IP Library Granted Patent US 11,374,977
Granted Patent B2
US 11,374,977 · App. 16/136,659 · Granted Jun 28, 2022

Endpoint risk-based network protection

Inventors: Valtteri Rahkonen (Helsinki, FI); Jaakko Moller (Helsinki, FI)
Assignee: Forcepoint LLC
H04L63/20H04L63/1416H04L63/1425H04L63/1441H04L67/2852
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,374,977
App. No.
16/136,659
Granted
Jun 28, 2022
Kind
B2
Abstract

A method, system, and computer-usable medium are disclosed for managing network communication by, responsive to an attempted connection from a client to a server, receiving information regarding the connection from the client, determining if the information regarding the connection matches an entry of a reputation cache, and responsive to determining that the information regarding the connection matches an entry of the reputation cache, undertaking a remedial action in accordance with a security policy.

Claims (50)

1. A computer-implemented method for managing network communication, comprising:

building a reputation cache by correlating malicious network activities to execution of particular executable programs on particular clients; and

responsive to an attempted connection from a client to a server:

receiving information regarding the connection from the client, wherein the information regarding the connection comprises information regarding a user associated with an executable program used by the client to establish the connection;

determining if the information regarding the connection matches an entry of the reputation cache;

responsive to determining that the information regarding the connection matches an entry of the reputation cache, undertaking a remedial action in accordance with a security policy; and

responsive to detecting a malicious action associated with traffic of the connection, updating the reputation cache such that a signer of the executable program is categorized as suspicious, and such that a risk level of the user associated with the executable program is adapted.

2. The method of claim 1 , wherein the remedial action comprises at least one of increasing inspection of the traffic of the connection and prevention of communication of the traffic.

3. The method of claim 1 , wherein the information regarding the connection comprises information regarding the client and information regarding the executable program used by the client to establish the connection.

4. The method of claim 1 , wherein the information regarding the connection comprises information regarding the server.

5. The method of claim 1 , wherein the information regarding the connection comprises information regarding the signer of the executable program used by the client to establish the connection.

6. The method of claim 1 , further comprising responsive to determining that the information regarding the connection does not match an entry of the reputation cache:

allowing the traffic;

inspecting the traffic;

updating the reputation cache in response to detecting a malicious action associated with the traffic; and

undertaking a remedial action in response to detecting the malicious action.

7. A system comprising:

a processor; and

a non-transitory, computer-readable storage medium embodying computer program code comprising instructions executable by the processor and configured for:

building a reputation cache by correlating malicious network activities to execution of particular executable programs on particular clients; and

responsive to an attempted connection from a client to a server:

receiving information regarding the connection from the client, wherein the information regarding the connection comprises information regarding a user associated with an executable program used by the client to establish the connection;

determining if the information regarding the connection matches an entry of the reputation cache;

responsive to determining that the information regarding the connection matches an entry of the reputation cache, undertaking a remedial action in accordance with a security policy; and

responsive to detecting a malicious action associated with traffic of the connection, updating the reputation cache such that a signer of the executable program is categorized as suspicious, and such that a risk level of the user associated with the executable program is adapted.

8. The system of claim 7 , wherein the remedial action comprises at least one of increasing inspection of the traffic of the connection and prevention of communication of the traffic.

9. The system of claim 7 , wherein the information regarding the connection comprises information regarding the client and information regarding the executable program used by the client to establish the connection.

10. The system of claim 7 , wherein the information regarding the connection comprises information regarding the server.

11. The system of claim 7 , wherein the information regarding the connection comprises information regarding the signer of the executable program used by the client to establish the connection.

12. The system of claim 7 , the instructions further configured for, responsive to determining that the information regarding the connection does not match an entry of the reputation cache:

allowing the traffic;

inspecting the traffic;

updating the reputation cache in response to detecting a malicious action associated with the traffic; and

undertaking a remedial action in response to detecting the malicious action.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

building a reputation cache by correlating malicious network activities to execution of particular executable programs on particular clients; and

responsive to an attempted connection from a client to a server:

receiving information regarding the connection from the client, wherein the information regarding the connection comprises information regarding a user associated with an executable program used by the client to establish the connection;

determining if the information regarding the connection matches an entry of the reputation cache;

responsive to determining that the information regarding the connection matches an entry of the reputation cache, undertaking a remedial action in accordance with a security policy; and

responsive to detecting a malicious action associated with traffic of the connection, updating the reputation cache such that a signer of the executable program is categorized as suspicious, and such that a risk level of the user associated with the executable program is adapted.

14. The storage medium of claim 13 , wherein the remedial action comprises at least one of increasing inspection of the traffic of the connection and prevention of communication of the traffic.

15. The storage medium of claim 13 , wherein the information regarding the connection comprises information regarding the client and information regarding the executable program used by the client to establish the connection.

16. The storage medium of claim 13 , wherein the information regarding the connection comprises information regarding the server.

17. The storage medium of claim 13 , wherein the information regarding the connection comprises information regarding the signer of the executable program used by the client to establish the connection.

18. The storage medium of claim 13 , the computer executable instructions further configured for, responsive to determining that the information regarding the connection does not match an entry of the reputation cache:

allowing the traffic;

inspecting the traffic;

updating the reputation cache in response to detecting a malicious action associated with the traffic; and

undertaking a remedial action in response to detecting the malicious action.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2018
From: RAHKONEN, VALTTERI; MOLLER, JAAKKO
To: FORCEPOINT LLC
Reel/Frame 046926/0869 →
Continuity (1)
Related Publication 20200099719A1 · Mar 26, 2020