Patents Assigned to Forcepoint, LLC
-
Publication number: 20200092264Abstract: A method, system, and computer-usable medium are disclosed for, responsive to receipt at a security device of a connection request from a client to a server receiving a message from the client to the server, extracting from a memory associated with the client a secret for performing decryption of application messages communicated from the server to the client, and using the secret to decrypt the application messages to perform at least one of monitoring and inspection of the application messages as decrypted in accordance with a security policy, while allowing the client and the server to maintain an end-to-end connection without intermediate termination at the security device.Type: ApplicationFiled: September 17, 2018Publication date: March 19, 2020Applicant: Forcepoint LLCInventors: Valtteri RAHKONEN, Kurt NATVIG, Olli-Pekka NIEMI, Mike GREEN
-
Publication number: 20200065182Abstract: A method, system, and computer-usable medium are disclosed for, responsive to receipt at an information handling system of a command to transmit an executable file to a second information handling system, scanning the executable file to determine if the executable file includes debug information, and responsive to determining that the executable file includes debug information, taking remedial action with respect to the executable file.Type: ApplicationFiled: August 21, 2018Publication date: February 27, 2020Applicant: Forcepoint LLCInventors: Ville MATTILA, Valtteri RAHKONEN, Otto AIRAMO
-
Publication number: 20200042891Abstract: A system for image classification is disclosed that includes a central system configured to provide high reliability image data processing and recognition and a plurality of endpoint systems, each configured to provide image data processing and recognition with a lower reliability than the central system and to generate probability data. A decision switch disposed at each of the plurality of endpoint systems is configured to receive the probability data and to determine whether to deny access, grant access or generate a referral message to the central system, wherein the referral message includes at least a set of image data generated at the endpoint system.Type: ApplicationFiled: August 1, 2018Publication date: February 6, 2020Applicant: Forcepoint LLCInventors: Gal Itach, Shai Ungar, Ran Geler, Ayval Ron, Uri Elias
-
Patent number: 10542013Abstract: A method, system and computer-usable medium are disclosed for generating a cyber behavior profile, comprising: monitoring user interactions between a user and an information handling system; converting the user interactions and the information about the user into electronic information representing the user interactions; generating a unique cyber behavior profile based upon the electronic information representing the user interactions and the information about the user; and, storing information relating to the unique cyber behavior profile in a behavior blockchain.Type: GrantFiled: August 13, 2018Date of Patent: January 21, 2020Assignee: Forcepoint LLCInventors: Richard Anthony Ford, Brandon L. Swafford, Christopher Brian Shirey, Matthew P. Moynahan, Richard Heath Thompson
-
Patent number: 10530786Abstract: A method, system and computer-usable medium for generating a user behavior profile, comprising: monitoring user interactions between a user and an information handling system; converting the user interactions and the information about the user into electronic information representing the user interactions; generating a unique user behavior profile based upon the electronic information representing the user interactions and the information about the user; storing information relating to the unique user behavior profile within a user behavior profile repository; and, storing information referencing the unique user behavior profile in a user behavior blockchain.Type: GrantFiled: October 17, 2018Date of Patent: January 7, 2020Assignee: Forcepoint LLCInventor: Richard A. Ford
-
Publication number: 20200004978Abstract: A system for identifying network users is provided that includes a domain controller agent having a user map that is configured to receive user data, to save the user data in an updated user map and to replace the user map with the updated user map. A filtering service has the user map and is configured to receive the updated user map and to replace the user map with the updated user map. An event subscription system is configured to generate event subscription data, wherein the domain controller agent is configured to subscribe to the event subscription system and to receive the event subscription data.Type: ApplicationFiled: June 29, 2018Publication date: January 2, 2020Applicant: Forcepoint LLCInventors: Anderson S. Albano, Michael C. Madigan, Shuo Li, Xiaoyue Fan
-
Publication number: 20190369945Abstract: A method, system, and computer-usable medium are disclosed for receiving a video stream of image frames, determining changes in one or more portions of the video stream, and presenting: (i) the video stream to a video display device, including an overlay indicating the one or more portions of the video stream wherein the changes occur; and/or (ii) a temporal change indicator to the video display device, indicating temporal portions of the video stream in which changes occur within the video stream.Type: ApplicationFiled: May 29, 2018Publication date: December 5, 2019Applicant: Forcepoint LLCInventors: Alexander SMITH, Natalie MCMULLEN, Kevin CRANDELL
