发明名称 Method and system for protection against information stealing software
摘要 A system and method for identifying infection of unwanted software on an electronic device is disclosed. A software agent configured to generate a bait and is installed on the electronic device. The bait can simulate a situation in which the user performs a login session and submits personal information or it may just contain artificial sensitive information. The output of the electronic device is monitored and analyzed for attempts of transmitting the bait. The output is analyzed by correlating the output with the bait and can be done by comparing information about the bait with the traffic over a computer network in order to decide about the existence and the location of unwanted software.
申请公布号 US9455981(B2) 申请公布日期 2016.09.27
申请号 US201514846538 申请日期 2015.09.04
申请人 Forcepoint, LLC 发明人 Troyansky Lidror
分类号 H04L29/06;G06F21/55;G06F21/56;G06F21/62 主分类号 H04L29/06
代理机构 Schwegman Lundberg & Woessner, P.A. 代理人 Schwegman Lundberg & Woessner, P.A.
主权项 1. A system for controlling dissemination of sensitive information from an electronic network to an electronic device on the Internet, the system comprising: an electronic hardware processor configured to execute computer instructions, wherein the computer instructions implement a traffic analyzer, the traffic analyzer in communication with the electronic network and configured to: detect an electronic message on the electronic network, the electronic message including a password to be transmitted to the electronic device on the Internet,determine a strength of the password based on one or more of a length of the password and an entropy score of the password,determine a sensitivity of information protected by the password based on the strength, wherein the sensitivity is positively correlated with the strength of the password such that a stronger password results in a determination of higher sensitivity and a weaker password results in a determination of lower sensitivity,determine a category of content at the electronic device by classifying website content at the electronic device,determine a risk level based at least in part on the category and the sensitivity of the information protected by the password,determine a required action in response to the risk level, wherein the required action includes one or more of blocking, quarantining, or alerting, andblock the electronic message destined for the electronic device and including the password in response to the required action including blocking.
地址 Austin TX US