Cybersecurity System Having Digital Certificate Reputation System

    公开(公告)号:US20210344667A1

    公开(公告)日:2021-11-04

    申请号:US16865176

    申请日:2020-05-01

    申请人: Forcepoint, LLC

    IPC分类号: H04L29/06

    摘要: A system, method, and computer-readable medium are disclosed for implementing a cybersecurity system having a digital certificate reputation system. At least one embodiment is directed to a computer-implemented method executing operations including receiving a communication having an internet protocol (IP) address and a digital certificate at a device within the secured network; determining whether the IP address is identified as having a high-security risk level; if the IP address has a high-security risk level, assigning a security risk level to the digital certificate based on the security risk level of the IP address; and using the security risk level for the digital certificate in executing the one or more security policies. Other embodiments include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices.

    Dynamic injection or modification of headers to provide intelligence

    公开(公告)号:US11128639B2

    公开(公告)日:2021-09-21

    申请号:US16405317

    申请日:2019-05-07

    申请人: Forcepoint LLC

    IPC分类号: H04L29/06

    摘要: A method, system, and computer-usable medium are disclosed for receiving a response, by a security management system, from a site external to an internal network comprising the security management system to an endpoint device of the internal network, and injecting a header into the response by the security management system, the header including security rules, such that when the response is communicated to the endpoint device, the endpoint device responds to the security management system with information regarding subsequent requests made by the endpoint device in connection with the response.

    Cross Domain Dynamic Data Protection Intermediary Message Transform Platform

    公开(公告)号:US20210243211A1

    公开(公告)日:2021-08-05

    申请号:US16780348

    申请日:2020-02-03

    申请人: Forcepoint, LLC

    IPC分类号: H04L29/06 H04L9/32

    摘要: A method, system and computer-usable medium for routing data loss prevention (DLP) events across different network levels. A determination is made as to a number of DLP networks. The classification and data as to a DLP network is determined. Certain data is processed, including an entity risk level and certain data is held, such as certificates. The held data is processed by a computing platform. Processed entity risk levels are returned to the DLP networks. When all networks are processed, processed and held data are sent to the computing platform.

    Dynamically reweighting distributions of event observations

    公开(公告)号:US11080109B1

    公开(公告)日:2021-08-03

    申请号:US16802969

    申请日:2020-02-27

    申请人: Forcepoint, LLC

    摘要: A system, method, and computer-readable medium are disclosed for performing a distribution of interrelated event features operation. The distribution of interrelated event features includes: receiving a stream of events, the stream of events comprising a plurality of events; extracting features from the plurality of events; constructing a distribution of the features from the plurality of events; analyzing the distribution of the features from the plurality of events; and, dynamically reweighting the distribution of the features to scale a number of events contained within the distribution.

    Anticipating Future Behavior Using Kill Chains

    公开(公告)号:US20210226971A1

    公开(公告)日:2021-07-22

    申请号:US16863808

    申请日:2020-04-30

    申请人: Forcepoint, LLC

    IPC分类号: H04L29/06

    摘要: A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes: monitoring an entity, the monitoring observing at least one electronically-observable data source; deriving an observable based upon the monitoring of the electronically-observable data source; identifying a security related activity of the entity, the security related activity being based upon the observable derived from the electronic data source, the security related activity being of analytic utility; associating the security related activity with a phase of a cyber kill chain; and, performing a security operation on the security related activity via a security system, the security operation disrupting performance of the phase of the cyber kill chain.

    Web extension JavaScript execution control by service/daemon

    公开(公告)号:US11048611B2

    公开(公告)日:2021-06-29

    申请号:US16204228

    申请日:2018-11-29

    申请人: Forcepoint, LLC

    发明人: Peidong Chen

    IPC分类号: G06F11/36

    摘要: A method, system and computer-usable medium for collecting and scanning data (i.e., web POST data) before the data is sent. A POST request is sent from a client device to server. The request is through a web browser running a script language listing. The script language listing is paused, while the data is held and scanned. A determination is made to allow or block the data before the data is sent through the POST request.

    Security system using pseudonyms to anonymously identify entities and corresponding security risk related behaviors

    公开(公告)号:US11025659B2

    公开(公告)日:2021-06-01

    申请号:US16168302

    申请日:2018-10-23

    申请人: Forcepoint, LLC

    IPC分类号: H04L29/06 G06F9/54 H04L29/08

    摘要: A method, system and computer-usable medium for using pseudonyms to identify entities and their corresponding security risk factors is disclosed. In certain embodiments, a computer-implemented method for identifying security risks associated with a plurality of different entities is disclosed, wherein the method comprises: receiving a stream of events, the stream of events comprising a plurality of events associated with the plurality of different entities; pseudonymizing events of the plurality of events by replacing entity names in the plurality of events with corresponding entity pseudonyms to thereby provide a plurality of pseudonymized events; executing security analytics operations on the plurality of pseudonymized events to identify user behaviors presenting security risks; and using the entity pseudonyms to anonymously identify entities engaging in security risk related behaviors.

    Risk adaptive protection
    30.
    发明授权

    公开(公告)号:US11025646B2

    公开(公告)日:2021-06-01

    申请号:US16533238

    申请日:2019-08-06

    申请人: Forcepoint, LLC

    发明人: Richard A. Ford

    摘要: A method, system and computer-usable medium for generating a user behavior profile, comprising: monitoring user interactions between a user and an information handling system; converting the user interactions and the information about the user into electronic information representing the user interactions; generating a unique user behavior profile based upon the electronic information representing the user interactions and the information about the user; storing information relating to the unique user behavior profile within a user behavior profile repository; and, storing information referencing the unique user behavior profile in a user behavior blockchain.