IP Library Granted Patent US 11,025,638
Granted Patent B2
US 11,025,638 · App. 16/040,128 · Granted Jun 1, 2021

System and method providing security friction for atypical resource access requests

Inventors: Richard A. Ford (Austin, TX); Jeff Timbs (Austin, TX); Kurt Natvig (Thatcham, GB)
Assignee: Forcepoint, LLC
H04L63/105H04L63/107H04L63/108H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,025,638
App. No.
16/040,128
Granted
Jun 1, 2021
Kind
B2
Abstract

A method, system and computer-usable medium for providing security friction to a request for access to a resource based on whether the access request is atypical. In certain embodiments, a request to access the resource based on a user identity is received electronically. The system determines whether the request is typical or atypical. If the request is typical, access to the requested resource is granted. However, if the request is atypical, access to the requested resource is only allowed if the correct information is provided in response to one or more access control methods that provide an amount of security friction that would otherwise not have been asserted if the resource request was typical. In certain embodiments, an elapsed time between access requests based on the user identity is used to determine whether the access request is atypical.

Claims (60)

1. A computer-implemented method for controlling access to a resource, comprising:

receiving a request to access the resource by an entity, the request being received via a protected endpoint environment, the protected endpoint environment comprising an endpoint agent executing on an endpoint device, the endpoint agent being implemented to autonomously decide if a particular action is appropriate for a user behavior, the request being based on a user identity of the entity:

determining whether the request is typical or atypical, the request being typical when an elapsed time between a current resource request time and a previous resource request time is less than a predetermined elapsed time, the request being atypical when the elapsed time between the current resource request time and the previous resource request time is greater than the predetermined elapsed time, wherein the request being atypical providing an indication that access rights of the entity have been compromised;

if the request is typical, granting access to the requested resource; and

if the request is atypical, controlling access to the requested resource using one or more user access control methods to provide security friction that would otherwise not have been used if the request were typical, the security friction providing a protective effect when the request is atypical.

2. The computer-implemented method of claim 1 , wherein, if the request is typical, access to the requested resource is granted without security friction.

3. The computer-implemented method of claim 1 , further comprising:

if the request is typical, controlling access to the requested resource using one or more access control methods to provide a first degree of security friction prior to granting access to the requested resource; and

if the request is atypical, controlling access to the requested resource using one or more access control methods to provide a second degree of security friction prior to granting access to the requested resource, wherein the second degree of security friction is higher than the first degree of security friction.

4. The computer-implemented method of claim 1 , further comprising:

determining a degree to which the request is atypical; and

providing different degrees of security friction corresponding to the degree to which the request is atypical.

5. The computer-implemented method of claim 4 , further comprising:

using access control methods providing high degrees of security friction for requests having high degrees of atypicality; and

using access control methods providing low degrees of security friction for requests having low degrees of atypicality.

6. The computer-implemented method of claim 1 , wherein determining whether the request is atypical comprises:

determining the elapsed time by comparing the time at which the request is made with a time at which a prior request to access the resource was previously received or granted based upon the user identity.

7. The computer-implemented method of claim 6 , further comprising one or more of:

determining that the request is atypical when the elapsed time exceeds a first threshold limit; and

determining that the request is atypical when the elapsed time is less than a second threshold limit.

8. The computer-implemented method of claim 7 , further comprising:

assigning a degree of atypicality based on a length of the elapsed time, wherein longer elapsed times are assigned higher degrees of atypicality than shorter elapsed times.

9. The computer-implemented method of claim 1 , wherein determining whether the request is atypical comprises:

determining that the request is atypical if a software program attempting to access the resource is a software program not typically used to access the resource.

10. The computer-implemented method of claim 1 , wherein the user identity is at least part of a user profile, the method further comprising:

determining whether the request is atypical by comparing a current security risk level associated with the user identity in effect at the time of the request with a security risk level associated with the user identity in effect at a time when the user identity was last used to request or gain access to the resource.

