IP Library Granted Patent US 10,148,694
Granted Patent B1
US 10,148,694 · App. 14/873,046 · Granted Dec 4, 2018

Preventing data loss over network channels by dynamically monitoring file system operations of a process

Inventors: Sumit Manmohan Sarin (Pune, IN); Sumesh Jaiswal (Pune, IN); Bishnu Chaturvedi (Pune, IN); Arnaud Scomparin (Dublin, CA)
Assignee: SYMANTEC CORPORATION
H04L63/20G06F21/566G06F21/60G06F21/62H04L63/105H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,148,694
App. No.
14/873,046
Granted
Dec 4, 2018
Kind
B1
Abstract

Techniques are disclosed for performing data loss prevention (DLP) by monitoring file system activity of an application having a network connection. A DLP agent tracks file system activity (e.g., file open and read operations) being initiated by the application. The DLP agent intercepts the file system activity and evaluates a file specified by the file system operation to determine whether the file includes sensitive data. If so determined, the DLP agent prevents the sensitive data from being transmitted (e.g., by blocking the file system activity, redacting the sensitive data from the file, etc.).

Claims (60)

1. A method comprising:

detecting an application creating a network connection;

determining, in response to detecting the application creating the network connection, whether the application satisfies one or more criteria including whether the application has a common file dialog library and whether the application has a graphical user interface;

upon determining that the application satisfies the one or more criteria, monitoring file system activity in the application;

upon detecting a request from the application to perform the file system activity on a file, intercepting the file system activity;

evaluating the file system activity according to a data loss prevention (DLP) policy, wherein the evaluation comprises:

determining whether the file includes sensitive data; and

determining whether the network connection is to an unauthorized external location; and

based on the evaluation that the file includes sensitive data and the network connection is to the unauthorized external location, preventing the application from sending the sensitive data in the file over the network connection.

2. The method of claim 1 , wherein the application includes one or more open network connections.

3. The method of claim 2 , wherein the one or more open network connections are detected by enumerating one or more TCP tables.

4. The method of claim 2 , further comprising:

monitoring network activity of the application for the creation of one or more new network connections.

5. The method of claim 1 , wherein preventing the sensitive data in the file from being sent over the network connection comprises:

blocking the request.

6. The method of claim 1 , wherein preventing the sensitive data in the file from being sent over the network connection comprises:

redacting the sensitive data from the file; and

granting the request after the redaction.

7. The method of claim 1 , further comprising:

upon determining, based on the evaluation, that the file does not contain sensitive data, granting the request.

8. The method of claim 1 , further comprising:

upon determining, based on the evaluation, that the file does contain sensitive data, generating an incident report.

9. A non-transitory computer-readable storage medium having instructions, which, when executed, perform an operation comprising:

detecting an application creating a network connection;

determining, in response to detecting the application creating the network connection, whether the application satisfies one or more criteria including whether the application has a common file dialog library and whether the application has a graphical user interface;

upon determining that the application satisfies the one or more criteria, monitoring file system activity in the application;

upon detecting a request from the application to perform the file system activity on a file, intercepting the file system activity;

evaluating the file system activity according to a data loss prevention (DLP) policy, wherein the evaluation comprises:

determining whether the file includes sensitive data; and

determining whether the network connection is to an unauthorized external location; and

based on the evaluation that the file includes sensitive data and the network connection is to the unauthorized external location, preventing the application from sending the sensitive data in the file over the network connection.

10. The computer-readable storage medium of claim 9 , wherein the application includes one or more open network connections.

11. The computer-readable storage medium of claim 10 , wherein the one or more open network connections are detected by enumerating one or more TCP tables.

12. The computer-readable storage medium of claim 9 , wherein preventing the sensitive data in the file from being sent over the network connection comprises:

blocking the request.

13. The computer-readable storage medium of claim 9 , wherein preventing the sensitive data in the file from being sent over the network connection comprises:

redacting the sensitive data from the file; and

granting the request after the redaction.

14. The computer-readable storage medium of claim 9 , the operation further comprising:

upon determining, based on the evaluation, that the file does contain sensitive data, generating an incident report.

15. A system comprising:

a processor; and

a memory storing program code, which, when executed on the processor, performs an operation comprising:

detecting an application creating a network connection;

determining, in response to detecting the application creating the network connection, whether the application satisfies one or more criteria including whether the application has a common file dialog library and whether the application has a graphical user interface;

upon determining that the application satisfies the one or more criteria, monitoring file system activity in the application;

upon detecting a request from the application to perform the file system activity on a file, intercepting the file system activity;

evaluating the file system activity according to a data loss prevention (DLP) policy, wherein the evaluation comprises:

determining whether the file includes sensitive data; and

determining whether the network connection is to an unauthorized external location; and

based on the evaluation that the file includes sensitive data and the network connection is to the unauthorized external location, preventing the application from sending the sensitive data in the file over the network connection.

16. The system of claim 15 , wherein the application includes one or more open network connections.

17. The system of claim 16 , wherein the one or more open network connections are detected by enumerating one or more TCP tables.

18. The system of claim 15 , wherein preventing the sensitive data in the file from being sent over the network connection comprises:

blocking the request.

19. The system of claim 15 , wherein preventing the sensitive data in the file from being sent over the network connection comprises:

redacting the sensitive data from the file; and

granting the request after the redaction.

20. The system of claim 15 , the operation further comprising:

upon determining, based on the evaluation, that the file does contain sensitive data, generating an incident report.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2015
From: SARIN, SUMIT MANMOHAN; JAISWAL, SUMESH; CHATURVEDI, BISHNU; SCOMPARIN, ARNAUD
To: SYMANTEC CORPORATION
Reel/Frame 036708/0455 →
Cited By (4)
US 12,348,537 US 12,355,817 US 12,598,216 US 12,684,018