-
Publication number: 20190349595Abstract: A method, system, and computer-usable medium are disclosed for receiving a video stream of image frames in a video format, decoding image frames of the video stream from the video format, for each respective frame of the image frames, upon completion of decoding of the respective frame, asynchronously encoding the respective frame into a lossless compression format, and asynchronously streaming all of the respective frames as encoded into the lossless compression format as a resulting video stream for display to a video display device.Type: ApplicationFiled: May 9, 2018Publication date: November 14, 2019Applicant: Forcepoint LLCInventors: Mark PRICE, Jason CLINTON, Scott GRIMES
-
Publication number: 20190342263Abstract: A method, system, and computer-usable medium are disclosed for responsive to a connection from a client to a server for establishing communications between the client and the server, store information regarding state of the connection and responsive to receiving a reply from the server to the client, route the reply to the client based on the information regarding the state of the connection.Type: ApplicationFiled: May 2, 2018Publication date: November 7, 2019Applicant: Forcepoint LLCInventors: Otto AIRAMO, Ville MATTILA, Tuomo SYVÄNNE
-
Publication number: 20190327263Abstract: A method, system, and computer-usable medium are disclosed for, responsive to receipt of traffic from a server to a client, parsing content of the traffic, and injecting additional content into original content of the server response to override an action of the original content, such that when the client executes the content of the traffic the client determines whether the content includes additional content that overrides the action of the original content, and in response to determining that the content includes additional content that overrides the action of the original content, communicates parameters associated with execution of the action to an inspection service to determine if the action is malicious.Type: ApplicationFiled: April 18, 2018Publication date: October 24, 2019Applicant: Forcepoint LLCInventors: Christian JALIO, Valtteri RAHKONEN, Antti LEVOMÄKI
-
Patent number: 10447718Abstract: A method, system and computer-usable medium for performing a security analysis operation within a security environment, comprising: monitoring electronically-observable user behavior about a particular entity; maintaining a state about the particular entity, the state representing a context of a particular event; converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior; generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior; and, analyzing the event using the state of the entity and the user behavior profile.Type: GrantFiled: May 14, 2018Date of Patent: October 15, 2019Assignee: Forcepoint LLCInventor: Richard Anthony Ford
-
Publication number: 20190265982Abstract: A system, for managing application specific configuration data, that receives, from a local server, a standardized configuration object, at a configuration engine, for a configurable entity, generates at least one configuration object file for the configuration entity, wherein the standardized configuration object is generated based on the application specific configuration data according to a system wide metadata specification. The system can further write each configuration object file to a shared memory structure associated with a configuration file of a configurable entity. The system receives the configuration object, compares the configuration object with another standardized configuration object, and interfaces the configuration object with the configuration engine. The interfaced configuration object can be a piece of configuration. The system permits read access to the configuration engine to the configuration object, permits read and write access to the management server to the configuration object.Type: ApplicationFiled: February 28, 2018Publication date: August 29, 2019Applicant: Forcepoint LLCInventors: Tuomo Mickelsson, Kari Nurmela, Marko Niiranen
-
Publication number: 20190253393Abstract: A method, system, and computer-usable medium are disclosed for providing a multi-access interface for network traffic, comprising: receiving information regarding topology of a virtual private network and storing the topology in the form of a routing table. A method, system, and computer-usable medium are disclosed for providing an interface for network traffic, comprising: in a virtual private network comprising a plurality of tunnels delivering only information associated with Open Systems Interconnect stack Level 3, receiving a network communication and performing multicast forwarding among the plurality of tunnels using multicast forwarding from Open Systems Interconnect stack Level 2.Type: ApplicationFiled: February 15, 2018Publication date: August 15, 2019Applicant: Forcepoint LLCInventors: Tuomo SYVÄNNE, Juha LUOMA, Ville MATTILA
-
Publication number: 20190253391Abstract: A method, system, and computer-usable medium are disclosed for performing packet processing of network traffic on a master security device of a plurality of security devices, such packet processing including connection tracking for the network traffic, and offloading packet inspection of the network traffic to one or more slave security devices of the plurality of security devices.Type: ApplicationFiled: February 9, 2018Publication date: August 15, 2019Applicant: Forcepoint LLCInventors: Mika LANSIRINNE, Valtteri RAHKONEN, Pekka RIIKONEN
