IP Library › Granted Patent US 12,739,258
Granted Patent B2
US 12,739,258 · App. 17/954,977 · Granted Sep 15, 2026

Computer network security

Inventors: Aleksandr Osipov (Tarrytown, NY); Jacob Kazakevich (Manalapan, NJ); Zachary Nakaska (Frisco, TX)
Assignee: Venn Technology Corporation
H04L63/1416H04L61/5007H04L63/102H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,258
App. No.
17/954,977
Filed
Sep 28, 2022
Granted
Sep 15, 2026
Kind
B2
Examiner
KIM, TAE K
Art Unit
2496
USPC
726/22
Abstract

A computer determines, by a security event detector, that an active threat exists at the computer. The security event detector resides at the computer or in a cloud resource. The security event detector identifies active threats at the computer or a network associated with the computer. The computer prevents, in response to determining that the active threat exists, access to a subset of computing resources accessible via the computer. The subset of computing resources is identified via a security policy that applies to the subset of computing resources. The security policy does not apply to one or more computing resources stored at the computer that are not in the subset. The computer determines, subsequent to determining that the active threat exists, that the active threat no longer exists. The computer allows, in response to determining that the active threat no longer exists, access to the subset of computing resources.

Claims (45)

1 . A method comprising:

determining, by a security event detector that operates based on a security policy, that an active threat exists at a computing machine, the security policy comprising a tracking policy that monitors activity with respect to a subset of computing resources accessible via the computing machine while not monitoring activity with respect to one or more computing resources stored at the computing machine that are not in the subset, wherein the security event detector resides at the computing machine or in a cloud resource, wherein the security event detector identifies active threats at the computing machine or a network associated with the computing machine, wherein the tracking policy causes storage, at a data repository, of records of the activity with respect to the subset and does not cause storage, at the data repository, of records of the activity with respect to the one or more computing resources that are not in the subset;

preventing, in response to determining that the active threat exists, access to the subset of the computing resources, wherein the preventing comprises continuing to allow access to the one or more computing resources that are not in the subset while access to the subset is prevented, wherein the subset is determined by the security policy prior to the determining that the active threat exists, wherein preventing access to the subset comprises making inaccessible, at the computing machine, at least one running application that accesses the subset, wherein the computing machine continues to allow access to the one or more computing resources that are not in the subset, wherein the security policy is enforced with respect to the subset of computing resources and is not enforced with respect to the one or more computing resources that are not in the subset;

determining, subsequent to determining that the active threat exists, that the active threat no longer exists; and

allowing, in response to determining that the active threat no longer exists, access to the subset of computing resources.

2 . The method of claim 1 , wherein the computing machine stores personal computing resources and business computing resources, wherein the subset of computing resources comprises the business computing resources and not the personal computing resources, wherein the computing resources comprise files, email messages, applications, network ports, network destinations, website access permissions, and external filesystem access permissions.

3 . The method of claim 1 , wherein determining that the active threat exists comprises:

scanning the computing machine to detect remote access to the computing machine.

4 . The method of claim 1 , wherein determining that the active threat no longer exists comprises:

persistently checking using the security event detector, once every threshold time period or upon detection of occurrence of a specified event, whether the active threat still exists at the computing machine or the associated network.

5 . The method of claim 4 , wherein the persistently checking occurs once every threshold time period, wherein the threshold time period is between thirty and ninety seconds.

6 . The method of claim 1 , wherein preventing access to the subset comprises:

making a running application inaccessible at the computing machine, wherein the running application is in the subset or accesses a computing resource from the subset.

7 . The method of claim 1 , wherein preventing access to the subset comprises: making one or more files in the subset inaccessible at the computing machine.

