IP Library Granted Patent US 11,562,093
Granted Patent B2
US 11,562,093 · App. 16/293,949 · Granted Jan 24, 2023

System for generating an electronic security policy for a file format type

Inventor: Amit Nitzan (Tel Aviv, IL)
Assignee: Forcepoint LLC
G06F21/6227G06F16/116
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,562,093
App. No.
16/293,949
Granted
Jan 24, 2023
Kind
B2
Abstract

A method, system, and computer-readable storage medium are disclosed for identifying binary signatures in a selected set of files and assigning at least one of the binary signatures to a file format name or file format type for use in a security policy generator. In certain embodiments, the method for generating an electronic security policy for a file format type, includes: identification of a plurality of files stored in electronic memory, where the plurality of files include files having the same file format type; providing a file format name that is to be associated with the file format type; accessing the plurality of files from the electronic memory; identifying a common binary signature for the file format type included in the plurality of files; correlating the file format type with the common binary signature; and generating the security policy for the file format type using the file format name.

Claims (68)

1. A computer-implemented method for generating a security policy, comprising:

receiving, at a user interface, identification of a plurality of files stored in electronic memory, wherein the plurality of files includes files having a file format type;

providing a file format name, the file format name being associated with the file format type;

accessing the plurality of files from the electronic memory;

identifying a common binary signature for the file format type included in the plurality of files; and

generating the security policy for the file format type using the file format name, the security policy being generated via a security policy generator, wherein the security policy includes the common binary signature for the file format type; and

deploying the security policy for use in a protected endpoint, the protected endpoint comprising an endpoint agent in combination with an endpoint device, the security policy being deployed via at least one of directly from the security policy generator and a deployment system having access to a security policy datastore; and wherein

the security policy generator is included within a security analytics environment, the security analytics environment comprising a security analytics system, the security analytics system being implemented to perform a risk-adaptive protection operation using the security policy, the risk-adaptive protection operation adaptively responding to a risk associated with an electronically-observable user behavior, a risk-adaptive behavior factor and a user authentication factor being used in performance of the risk-adaptive protection operation;

the user authentication factor comprises a user biometric authentication factor, a token user authentication factor and a user identifier user authentication factor; and,

the risk-adaptive behavior factors comprise a user profile attribute factor, a user access insights factor, a user interactions factor, a date/time/frequency factor, a user location factor, a user gesture factor and a user mindset factor.

2. The computer-implemented method of claim 1 , further comprising:

using the common binary signature deployed in the security policy to detect occurrences of events relating to files having the file format type.

3. The computer-implemented method of claim 1 , wherein identifying the common binary signature comprises:

scanning the plurality of files to detect binary content common to two or more of the plurality of files, wherein the binary content common to two or more of the plurality of files is added to a set of binary signature candidates for the file format name.

4. The computer-implemented method of claim 3 , wherein

only binary signature candidates common to a majority of the plurality of files are correlated with the file format name for use as the common binary signature.

5. The computer-implemented method of claim 1 , wherein

a single binary signature candidate from a set of binary signature candidates is correlated with the file format name for use as the common binary signature.

6. The computer-implemented method of claim 1 , wherein

the file format name is received at the user interface.

7. The computer-implemented method of claim 1 , wherein

the file format name is automatically determined based on one or more common attributes of the plurality of files, wherein the common attributes include one or more of a file extension or text identified in two or more of the plurality of files.

8. The computer-implemented method of claim 1 , wherein the security policy is deployed to a plurality of endpoint devices.

9. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving, at a user interface, identification of a plurality of files stored in electronic memory, wherein the plurality of files includes files having a file format type;

providing a file format name, the file format name being associated with the file format type

accessing the plurality of files from the electronic memory;

identifying a common binary signature for the file format type included in the plurality of files; and

generating a security policy for the file format type using the file format name, the security policy being generated via a security policy generator, wherein the security policy includes the common binary signature for the file format type; and

deploying the security policy for use in a protected endpoint, the protected endpoint comprising an endpoint agent in combination with an endpoint device, the security policy being deployed via at least one of directly from the security policy generator and a deployment system having access to a security policy datastore; and wherein

the security policy generator is included within a security analytics environment, the security analytics environment comprising a security analytics system, the security analytics system being implemented to perform a risk-adaptive protection operation using the security policy, the risk-adaptive protection operation adaptively responding to a risk associated with an electronically-observable user behavior, a risk-adaptive behavior factor and a user authentication factor being used in performance of the risk-adaptive protection operation;

the user authentication factor comprises a user biometric authentication factor, a token user authentication factor and a user identifier user authentication factor; and,

the risk-adaptive behavior factors comprise a user profile attribute factor, a user access insights factor, a user interactions factor, a date/time/frequency factor, a user location factor, a user gesture factor and a user mindset factor.

10. The system of claim 9 , wherein the instructions are further configured for:

using the common binary signature deployed in the security policy to detect occurrences of events relating to files having the file format type.

11. The system of claim 9 , wherein identifying the common binary signature comprises:

scanning the plurality of files to detect binary content common to two or more of the plurality of files, wherein the binary content common to two or more of the plurality of files is added to a set of binary signature candidates for the file format name.

12. The system of claim 11 , wherein

there are at least three files having the file format type; and,

only binary signature candidates common to a majority of the plurality of files are correlated with the file format name for use as the common binary signature.

13. The system of claim 9 , wherein

the file format name is received at the user interface.

14. The system of claim 9 , wherein

the file format name is automatically determined based on one or more common attributes of the plurality of files, wherein the common attributes include one or more of a file extension or text identified in two or more of the plurality of files.

15. The system of claim 9 wherein

the security policy is deployed to a plurality of endpoint devices.

16. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

receiving, at a user interface, identification of a plurality of files stored in electronic memory, wherein the plurality of files includes files having a file format type;

providing a file format name, the file format name being associated with the file format type;

accessing the plurality of files from the electronic memory;

identifying a common binary signature for the file format type included in the plurality of files; and

generating a security policy for the file format type using the file format name, the security policy being generated via a security policy generator, wherein the security policy includes the common binary signature for the file format type; and

deploying the security policy for use in a protected endpoint, the protected endpoint comprising an endpoint agent in combination with an endpoint device, the security policy being deployed via at least one of directly from the security policy generator and a deployment system having access to a security policy datastore; and wherein

the security policy generator is included within a security analytics environment, the security analytics environment comprising a security analytics system, the security analytics system being implemented to perform a risk-adaptive protection operation using the security policy, the risk-adaptive protection operation adaptively responding to a risk associated with an electronically-observable user behavior, a risk-adaptive behavior factor and a user authentication factor being used in performance of the risk-adaptive protection operation;

the user authentication factor comprises a user biometric authentication factor, a token user authentication factor and a user identifier user authentication factor; and,

the risk-adaptive behavior factors comprise a user profile attribute factor, a user access insights factor, a user interactions factor, a date/time/frequency factor, a user location factor, a user gesture factor and a user mindset factor.

17. The non-transitory, computer-readable storage medium of claim 16 , wherein the instructions are further configured for:

using the common binary signature deployed in the security policy to detect occurrences of events relating to files having the file format type.

18. The non-transitory, computer-readable storage medium of claim 16 , wherein identifying the common binary signature comprises:

scanning the plurality of files to detect binary content common to two or more of the plurality of files, wherein the binary content common to two or more of the plurality of files is added to a set of binary signature candidates for the file format name.

19. The non-transitory, computer-readable storage medium of claim 18 , wherein

there are at least three files having the file format type; and,

only binary signature candidates common to a majority of the plurality of files are correlated with the file format name for use as the common binary signature.

20. The non-transitory, computer-readable storage medium of claim 16 , wherein

the file format name is automatically determined based on one or more common attributes of the plurality of files, wherein the common attributes include one or more of a file extension or text identified in two or more of the plurality of files.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2019
From: NITZAN, AMIT
To: FORCEPOINT, LLC
Reel/Frame 048515/0665 →