation, comprising:

monitoring user behavior via an Input/output collector, the Input/output collector capturing user/device interactions between a user and a device;

determining whether the user/device interactions include sensitive personal information;

obfuscating the sensitive personal information, the obfuscating preventing viewing of the sensitive personal information;

presenting the sensitive personal information as a sensitive personal information indication, the sensitive personal information indication indicating the user/device interactions include sensitive personal information;

offering the user an opportunity to enroll user sensitive personal information in a privacy protection system;

enrolling the user sensitive personal information in the privacy protection system, the enrolling preventing display of sensitive personal information to a security administrator via a company security system, the company security system comprising an insider threat monitoring system; and,

presenting a sensitive personal information indication via the company security system, the sensitive personal information indication informing the security administrator that sensitive personal information was entered by the user.

2. The method of claim 1 , wherein:

the obfuscating comprises storing the sensitive personal information via a one way function, the one way function preventing access to the sensitive personal information.

3. The method of claim 2 , wherein:

the data stream collector comprises a keystroke collector; and,

the monitoring comprises collecting keystrokes resulting from user/device interactions, the keystrokes corresponding to the sensitive personal information being added to the one way function.

4. The method of claim 1 , further comprising:

capturing a context associated with the data streams resulting from user/device interactions between a user and a corresponding endpoint device; and,

presenting the context along with the sensitive personal information token.

5. The method of claim 1 , further comprising:

developing sensitive personal information obfuscation policies; and,

using the sensitive personal information obfuscation policies to determine whether the user/device interactions include sensitive personal information and which sensitive personal information to obfuscate.

6. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring user behavior via an Input/output collector, the Input/output collector capturing user/device interactions between a user and a device;

determining whether the user/device interactions include sensitive personal information;

obfuscating the sensitive personal information, the obfuscating preventing viewing of the sensitive personal information;

presenting the sensitive personal information as a sensitive personal information indication, the sensitive personal information indication indicating the user/device interactions include sensitive personal information;

offering the user an opportunity to enroll user sensitive personal information in a privacy protection system;

enrolling the user sensitive personal information in the privacy protection system, the enrolling preventing display of sensitive personal information to a security administrator via a company security system, the company security system comprising an insider threat monitoring system; and,

presenting a sensitive personal information indication via the company security system, the sensitive personal information indication informing the security administrator that sensitive personal information was entered by the user.

7. The system of claim 6 , wherein:

the obfuscating comprises storing the sensitive personal information via a one way function, the one way function preventing access to the sensitive personal information.

8. The system of claim 7 , wherein:

the data stream collector comprises a keystroke collector; and,

the monitoring comprises collecting keystrokes resulting from user/device interactions, the keystrokes corresponding to the sensitive personal information being added to the one way function.

9. The system of claim 6 , wherein:

capturing a context associated with the data streams resulting from user/device interactions between a user and a corresponding endpoint device; and,

presenting the context along with the sensitive personal information token.

10. The system of claim 6 , wherein the instructions executable by the processor are further configured for:

developing sensitive personal information obfuscation policies; and,

using the sensitive personal information obfuscation policies to determine whether the data streams resulting from user/device interactions include sensitive personal information and which sensitive personal information to obfuscate.

11. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring user behavior via an Input/output collector, the Input/output collector capturing user/device interactions between a user and a device;

determining whether the data streams resulting from user/device interactions include sensitive personal information;

obfuscating the sensitive personal information, the obfuscating preventing viewing of the sensitive personal information;

presenting the sensitive personal information as a sensitive personal information indication, the sensitive personal information indication indicating the user/device interactions include sensitive personal information;

offering the user an opportunity to enroll user sensitive personal information in a privacy protection system;

enrolling the user sensitive personal information in the privacy protection system, the enrolling preventing display of sensitive personal information to a security administrator via a company security system, the company security system comprising an insider threat monitoring system; and,

presenting a sensitive personal information indication via the company security system, the sensitive personal information indication informing the security administrator that sensitive personal information was entered by the user.

12. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the obfuscating comprises storing the sensitive personal information via a one way function, the one way function preventing access to the sensitive personal information.

13. The non-transitory, computer-readable storage medium of claim 12 , wherein:

the data stream collector comprises a keystroke collector; and,

the monitoring comprises collecting keystrokes resulting from user/device interactions, the keystrokes corresponding to the sensitive personal information being added to the one way function.

14. The non-transitory, computer-readable storage medium of claim 11 , wherein the computer executable instructions are further configured for:

capturing a context associated with the data streams resulting from user/device interactions between a user and a corresponding endpoint device; and,

presenting the context along with the sensitive personal information token.

15. The non-transitory, computer-readable storage medium of claim 11 , wherein:

developing sensitive personal information obfuscation policies; and,

using the sensitive personal information obfuscation policies to determine whether the user/device interactions include sensitive personal information and which sensitive personal information to obfuscate.

16. The non-transitory, computer-readable storage medium of claim 11 , wherein the computer executable instructions are deployable to a client system from a server system at a remote location.

17. The non-transitory, computer-readable storage medium of claim 11 , wherein the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2017
From: FORD, RICHARD A.; SHIREY, CHRISTOPHER B.; KNEPHER, JONATHAN B.; TROYANSKY, LIDROR
To: FORCEPOINT, LLC
Reel/Frame 043415/0479 →
Continuity (2)
Provisional Application 62537102 · Jul 26, 2017
Related Publication 20190034660A1 · Jan 31, 2019
Cited By (2)
US 12,505,249 US 12,566,889