11. The computer-implemented method of claim 10 , further comprising:

determining a degree to which a request is atypical includes determining a degree to which the security risk levels associated with the user identity differ.

12. A system comprising:

a hardware processor;

an electronic communication channel coupled to the hardware processor; and

a computer-usable medium embodying computer program code, the computer-usable medium being coupled to the electronic communication channel, the computer program code used for asserting different access control methods to provide different amounts of security friction for access to a resource, the computer-usable medium storing instructions executable by the hardware processor and configured to implement operations comprising:

receiving a request to access the resource by an entity, the request being received via a protected endpoint environment, the protected endpoint environment comprising an endpoint agent executing on an endpoint device, the endpoint agent being implemented to autonomously decide if a particular action is appropriate for a user behavior, the request being based on a user identity of the entity:

determining whether the request is typical or atypical, the request being typical when an elapsed time between a current resource request time and a previous resource request time is less than a predetermined elapsed time, the request being atypical when the elapsed time between the current resource request time and the previous resource request time is greater than the predetermined elapsed time, wherein the request being atypical providing an indication that access rights of the entity have been compromised;

if the request is typical, granting access to the requested resource; and

if the request is atypical, controlling access to the requested resource using one or more user access control methods to provide security friction that would otherwise not have been used if the request were typical, the security friction providing a protective effect when the request is atypical.

13. The system of claim 12 , wherein the instructions are further configured for:

if the request is typical, access to the requested resource is granted without security friction.

14. The system of claim 12 , wherein the instructions are further configured for executing operations comprising:

if the request is typical, controlling access to the requested resource using one or more access control methods to provide a first degree of security friction prior to granting access to the requested resource; and

if the request is atypical, controlling access to the requested resource using one or more access control methods to provide a second degree of security friction prior to granting access to the requested resource, wherein the second degree of security friction is higher than the first degree of security friction.

15. The system of claim 12 , wherein the instructions are further configured for executing operations comprising:

determining a degree to which the request is atypical; and

providing different degrees of security friction corresponding to the degree to which the request is atypical.

16. The system of claim 12 , wherein the instructions are further configured for executing operations comprising:

using access control methods to provide high amounts of security friction for requests having high degrees of atypicality; and

using access control methods to provide low amounts of security friction for requests having low degrees of atypicality.

17. The system of claim 12 , wherein the instructions are further configured for executing operations to determine whether the request is atypical comprising:

determining the elapsed time by comparing the time at which the request is made with a time at which a prior electronic request to access the resource was previously received or granted based upon the user identity.

18. The system of claim 17 , wherein the instructions are further configured for executing operations comprising one or more of:

determining that the request is atypical when the elapsed time exceeds a first threshold limit; and

determining that the request is atypical when the elapsed time is less than a second threshold limit.

19. The system of claim 18 , wherein the instructions are further configured for executing operations further comprising:

assigning a degree of atypicality to the request based on a length of the elapsed time, wherein longer elapsed times are assigned higher degrees of atypicality than shorter elapsed times.

20. The system of claim 12 , wherein the instructions are further configured for executing operations to determining whether the request is atypical comprising:

determining that the request is atypical if a software program requesting access to the resource is a software program not typically used to access the resource.

21. The system of claim 12 , wherein the user identity is at least part of a user profile, and wherein the instructions are further configured for executing operations comprising:

determining whether the request is atypical by comparing a current security risk level associated with the user identity in effect at the time of the request with a prior security risk level associated with the user identity in effect at a time when the user identity was last used to request or gain access to the resource.

22. The system of claim 21 , wherein the instructions are further configured for executing operations comprising:

determining the degree to which a request is atypical includes determining a degree to which the security risk levels associated with the user identity differ.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2018
From: FORD, RICHARD A.; TIMBS, JEFF; NATVIG, KURT
To: FORCEPOINT, LLC
Reel/Frame 046899/0394 →