8 . A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

determining, by a security event detector that operates based on a security policy, that an active threat exists at a computing machine, the security policy comprising a tracking policy that monitors activity with respect to a subset of computing resources accessible via the computing machine while not monitoring activity with respect to one or more computing resources stored at the computing machine that are not in the subset, wherein the security event detector resides at the computing machine or in a cloud resource, wherein the security event detector identifies active threats at the computing machine or a network associated with the computing machine, wherein the tracking policy causes storage, at a data repository, of records of the activity with respect to the subset and does not cause storage, at the data repository, of records of the activity with respect to the one or more computing resources that are not in the subset;

preventing, in response to determining that the active threat exists, access to the subset of the computing resources, wherein the preventing comprises continuing to allow access to the one or more computing resources that are not in the subset while access to the subset is prevented, wherein the subset is determined by the security policy prior to the determining that the active threat exists, wherein preventing access to the subset comprises making inaccessible, at the computing machine, at least one running application that accesses the subset, wherein the computing machine continues to allow access to the one or more computing resources that are not in the subset, wherein the security policy is enforced with respect to the subset of computing resources and is not enforced with respect to the one or more computing resources that are not in the subset;

determining, subsequent to determining that the active threat exists, that the active threat no longer exists; and

allowing, in response to determining that the active threat no longer exists, access to the subset of computing resources.

9 . The machine-readable medium of claim 8 , wherein the computing machine stores personal computing resources and business computing resources, wherein the subset of computing resources comprises the business computing resources and not the personal computing resources, wherein the computing resources comprise files, email messages, applications, network ports, network destinations, website access permissions, and external filesystem access permissions.

10 . The machine-readable medium of claim 8 , wherein determining that the active threat exists comprises:

scanning, using the security event detector, the computing machine or the associated network to identify the active threat.

11 . The machine-readable medium of claim 8 , wherein determining that the active threat no longer exists comprises:

persistently checking using the security event detector, once every threshold time period or upon detection of occurrence of a specified event, whether the active threat still exists at the computing machine or the associated network.

12 . The machine-readable medium of claim 11 , wherein the persistently checking occurs once every threshold time period, wherein the threshold time period is between thirty and ninety seconds.

13 . The machine-readable medium of claim 8 , wherein preventing access to the subset comprises:

making a running application inaccessible at the computing machine, wherein the running application is in the subset or accesses a computing resource from the subset.

14 . The machine-readable medium of claim 8 , wherein preventing access to the subset comprises:

making one or more files in the subset inaccessible at the computing machine.

15 . A system comprising:

processing circuitry; and

a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

determining, by a security event detector that operates based on a security policy, that an active threat exists at a computing machine, the security policy comprising a tracking policy that monitors activity with respect to a subset of computing resources accessible via the computing machine while not monitoring activity with respect to one or more computing resources stored at the computing machine that are not in the subset, wherein the security event detector resides at the computing machine or in a cloud resource, wherein the security event detector identifies active threats at the computing machine or a network associated with the computing machine, wherein the tracking policy causes storage, at a data repository, of records of the activity with respect to the subset and does not cause storage, at the data repository, of records of the activity with respect to the one or more computing resources that are not in the subset;

preventing, in response to determining that the active threat exists, access to the subset of the computing resources, wherein the preventing comprises continuing to allow access to the one or more computing resources that are not in the subset while access to the subset is prevented, wherein the subset is determined by the security policy prior to the determining that the active threat exists, wherein preventing access to the subset comprises making inaccessible, at the computing machine, at least one running application that accesses the subset, wherein the computing machine continues to allow access to the one or more computing resources that are not in the subset, wherein the security policy is enforced with respect to the subset of computing resources and is not enforced with respect to the one or more computing resources that are not in the subset;

determining, subsequent to determining that the active threat exists, that the active threat no longer exists; and

allowing, in response to determining that the active threat no longer exists, access to the subset of computing resources.

16 . The system of claim 15 , wherein the computing machine stores personal computing resources and business computing resources, wherein the subset of computing resources comprises the business computing resources and not the personal computing resources, wherein the computing resources comprise files, email messages, applications, network ports, network destinations, website access permissions, and external filesystem access permissions.

