IP Library Granted Patent US 11,763,019
Granted Patent B2
US 11,763,019 · App. 17/306,584 · Granted Sep 19, 2023

Protecting sensitive information from a secure data store

Inventors: David P. Keene (Dublin, OH); Daryl E. Donley (Dublin, OH)
Assignee: Sophos Limited
G06F21/6218G06F21/602G06F21/88H04L63/02H04L63/083H04L63/10H04L63/14H04L63/20H04W12/065H04W12/088H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,763,019
App. No.
17/306,584
Granted
Sep 19, 2023
Kind
B2
Abstract

In embodiments of the present invention improved capabilities are described for the steps of receiving an indication that a computer facility has access to a secure data store, causing a security parameter of a storage medium local to the computer facility to be assessed, determining if the security parameter is compliant with a security policy relating to computer access of the remote secure data store, and in response to an indication that the security parameter is non-compliant, cause the computer facility to implement an action to prevent further dissemination of information, to disable access to network communications, to implement an action to prevent further dissemination of information, and the like.

Claims (33)

1. A method of protecting stored information, the method comprising:

storing a security policy controlling access by an endpoint in an enterprise network to a remote data store outside the enterprise network, the security policy requiring that a data store connected to the endpoint store data in a cryptographically protected manner;

receiving an indication at a threat management facility for the enterprise network of a requested access by the endpoint to the remote data store, the endpoint includes a removable data store connected to the endpoint;

based on the indication of the requested access to the remote data store, determining whether the removable data store connected to the endpoint is compliant with the requirement of the security policy for storing data in the cryptographically protected manner;

when the removable data store is compliant with the requirement of the security policy for storing data in the cryptographically protected manner, permitting an exchange of data between the remote data store and the endpoint; and

when the removable data store is not compliant with the requirement of the security policy for storing data in the cryptographically protected manner, preventing the exchange of data between the remote data store and the endpoint by disabling communications between the endpoint and the remote data store.

2. The method of claim 1 , further comprising disabling network communications to the endpoint and disabling network communications from the endpoint.

3. The method of claim 1 , further comprising disabling all network communications to the endpoint, except for communications between the threat management facility and the endpoint, and disabling all network communications from the endpoint, except for communications between the threat management facility and the endpoint.

4. The method of claim 1 , further comprising disabling write capabilities to the removable data store.

5. The method of claim 1 , further comprising disabling local port communications by the endpoint.

6. The method of claim 1 , wherein the security policy includes a second requirement for anti-virus software running on the endpoint.

7. The method of claim 1 , wherein the security policy include a second requirement for a correct version of endpoint compliance software running on the endpoint.

8. The method of claim 1 , wherein the security policy includes a second requirement for a firewall operating on the endpoint.

9. A computer program product comprising computer-executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs steps comprising:

storing a security policy for controlling access by a network endpoint to a remote data store, the security policy requiring a data store connected to the network endpoint to meet one or more security requirements for identification as a secure data store, the one or more security requirements including a requirement that the data store is cryptographically protected;

receiving an indication at a threat management facility of requested access by a first endpoint to the remote data store;

based on the indication of requested access by the first endpoint to the remote data store, determining whether a security parameter of a first data store connected to the first endpoint is compliant with the one or more security requirements for identification as a secure data store;

when the security parameter of the first data store is compliant with the one or more security requirements for identification as the secure data store, permitting exchange of data between the remote data store and the first endpoint; and

when the security parameter of the first data store is not compliant with the one or more security requirements for identification as the secure data store, causing the first endpoint to implement an action to regulate an exchange of data between the remote data store and the first endpoint.

10. The computer program product of claim 9 , wherein the action includes at least one of disabling network communications to the first endpoint and disabling network communications from the first endpoint.

11. The computer program product of claim 9 , wherein the action includes disabling communications between the first endpoint and the remote data store.

12. The computer program product of claim 9 , wherein the action includes disabling write capabilities to data stores associated with the first endpoint.

13. The computer program product of claim 9 , wherein the action includes disabling local port communications.

14. The computer program product of claim 9 , wherein the one or more security requirements include a second requirement for a firewall operating on the first endpoint.

15. The computer program product of claim 9 , wherein the first data store is wirelessly connected to the first endpoint.

16. The computer program product of claim 9 , wherein the first data store includes an internal data store of the first endpoint.

17. The computer program product of claim 9 , wherein the first data store includes a removable data store connected to the first endpoint.

18. A system, comprising:

a remote data store;

a first endpoint including a computing device comprising a memory and a processor, the first endpoint in a communicating relationship with the remote data store, and the first endpoint storing a security policy for controlling access by a network endpoint to the remote data store, the security policy requiring a data store connected to the network endpoint to meet one or more security requirements for identification as a secure data store, the one or more security requirements including a requirement that the data store is cryptographically protected; and

a threat management facility coupled in a communicating relationship with the first endpoint, the threat management facility comprising one or more processors and a memory, the memory comprising instructions that, when executed by the one or more processors, in response to an indication of requested access by the first endpoint to the remote data store, determine whether a first internal data store connected to the first endpoint is compliant with one or more security requirements for identification as a secure data store, to permit exchange of data between the remote data store and the first endpoint when the first internal data store is compliant with the one or more security requirements for identification as a secure data store, and, when the first internal data store is not compliant with at least one of the one or more security requirements, to cause the first endpoint to implement an action, by the first endpoint to regulate an exchange of data between the remote data store and the first endpoint.

19. The system of claim 18 , wherein the action to regulate the exchange of data includes one or more of: disabling communications between the first endpoint and the remote data store and disabling all local port communications by the first endpoint.

20. The system of claim 18 , wherein the action to regulate the exchange of data includes disabling write capabilities to data stores associated with the first endpoint.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2021
From: KEENE, DAVID P.; DONLEY, DARYL E.
To: SOPHOS PUBLIC LIMITED COMPANY
Reel/Frame 056123/0220 →
CHANGE OF NAME Recorded May 4, 2021
From: SOPHOS PUBLIC LIMITED COMPANY
To: SOPHOS LIMITED
Reel/Frame 056123/0261 →
Continuity (4)
Continuation 16523273 · Jul 26, 2019
Continuation 15241915 · Aug 19, 2016
Continuation 12405642 · Mar 17, 2009
Related Publication 20210271770A1 · Sep 2, 2021