IP Library Granted Patent US 11,516,206
Granted Patent B2
US 11,516,206 · App. 16/865,176 · Granted Nov 29, 2022

Cybersecurity system having digital certificate reputation system

Inventors: Lawrence Bruce Huston, III (Ann Arbor, MI); David Coffey (Austin, TX)
Assignee: Forcepoint LLC
H04L63/0823H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,516,206
App. No.
16/865,176
Granted
Nov 29, 2022
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for implementing a cybersecurity system having a digital certificate reputation system. At least one embodiment is directed to a computer-implemented method executing operations including receiving a communication having an internet protocol (IP) address and a digital certificate at a device within the secured network; determining whether the IP address is identified as having a high-security risk level; if the IP address has a high-security risk level, assigning a security risk level to the digital certificate based on the security risk level of the IP address; and using the security risk level for the digital certificate in executing the one or more security policies. Other embodiments include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices.

Claims (62)

1. A computer-implemented method for executing one or more security policies in a secured network, comprising:

receiving a communication including an Internet protocol (IP) address and a digital certificate at a device within the secured network, the IP address having an IP address security risk level, the digital certification having a digital certificate security risk level;

determining whether the IP address security risk level is identified as having a high-security risk level;

if the IP address has a high-security risk level, assigning a security risk level to the digital certificate based on the security risk level of the IP address;

using the security risk level for the IP address and the security risk level for the digital certificate in executing the one or more security policies, the one or more security policies comprising one or more reputation security policies, executing the one or more reputation security policies is based upon the security risk level for the IP address and the security risk level for the digital certificate; and,

if the digital certificate is associated with an IP address having a high-security risk level,

analyzing the digital certificate to identify one or more digital certificate characteristics; and

analyzing other digital certificates to determine whether other digital certificates have one or more of the same digital certificate characteristics.

2. The computer-implemented method of claim 1 , wherein

the one or more security policies assign different weights to the security risk level of the IP address and the security risk level of the digital certificate to determine an appropriate security response.

3. The computer-implemented method of claim 1 , further comprising:

determining whether the IP address has a high-security risk includes determining whether the IP address is on a blacklist of IP addresses; and

assigning a high-security risk level to the digital certificate if the IP address is on the blacklist of IP addresses.

4. The computer-implemented method of claim 1 , further comprising:

retrieving a user behavior security risk level corresponding to security risk presented by a user, wherein the user is an intended recipient of the communication; and

using the security risk level for the IP address, the security risk level for the digital certificate, and the user behavior security risk level for the user to execute one or more security policies.

5. The computer-implemented method of claim 1 , further comprising:

increasing a security risk level of the IP address if the digital certificate has been previously used with one or more IP addresses presenting an elevated security risks.

6. The computer-implemented method of claim 1 , further comprising:

assigning an elevated security risk level to the other digital certificates having one or more of the same digital certificate characteristics.

7. A system comprising:

one or more information handling systems, wherein the one or more information handling systems include:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus;

wherein the computer program code included in one or more of the information handling systems is executable by the processor of the information handling system so that the information handling system, alone or in combination with other information handling systems, executes operations comprising:

receiving a communication including an Internet protocol (IP) address and a digital certificate at a device within the secured network, the IP address having an IP address security risk level, the digital certification having a digital certificate security risk level;

determining whether the IP address is identified as having a high-security risk level, the determining being based upon the associated reputation of the digital certificate;

if the IP address has a high-security risk level, assigning a security risk level to the digital certificate based on the security risk level of the IP address;

using the security risk level for the IP address and the security risk level for the digital certificate in executing the one or more security policies, the one or more security policies comprising one or more reputation security policies, executing the one or more reputation security policies is based upon the security risk level for the IP address and the security risk level for the digital certificate; and,

if the digital certificate is associated with an IP address having a high-security risk level,

analyzing the digital certificate to identify one or more digital certificate characteristics; and

analyzing other digital certificates to determine whether other digital certificates have one or more of the same digital certificate characteristics.

8. The system of claim 7 , wherein

the one or more security policies assign different weights to the security risk level of the IP address and the security risk level of the digital certificate to determine an appropriate security response.

9. The system of claim 7 , wherein

determining whether the IP address has a high-security risk includes determining whether the IP address is on a blacklist of IP addresses; and

assigning a high-security risk level to the digital certificate if the IP address is on the blacklist of IP addresses.

10. The system of claim 7 , wherein the computer program code is further configured for:

retrieving a user behavior security risk level corresponding to security risk presented by a user, wherein the user is an intended recipient of the communication; and

using the security risk level for the IP address, the security risk level for the digital certificate, and the user behavior security risk level for the user to execute one or more security policies.

11. The system of claim 7 , wherein the computer program code is further configured for:

increasing a security risk level of the IP address if the digital certificate has been previously used with one or more IP addresses presenting elevated security risks.

12. The system of claim 7 , wherein the computer program code is further configured for:

assigning an elevated security risk level to the other digital certificates having one or more of the same digital certificate characteristics.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer-executable instructions configured for:

receiving a communication including an Internet protocol (IP) address and a digital certificate at a device within the secured network, the IP address having an IP address security risk level, the digital certification having a digital certificate security risk level;

determining whether the IP address security risk level is identified as having a high-security risk level;

if the IP address has a high-security risk level, assigning a security risk level to the digital certificate based on the security risk level of the IP address;

using the security risk level for the IP address and the security risk level for the digital certificate in executing the one or more security policies, the one or more security policies comprising one or more reputation security policies, executing the one or more reputation security policies is based upon the security risk level for the IP address and the security risk level for the digital certificate; and,

if the digital certificate is associated with an IP address having a high-security risk level, analyzing the digital certificate to identify one or more digital certificate characteristics; and

analyzing other digital certificates to determine whether other digital certificates have one or more of the same digital certificate characteristics.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein

the one or more security policies assign different weights to the security risk level of the IP address and the security risk level of the digital certificate to determine an appropriate security response.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein

determining whether the IP address has a high-security risk includes determining whether the IP address is on a blacklist of IP addresses; and

assigning a high-security risk level to the digital certificate if the IP address is on the blacklist of IP addresses.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein the instructions are further configured for:

retrieving a user behavior security risk level corresponding to security risk presented by a user, wherein the user is an intended recipient of the communication; and

using the security risk level for the IP address, the security risk level for the digital certificate, and the user behavior security risk level for the user to execute one or more security policies.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein the instructions are further configured for:

increasing a security risk level of the IP address if the digital certificate has been previously used with one or more IP addresses presenting an elevated security risk.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2020
From: HUSTON, LAWRENCE BRUCE, III; COFFEY, DAVID
To: FORCEPOINT, LLC
Reel/Frame 052598/0200 →