17 . The system of claim 15 , wherein determining that the active threat exists comprises:

scanning, using the security event detector, the computing machine or the associated network to identify the active threat.

18 . The system of claim 15 , wherein determining that the active threat no longer exists comprises:

persistently checking using the security event detector, once every threshold time period or upon detection of occurrence of a specified event, whether the active threat still exists at the computing machine or the associated network.

19 . The system of claim 15 , wherein preventing access to the subset comprises:

making a running application inaccessible at the computing machine, wherein the running application is in the subset or accesses a computing resource from the subset.

20 . The system of claim 15 , wherein preventing access to the subset comprises:

making one or more files in the subset inaccessible at the computing machine.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2024
From: COMERICA BANK
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 069121/0211 →
SECURITY INTEREST Recorded Aug 31, 2023
From: VENN TECHNOLOGY CORPORATION
To: COMERICA BANK
Reel/Frame 064763/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2022
From: OSIPOV, ALEKSANDR; KAZAKEVICH, JACOB; NAKASKA, ZACHARY
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 061244/0995 →
Continuity (2)
Provisional Application 63261850 · Sep 30, 2021
Related Publication 20230101145A1 · Mar 30, 2023
References Cited (35)
US 7748047B2 · O'Neill · 2010 [cited by applicant]
US 9894099B1 · Jacobsen · 2018 [cited by examiner]
US 11075923B1 · Srinivasan · 2021 [cited by examiner]
US 11368481B2 · Kirti · 2022 [cited by examiner]
US 11757936B2 · Xiao · 2023 [cited by examiner]
US 11949678B2 · Keller · 2024 [cited by examiner]
US 20070168552A1 · Alse et al. · 2007 [cited by applicant]
US 20080301273A1 · Brown et al. · 2008 [cited by applicant]
US 20090037603A1 · Battello et al. · 2009 [cited by applicant]
US 20100242088A1 · Thomas · 2010 [cited by examiner]
US 20150188777A1 · Frost · 2015 [cited by examiner]
US 20160261564A1 · Foxhoven · 2016 [cited by examiner]
US 20160330236A1 · Reddy · 2016 [cited by examiner]
US 20160373405A1 · Miller et al. · 2016 [cited by applicant]
US 20170300690A1 · Ladnai · 2017 [cited by examiner]
US 20180097841A1 · Stolarz · 2018 [cited by examiner]
US 20180131719A1 · Amit · 2018 [cited by examiner]
US 20180375894A1 · Vervier et al. · 2018 [cited by applicant]
US 20190021004A1 · Shanmugavadivel · 2019 [cited by examiner]
US 20190081963A1 · Waghorn · 2019 [cited by examiner]
US 20200153833A1 · Rosenblum · 2020 [cited by examiner]
US 20200314123A1 · Staab · 2020 [cited by examiner]
US 20200334365A1 · Buck · 2020 [cited by examiner]
US 20210014256A1 · Malhotra · 2021 [cited by examiner]
US 20210271741A1 · Habal · 2021 [cited by examiner]
US 20220116397A1 · Deshmukh · 2022 [cited by examiner]
US 20220261487A1 · Lounsberry · 2022 [cited by examiner]
US 20220272117A1 · Maheve · 2022 [cited by examiner]
US 20220309156A1 · Grossman · 2022 [cited by examiner]
US 20220311805A1 · Talati · 2022 [cited by examiner]
US 20230037489A1 · Paul · 2023 [cited by examiner]
US 20230067858A1 · Shapira · 2023 [cited by examiner]
US 20230085509A1 · Noel · 2023 [cited by examiner]
US 20230308460A1 · Thomas · 2023 [cited by examiner]
Non-Final Office Action Dated Jul. 20, 2023 for U.S. Appl. No. 17/955,032, filed Sep. 28, 2022. [cited by applicant]