IP Library Granted Patent US 12,242,561
Granted Patent B1
US 12,242,561 · App. 18/217,948 · Granted Mar 4, 2025

Managing content uploads

Inventors: Stephen John Stanley Thornhill (Chalfont St. Giles, GB); Andrew Peter Edward Prince (Chippenham, GB); Joshua Frank Wharton (Reading, GB)
Assignee: Menlo Security, Inc.
G06F16/958H04L9/32H04L67/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,561
App. No.
18/217,948
Granted
Mar 4, 2025
Kind
B1
Abstract

Providing policy check functionality to file uploads is disclosed. An attempted file upload is detected at a browser isolation system. A user of a client is prompted to provide a credential associated with the file and usable to access contents of the file. A policy is applied to the file upload.

Claims (44)

1. A system, comprising:

a processor configured to:

receive, at a browser isolation system situated between: (1) a client device that is part of an enterprise network, and (2) a server, an indication that a user of a browser executing on the client device is attempting to upload a first file to a destination website served by the server;

obtain a copy of the first file from the client device;

prompt, in response to determining by the browser isolation system that a credential is required for the browser isolation system to access contents of the first file, the user of the client device for the credential in the browser;

determine a policy to apply to the user's attempted upload of the first file to the destination website, wherein applying the policy includes determining, by the browser isolation system, that the first file should be transmitted to a service configured to alter the first file in accordance with a requirement specified by an administrator of the enterprise network and transmitting the first file to the service, wherein the service is configured to: selectively perform at least one of: (1) adding material to or (2) deleting material from contents of the first file to from the modified version of the first file; and

receive the modified version of the first file from the service and transmit, by the browser isolation system, the modified version of the first file to the server; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein prompting the user of the client device for the credential includes serving a password entry portal page by the browser isolation system to the browser executing on the client device.

3. The system of claim 1 , wherein determining that the credential is required for the browser isolation system to access the contents of the first file includes determining that the first file is encrypted.

4. The system of claim 3 , wherein the processor is further configured to decrypt the first file using the credential.

5. The system of claim 1 , wherein applying the policy includes making the contents of the first file accessible to an auditor.

6. The system of claim 1 , wherein the service is configured to redact a type of information from the first file.

7. The system of claim 1 , wherein the modified version of the first file is generated from the first file by a third party utility.

8. The system of claim 1 , wherein the processor is configured to transmit a decrypted copy of the first file to an external server and receive, from the external server, the modified version of the first file.

9. The system of claim 1 , wherein applying the policy includes determining a categorization of the destination website.

10. The system of claim 1 , wherein the user is prompted using a thin client executing in the browser.

11. The system of claim 1 , wherein the first file comprises an archive and wherein the processor is configured to determine that an included file contained within the archive is encrypted and in response to determining that the included file contained within the archive is encrypted, prompt the user for a credential associated with the included file contained within the archive.

12. The system of claim 1 , wherein determining the policy to apply to the user's attempted upload of the first file to the destination website includes determining that the first file be archived by the browser isolation system.

13. The system of claim 1 , wherein the service is configured to add a watermark to the first file.

14. A method, comprising:

receiving, at a browser isolation system situated between: (1) a client device that is part of an enterprise network, and (2) a server, an indication that a user of a browser executing on the client device is attempting to upload a first file to a destination website served by the server;

obtaining a copy of the first file from the client device;

prompting, in response to determining by the browser isolation system that a credential is required for the browser isolation system to access contents of the first file, the user of the client device for the credential in the browser;

determining a policy to apply to the user's attempted upload of the first file to the destination website, wherein applying the policy includes determining, by the browser isolation system, that the first file should be transmitted to a service configured to alter the first file in accordance with a requirement specified by an administrator of the enterprise network and transmitting the first file to the service, wherein the service is configured to: selectively perform at least one of: (1) adding material to or (2) deleting material from the contents of the first file to form a modified version of the first file; and

receiving the modified version of the first file from the service and transmitting, by the browser isolation system the modified version of the first file to the server.

15. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving, at a browser isolation system situated between: (1) a client device that is part of an enterprise network, and (2) a server, an indication that a user of a browser executing on the client device is attempting to upload a first file to a destination website served by the server;

obtaining a copy of the first file from the client device;

prompting, in response to determining by the browser isolation system that a credential is required for the browser isolation system to access contents of the first file, the user of the client device for the credential in the browser;

determining a policy to apply to the user's attempted upload of the first file to the destination website, wherein applying the policy includes determining, by the browser isolation system, that the first file should be transmitted to a service configured to alter the first file in accordance with a requirement specified by an administrator of the enterprise network and transmitting the first file to the service, wherein the service is configured to: selectively perform at least one of: (1) adding material to or (2) deleting material from the contents of the first file to form a modified version of the first file; and

receiving the modified version of the first file from the service and transmitting, by the browser isolation system, the modified version of the first file to the server.