-
Publication number: 20190245930Abstract: A method, system, and computer-usable medium are disclosed for, responsive to communication of a client handshake to a server for establishing communications between the client and server, managing handshake messages between the client and server until an application layer message is communicated from the client, such that a connection between the client and the server appears to be established, and responsive to communication of the application layer message from the client, rendering a policy decision with respect to a connection between the client and the server based on a payload of the application layer message, the policy decision defining a selected path between the client and the server and including a chosen target device from a plurality of potential target devices, wherein the chosen target device is within the selected path and establishing the selected path for communication between the client and the server in accordance with the policy decision.Type: ApplicationFiled: February 8, 2018Publication date: August 8, 2019Applicant: Forcepoint LLCInventors: Valtteri RAHKONEN, Tuomo SYVÄNNE
-
Publication number: 20190229923Abstract: A method, system, and computer-usable medium are disclosed for, responsive to an attempted connection from a client to a server for establishing communications between the client and the server, redirecting the connection to a proxy and injecting protocol-independent header information into a datagram of the traffic between the client and the server, the protocol-independent header information including information based upon which the proxy enforces a security policy.Type: ApplicationFiled: January 23, 2018Publication date: July 25, 2019Applicant: Forcepoint LLCInventors: Otto AIRAMO, Tuomo SYVÄNNE, Ville MATTILA
-
Patent number: 10326776Abstract: A system, method, and computer-usable medium are disclosed for generating a cyber behavior profile comprising monitoring user interactions between a user and an information handling system; converting the user interactions into electronic information representing the user interactions, the electronic information representing the user interactions comprising temporal detail corresponding to the user interaction; and generating a user behavior profile based upon the electronic information representing the user interactions, the generating the user profile including a layer of detail corresponding to the temporal detail corresponding to the user interaction.Type: GrantFiled: May 14, 2018Date of Patent: June 18, 2019Assignee: Forcepoint, LLCInventors: Richard Anthony Ford, Brandon L. Swafford
-
Patent number: 10326775Abstract: A system, method, and computer-usable medium are disclosed for performing a multi-factor authentication operation, comprising: monitoring electronically-observable user behavior; converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior; generating a user behavior factor based upon the electronic information representing the electronically-observable user behavior; and, using the user behavior factor as a factor of a multi-factor authentication.Type: GrantFiled: May 8, 2018Date of Patent: June 18, 2019Assignee: Forcepoint, LLCInventors: Richard Anthony Ford, Brandon L. Swafford
-
Patent number: 10318729Abstract: A method, system and computer-usable medium are disclosed for performing a privacy operation, comprising: monitoring user behavior via a data stream collector, the data stream collector capturing data streams resulting from user/device interactions between a user and a corresponding endpoint device; determining whether the data streams resulting from user/device interactions include sensitive personal information; obfuscating the sensitive personal information, the obfuscating preventing unauthorized viewing of the sensitive personal information; and, presenting the sensitive personal information as a sensitive personal information token indicating the data streams include sensitive personal information.Type: GrantFiled: August 2, 2017Date of Patent: June 11, 2019Assignee: Forcepoint, LLCInventors: Richard A. Ford, Christopher B. Shirey, Jonathan B. Knepher, Lidror Troyansky
-
Patent number: 10320839Abstract: A method, system and computer-usable medium are disclosed for performing an automated anti-spoofing configuration operation, comprising: determining whether a source address of an internet protocol (IP) packet is allowed by a receiving interface of a firewall; determining whether the IP packet comprises a multicast packet when the IP packet is allowed by the receiving interface of the firewall; replacing the source address with a rendezvous point address; using the rendezvous point address to determine whether routing path information associated with the multicast packet matches information stored within a multicast routing information base for the receiving interface of the firewall; and, identifying the multicast packet as spoofed when the routing path information associated with multicast packet does not have corresponding information stored within the multicast routing information base.Type: GrantFiled: September 19, 2017Date of Patent: June 11, 2019Assignee: Forcepoint, LLCInventors: Ville Mattila, Tomi Salminen, Tuomo Syvänne