IP Library Granted Patent US 10,997,310
Granted Patent B2
US 10,997,310 · App. 16/523,273 · Granted May 4, 2021

Protecting sensitive information from a secure data store

Inventors: David P. Keene (Dublin, OH); Daryl E. Donley (Dublin, OH)
Assignee: Sophos Limited
G06F21/6218G06F21/602G06F21/88H04L63/02H04L63/083H04L63/10H04L63/14H04L63/20H04W12/065H04W12/088H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,997,310
App. No.
16/523,273
Granted
May 4, 2021
Kind
B2
Abstract

In embodiments of the present invention improved capabilities are described for the steps of receiving an indication that a computer facility has access to a secure data store, causing a security parameter of a storage medium local to the computer facility to be assessed, determining if the security parameter is compliant with a security policy relating to computer access of the remote secure data store, and in response to an indication that the security parameter is non-compliant, cause the computer facility to implement an action to prevent further dissemination of information, to disable access to network communications, to implement an action to prevent further dissemination of information, and the like.

Claims (33)

1. A method of protecting stored information, the method comprising:

storing a security policy for controlling access by a network endpoint to a remote data store, the security policy requiring a data store connected to the network endpoint to meet one or more security requirements for identification as a secure data store, the one or more security requirements including a requirement that the data store is connected to the network endpoint through password protected access;

receiving an indication at a threat management facility that a first endpoint has access to the remote data store;

based on the indication that the first endpoint has accessed the remote data store, auditing the first endpoint to determine whether a security parameter of a first data store connected to the first endpoint is compliant with the one or more security requirements for identification as a secure data store;

when the security parameter of the first data store is compliant with the one or more security requirements for identification as a secure data store, permitting dissemination of data from the remote data store to the first endpoint; and

when the security parameter of the first data store is not compliant with at least one of the one or more security requirements, causing the first endpoint to implement an action by the first endpoint to regulate dissemination of data from the remote data store to the first endpoint.

2. The method of claim 1 , wherein the action includes at least one of disabling network communications to the first endpoint and disabling network communications from the first endpoint.

3. The method of claim 1 , wherein the action includes at least one of disabling all network communications to the first endpoint, except for communication between the threat management facility and the first endpoint, and disabling all network communications from the first endpoint, except for communication between the threat management facility and the first endpoint.

4. The method of claim 1 , wherein the action includes disabling communications between the first endpoint and the remote data store.

5. The method of claim 1 , wherein the action includes disabling write capabilities to the first data store.

6. The method of claim 1 , wherein the action includes disabling local port communications.

7. The method of claim 1 , wherein the one or more security requirements include a requirement of anti-virus software running on the network endpoint.

8. The method of claim 1 , wherein the one or more security requirements include a requirement of a correct version of endpoint compliance software running on the network endpoint.

9. The method of claim 1 , wherein the one or more security requirements include a requirement of the network endpoint having an appropriate operating firewall.

10. A computer program product embodied in a non-transitory computer readable medium that, when executing on a threat management facility, performs steps comprising:

storing a security policy for controlling access by a network endpoint to a remote data store, the security policy requiring a data store connected to the network endpoint to meet one or more security requirements for identification as a secure data store, the one or more security requirements including a requirement that the data store is connected to the network endpoint through password protected access;

receiving an indication at the threat management facility that a first endpoint has access to the remote data store;

based on the indication that the first endpoint has accessed the remote data store, auditing the first endpoint to determine whether a security parameter of a first data store connected to the first endpoint is compliant with the one or more security requirements for identification as a secure data store;

when the security parameter of the first data store is compliant with the one or more security requirements for identification as a secure data store, permitting dissemination of data from the remote data store to the first endpoint; and

when the security parameter of the first data store is not compliant with at least one of the one or more security requirements, causing the first endpoint to implement an action by the first endpoint to regulate dissemination of data from the remote data store to the first endpoint.

11. The computer program product of claim 10 , wherein the action includes at least one of disabling network communications to the first endpoint and disabling network communications from the first endpoint.

12. The computer program product of claim 10 , wherein the action includes disabling communications between the first endpoint and the remote data store.

13. The computer program product of claim 10 , wherein the action includes disabling write capabilities to data stores associated with the first endpoint.

14. The computer program product of claim 10 , wherein the action includes disabling local port communications.

15. The computer program product of claim 10 , wherein the one or more security requirements include a requirement of anti-virus software running on the network endpoint.

16. The computer program product of claim 10 , wherein the one or more security requirements include a requirement of a correct version of endpoint compliance software running on the network endpoint.

17. The computer program product of claim 10 , wherein the one or more security requirements include a requirement of the network endpoint having an appropriate operating firewall.

18. A system comprising:

a remote data store;

a first endpoint including a computing device comprising a memory and a processor, the first endpoint in a communicating relationship with the remote data store, and the first endpoint storing a security policy for controlling access by a network endpoint to the remote data store, the security policy requiring a data store connected to the network endpoint to meet one or more security requirements for identification as a secure data store, the one or more security requirements including a requirement that the data store is connected to the network endpoint through password protected access; and

a threat management facility coupled in a communicating relationship with the first endpoint, the threat management facility configured to, in response to an indication that the first endpoint has access to the remote data store, audit the first endpoint to determine whether a first internal data store connected to the first endpoint is compliant with one or more security requirements for identification as a secure data store, to permit dissemination of data from the remote data store to the first endpoint when the first internal data store is compliant with the one or more security requirements for identification as a secure data store, and, when the first internal data store is not compliant with at least one of the one or more security requirements, to cause the first endpoint to implement an action, by the first endpoint to regulate dissemination of data from the remote data store to the first endpoint.

19. The system of claim 18 , wherein regulating dissemination of data includes one or more of the following: disabling communications between the first endpoint and the remote data store; and disabling all local port communications.

20. The system of claim 18 , wherein regulating dissemination of data includes disabling write capabilities to data stores associated with the first endpoint.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2019
From: KEENE, DAVID P.; DONLEY, DARYL E.
To: SOPHOS PUBLIC LIMITED COMPANY
Reel/Frame 049887/0287 →
CHANGE OF NAME Recorded Jul 29, 2019
From: SOPHOS PUBLIC LIMITED COMPANY
To: SOPHOS LIMITED
Reel/Frame 049890/0303 →