16. The method of claim 15 , wherein the service is configured to redact a type of information from the first file.

17. The method of claim 15 , wherein prompting the user of the client device for the credential includes serving a password entry portal page by the browser isolation system to the browser executing on the client device.

18. The method of claim 15 , wherein determining that the credential is required for the browser isolation system to access the contents of the first file includes determining that the first file is encrypted.

19. The method of claim 18 , further comprising decrypting the first file using the credential.

20. The method of claim 15 , wherein applying the policy includes making the contents of the first file accessible to an auditor.

21. The method of claim 15 , wherein the modified version of the first file is generated from the first file by a third party utility.

22. The method of claim 15 , further comprising transmitting a decrypted copy of the first file to an external server and receiving, from the external server, the modified version of the first file.

23. The method of claim 15 , wherein applying the policy includes determining a categorization of the destination website.

24. The method of claim 15 , wherein the user is prompted using a thin client executing in the browser.

25. The method of claim 15 , wherein the first file comprises an archive, determining that an included file contained within the archive is encrypted, and in response to determining that the included file contained within the archive is encrypted, prompting the user for a credential associated with the included file contained within the archive.

26. The method of claim 15 , wherein determining the policy to apply to the user's attempted upload of the first file to the destination website includes determining that the first file be archived by the browser isolation system.

27. The method of claim 15 , wherein the service is configured to add a watermark to the first file.

Continuity (3)
Continuation 17895873 · Aug 25, 2022
Continuation 17000084 · Aug 21, 2020
Provisional Application 62992958 · Mar 21, 2020
References Cited (39)
US 8356357B1 · Barile · 2013 [cited by applicant]
US 8429429B1 · Kargman · 2013 [cited by applicant]
US 8726396B1 · Dodke · 2014 [cited by applicant]
US 8825748B2 · Sng · 2014 [cited by applicant]
US 8918867B1 · Salour · 2014 [cited by examiner]
US 9374374B2 · Steinberg · 2016 [cited by applicant]
US 9391832B1 · Song · 2016 [cited by applicant]
US 9887970B2 · Luff · 2018 [cited by applicant]
US 10958732B1 · Procopio · 2021 [cited by applicant]
US 11005819B1 · Song · 2021 [cited by applicant]
US 20100146600A1 · Eldar · 2010 [cited by applicant]
US 20120051657A1 · Lamanna · 2012 [cited by applicant]
US 20120096122A1 · Zhu · 2012 [cited by applicant]
US 20130061284A1 · Berengoltz · 2013 [cited by applicant]
US 20140019753A1 · Lowry · 2014 [cited by applicant]
US 20150095645A1 · Eldar · 2015 [cited by applicant]
US 20170041296A1 · Ford · 2017 [cited by examiner]
US 20170048252A1 · Straub · 2017 [cited by applicant]
US 20170063883A1 · Franzoni Martinez · 2017 [cited by applicant]
US 20170099344A1 · Hadfield · 2017 [cited by examiner]
US 20170235965A1 · Balinsky · 2017 [cited by examiner]
US 20170264619A1 · Narayanaswamy · 2017 [cited by applicant]
US 20170302635A1 · Humphries · 2017 [cited by applicant]
US 20180316674A1 · Shaked · 2018 [cited by applicant]
US 20190075130A1 · Petry · 2019 [cited by applicant]
US 20190213342A1 · Acharya · 2019 [cited by applicant]
US 20190289371A1 · Mok · 2019 [cited by applicant]
US 20200042837A1 · Skinner · 2020 [cited by examiner]
US 20200106842A1 · Chauhan · 2020 [cited by applicant]
US 20200186343A1 · Stuntebeck · 2020 [cited by applicant]
US 20200267167A1 · Venkataswami · 2020 [cited by applicant]
US 20200404000A1 · Hayes · 2020 [cited by applicant]
US 20210200866A1 · Strogov · 2021 [cited by applicant]
US 20210377219A1 · Finchelstein · 2021 [cited by examiner]
US 20210377303A1 · Bui · 2021 [cited by applicant]
US 20210377304A1 · Ma · 2021 [cited by applicant]
US 20230110049A1 · Bhalerao · 2023 [cited by applicant]
US 20230247238A1 · Vimalraj · 2023 [cited by applicant]
Alkilani et al., Data Exfiltration Techniques and Data Loss Prevention System, 2019 International Arab Conference on Information Technology (ACIT), 2019, pp. 124-127, doi: 10.1109/ACIT47987.2019.8991131 (Year : 2019). [cited by applicant]