发明名称 METHODS AND SYSTEMS FOR PREVENTING TRANSMISSION OF SENSITIVE DATA FROM A REMOTE COMPUTER DEVICE
摘要 A technique for preventing selected sets of data words from unauthorized transmission out of the secure perimeter of a computer system is disclosed. A set of security rules is applied to an outgoing data message and if one of the set of rules is triggered, at least a portion of the message is transmitted to a central server that is within the secure perimeter, for scanning by another set of security rules. The central server then sends a security command back to the remote device, which executes the security command before transmitting the outgoing message out of the secure perimeter of the computer system.
申请公布号 US2015286831(A1) 申请公布日期 2015.10.08
申请号 US201514745656 申请日期 2015.06.22
申请人 Workshare, Ltd. 发明人 More Scott;Beyer Ilya
分类号 G06F21/62;H04L29/06 主分类号 G06F21/62
代理机构 代理人
主权项 1. A computer system secured against unauthorized external communications of data items from an egress point, said system comprising: a central server; at least one remote devices connected to the central server by a data network where the remote devices are authorized to communicate with the central server using the data network connection, said remote device comprised of a local data scanning component, where the data scanning component is configured to inspect an outgoing message stored on the remote device to determine if the outgoing message is addressed to a location accessed through the egress point and in dependence on such determination and prior to transmission of the outgoing message , scan the data comprising the message using a first at least one security rules stored locally on the remote device and in the case of triggering said first at least one security rules, transmit a portion of the outgoing message data to the central server; where the central server is further comprised of a security component that is adapted to receive the transmitted portion of the outgoing message, determine a security action by scanning the received portion of the outgoing message using a second at least one security rule stored on the central server and transmit a command encoding the determined security action to the remote device, where the remote device is further configured to execute the determined security action on the outgoing message prior to its transmission through the egress point.
地址 London GB