IP Library Granted Patent US 11,134,087
Granted Patent B2
US 11,134,087 · App. 16/119,353 · Granted Sep 28, 2021

System identifying ingress of protected data to mitigate security breaches

Inventor: Richard A. Ford (Austin, TX)
Assignee: Forcepoint, LLC
H04L63/12G06F21/552G06F21/6218H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,134,087
App. No.
16/119,353
Granted
Sep 28, 2021
Kind
B2
Abstract

A method, system and computer-usable medium for mitigating security breaches associated with dissemination of protected data. In certain embodiments, the method includes receiving information communicated to a secured network from a source external to the secured network and determining whether the received information includes protected data. If the received information includes protected data, a determination is made as to whether the receipt of the protected data is anomalous. If the receipt of the protected data is anomalous, one or more sources of egress of the protected data from the secured network are identified. By identifying the sources of egress, actions may be taken to prevent future egress of the protected data.

Claims (69)

1. A computer-implementable method for mitigating security breaches associated with dissemination of protected data, comprising:

receiving information communicated to a secured network from a source external to the secured network, the secured network comprising an electronic security system that implements security policies to avoid and track unauthorized access, exploitation, modification or denial of network resources;

determining whether the received information includes protected data, the protected data comprising data over which the secured network exercises controlled access and does not make available without the controlled access; and

if the received information includes protected data, determining whether the receipt of the protected data is anomalous, receipt of the protected data being anomalous indicating the protected data was disseminated from the secured network in a broken business process not included in the security policies; and

if the receipt of the protected data is anomalous, identifying one or more sources of egress of the protected data from the secured network.

2. The method of claim 1 , wherein the receipt of the protected data is determined to be anomalous under one or more conditions comprising:

determining that the external source is not authorized to access the protected data;

determining that the external source utilizes an unauthorized device to electronically communicate the protected data to the secured network; and/or

determining that there are no identifiable sources of egress of the protected data from the secured network.

3. The method of claim 1 , wherein determining whether the received information includes protected data comprises one or more of:

determining whether the received protected data includes a duplicate of one or more protected files stored in the secured network; and/or

determining whether the received protected data includes one or more files derived from one or more protected files stored in the secured network.

4. The method of claim 1 , further comprising:

if the receipt of the protected data is anomalous,

saving session data for a session in which the protected data was received; and

tagging the session data as including an anomalous receipt of the protected data to thereby facilitate identification of the external source.

5. The method of claim 4 , further comprising:

if the receipt of the protected data is anomalous,

searching analytics data to identify entities within the secured network that have transmitted the protected data to the external source based, at least in part, on the tagged session data.

6. The method of claim 1 , further comprising:

if the receipt of the protected data is anomalous,

searching analytics data to identify entities within the secured network that have transmitted the protected data to one or more entities external to the secured network.

7. The method of claim 6 , further comprising:

searching analytics data to identify entities that have accessed the protected data within the secured network when no occurrences of transmission of the protected data to one or more entities external to the secured network are identifiable.

8. The method of claim 7 , further comprising:

prioritizing a security breach investigation of entities that have accessed protected data within the secured network based on user behaviors of the entities.

9. The method of claim 1 , wherein identifying one or more sources of egress of the protected data from within the secured network comprises:

identifying business processes through which the protected data was manually conveyed to third parties.

10. The method of claim 1 , wherein the determination of whether the received information includes protected data comprises one or more of:

comparing key phrases extracted from the received information with key phrases associated with protected data stored in the secured network;

comparing a file fingerprint of the received information with one or more file fingerprints of files containing protected data stored in the secured network;

comparing a digital watermark extracted from the received information with one or more digital watermarks associated with protected data stored in the secured network; and

comparing an image watermark extracted from the received information with one or more image watermarks associated with protected data stored in the secured network.

11. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving information communicated to a secured network from a source external to the secured network, the secured network comprising an electronic security system that implements security policies to avoid and track unauthorized access, exploitation, modification or denial of network resources;

determining whether the received information includes protected data, the protected data comprising data over which the secured network exercises controlled access and does not make available without the controlled access; and

if the received information includes protected data, determining whether the receipt of the protected data is anomalous, receipt of the protected data being anomalous indicating the protected data was disseminated from the secured network in a broken business process not included in the security policies; and

if the receipt of the protected data is anomalous, identifying one or more sources of egress of the protected data from the secured network.

12. The system of claim 11 , wherein the instructions are configured for determining that receipt of the protected data is anomalous under one or more conditions comprising:

determining that the external source is not authorized to access the protected data;

determining that the external source utilizes an unauthorized device to electronically communicate the protected data to the secured network; and/or

determining that there are no identifiable sources of egress of the protected data from the secured network.

13. The system of claim 11 , wherein determining whether the received information includes protected data comprises one or more of:

determining whether the received protected data includes a duplicate of one or more protected files in the secured network; and

determining whether the received protected data includes one or more files derived from one or more protected files in the secured network.

14. The system of claim 11 , further comprising:

if the receipt of the protected data is anomalous,

saving session data for a session in which the protected data was received; and

tagging the session data as including an anomalous receipt of the protected data to thereby facilitate identification of the external source.

15. The system of claim 14 , further comprising:

if the receipt of the protected data is anomalous,

searching analytics data to identify entities that have transmitted the protected data to the external source based, at least in part, on the tagged session data.

16. The system of claim 11 , further comprising:

if the receipt of the protected data is anomalous,

searching analytics data to identify entities within the secured network that have transmitted the protected data to one or more entities external to the secured network.

17. The system of claim 11 , further comprising:

searching analytics data to identify entities within the secured network that have accessed the protected data within the secured network when no occurrences of transmission of the protected data to one or more entities external to the secured network are identifiable.

18. The system of claim 11 , wherein identifying one or more sources of egress of the protected data from within the secured network comprises:

identifying business processes through which the protected data was manually conveyed to third parties.

19. The system of claim 11 , further comprising:

prioritizing a security breach investigation of entities that have accessed protected data within the secured network based on user behaviors of the entities.

20. The system of claim 11 , wherein the determination of whether the received information includes protected data comprises one or more of:

comparing key phrases extracted from the received information with key phrases associated with protected data stored in the secured network;

comparing a file fingerprint of the received information with one or more file fingerprints of files containing protected data stored in the secured network;

comparing a digital watermark extracted from the received information with one or more digital watermarks associated with protected data stored in the secured network; and

comparing an image watermark extracted from the received information with one or more image watermarks associated with protected data stored in the secured network.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2018
From: FORD, RICHARD A.
To: FORCEPOINT, LLC
Reel/Frame 046870/0289 →
Continuity (1)
Related Publication 20200076826A1 · Mar 5, 2020
Cited By (1)
US 12,360,685