IP Library Granted Patent US 10,733,323
Granted Patent B2
US 10,733,323 · App. 16/369,924 · Granted Aug 4, 2020

Privacy protection during insider threat monitoring

Inventors: Richard A. Ford (Austin, TX); Christopher B. Shirey (Leander, TX); Jonathan B. Knepher (La Mesa, CA); Lidror Troyansky (Givataim, IL)
Assignee: Forcepoint LLC
G06F21/6245G06F11/3438G06F21/552G06F21/577G06F21/602G06F21/6254G06F21/84H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L67/025H04L67/141H04L67/146H04L67/22H04L67/306G06F2221/031G06F2221/032G06F2221/034H04L63/20H04L67/289H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,733,323
App. No.
16/369,924
Granted
Aug 4, 2020
Kind
B2
Abstract

A method, system and computer-usable medium are disclosed for performing a privacy operation, comprising: monitoring user behavior via an Input/output collector, the Input/output collector capturing user/device interactions between a user and a device; determining whether the user/device interactions include sensitive personal information; obfuscating the sensitive personal information, the obfuscating preventing viewing of the sensitive personal information; storing obfuscated sensitive personal information within an obfuscated sensitive personal information repository; and, allowing access to the obfuscated sensitive personal information stored within the obfuscated sensitive personal information repository only when an administrator is authorized to access the obfuscated sensitive personal information so as to provide conditional sensitive personal information access.

Claims (53)

1. A computer-implementable method for performing a privacy operation, comprising:

monitoring user behavior via an Input/output collector, the Input/output collector capturing user/device interactions between a user and a device, the Input/output collector comprising a keystroke collector, the monitoring comprising collecting keystrokes resulting from user/device interactions;

determining whether the keystrokes resulting from the user/device interactions include sensitive personal information;

obfuscating the sensitive personal information, the obfuscating preventing viewing of the sensitive personal information;

storing sensitive personal information that has been obfuscated within an obfuscated sensitive personal information repository; and,

allowing access to the sensitive personal information stored within the obfuscated sensitive personal information repository only when a security administrator is authorized to access the sensitive personal information, the allowing access only when the security administrator is authorized providing conditional sensitive personal information access, authorization to access the sensitive personal information being provided via a superior of the administrator, access to the sensitive personal information being via a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

2. The method of claim 1 , wherein:

the obfuscating comprises storing the sensitive personal information within the obfuscated sensitive personal information repository via a one-way function, the one-way function preventing access to the sensitive personal information unless access to the obfuscated sensitive personal information is authorized.

3. The method of claim 2 , wherein:

the keystrokes corresponding to the sensitive personal information being are added to the one-way function.

4. The method of claim 1 , wherein:

storing the sensitive personal information comprises storing the sensitive personal information as a tamper-evident record, the tamper-evident record providing immutability of requests for conditional sensitive personal information access.

5. The method of claim 1 , wherein:

the allowing access further comprises determining whether the security administrator is authorized to access the obfuscated sensitive personal information based upon a sensitive personal information policy.

6. The method of claim 5 , wherein:

the sensitive personal information policy is generated using a sensitive personal information obfuscation and conditional access policy generation operation, the sensitive personal information obfuscation and conditional access policy generation operation comprising determining factors associated with a particular sensitive personal information policy, the factors associated with a particular sensitive personal information policy comprising at least one of known user authentication factors, identification factors and risk-adaptive behavior factors.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring user behavior via an Input/output collector, the Input/output collector capturing user/device interactions between a user and a device, the Input/output collector comprising a keystroke collector, the monitoring comprising collecting keystrokes resulting from user/device interactions;

determining whether the keystrokes resulting from the user/device interactions include sensitive personal information;

obfuscating the sensitive personal information, the obfuscating preventing viewing of the sensitive personal information;

storing sensitive personal information that has been obfuscated within an obfuscated sensitive personal information repository; and,

allowing access to the sensitive personal information stored within the obfuscated sensitive personal information repository only when a security administrator is authorized to access the sensitive personal information, the allowing access only when the security administrator is authorized providing conditional sensitive personal information access, authorization to access the sensitive personal information being provided via a superior of the administrator, access to the sensitive personal information being via a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

8. The system of claim 7 , wherein:

the obfuscating comprises storing the sensitive personal information within the obfuscated sensitive personal information repository via a one-way function, the one-way function preventing access to the sensitive personal information unless access to the obfuscated sensitive personal information is authorized.

9. The system of claim 8 , wherein:

the keystrokes corresponding to the sensitive personal information are added to the one-way function.

10. The system of claim 7 , wherein:

storing the sensitive personal information comprises storing the sensitive personal information as a tamper-evident record, the tamper-evident record providing immutability of requests for conditional sensitive personal information access.

11. The system of claim 7 , wherein:

the allowing access further comprises determining whether the security administrator is authorized to access the obfuscated sensitive personal information based upon a sensitive personal information policy.

12. The system of claim 11 , wherein the instructions executable by the processor are further configured for:

the sensitive personal information policy is generated using a sensitive personal information obfuscation and conditional access policy generation operation, the sensitive personal information obfuscation and conditional access policy generation operation comprising determining factors associated with a particular sensitive personal information policy, the factors associated with a particular sensitive personal information policy comprising at least one of known user authentication factors, identification factors and risk-adaptive behavior factors.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring user behavior via an Input/output collector, the Input/output collector capturing user/device interactions between a user and a device, the Input/output collector comprising a keystroke collector, the monitoring comprising collecting keystrokes resulting from user/device interactions;

determining whether the keystrokes resulting from the user/device interactions include sensitive personal information;

obfuscating the sensitive personal information, the obfuscating preventing viewing of the sensitive personal information;

storing sensitive personal information that has been obfuscated within an obfuscated sensitive personal information repository; and,

allowing access to the sensitive personal information stored within the obfuscated sensitive personal information repository only when a security administrator is authorized to access the sensitive personal information, the allowing access only when the security administrator is authorized providing conditional sensitive personal information access, authorization to access the sensitive personal information being provided via a superior of the administrator, access to the sensitive personal information being via a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the obfuscating comprises storing the sensitive personal information within the obfuscated sensitive personal information repository via a one-way function, the one-way function preventing access to the sensitive personal information unless access to the obfuscated sensitive personal information is authorized.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the keystrokes corresponding to the sensitive personal information are added to the one-way function.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

storing the sensitive personal information comprises storing the sensitive personal information as a tamper-evident record, the tamper-evident record providing immutability of requests for conditional sensitive personal information access.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the allowing access further comprises determining whether the security administrator is authorized to access the obfuscated sensitive personal information based upon a sensitive personal information policy.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the sensitive personal information policy is generated using a sensitive personal information obfuscation and conditional access policy generation operation, the sensitive personal information obfuscation and conditional access policy generation operation comprising determining factors associated with a particular sensitive personal information policy, the factors associated with a particular sensitive personal information policy comprising at least one of known user authentication factors, identification factors and risk-adaptive behavior factors.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2019
From: FORD, RICHARD A.; SHIREY, CHRISTOPHER B.; KNEPHER, JONATHAN B.; TROYANSKY, LIDROR
To: FORCEPOINT, LLC
Reel/Frame 048742/0554 →
Cited By (1)
US 12,250,245