- 专利标题: Behavioral-based control of access to encrypted content by a process
-
申请号: US16248417申请日: 2019-01-15
-
公开(公告)号: US10691824B2公开(公告)日: 2020-06-23
- 发明人: Kenneth D. Ray , Andrew J. Thomas , Anthony John Merry , Harald Schütz , Andreas Berger , John Edward Tyrone Shaw
- 申请人: Sophos Limited
- 申请人地址: GB Abingdon
- 专利权人: Sophos Limited
- 当前专利权人: Sophos Limited
- 当前专利权人地址: GB Abingdon
- 代理机构: Strategic Patents, P.C.
- 主分类号: G06F21/62
- IPC分类号: G06F21/62 ; G06F21/55 ; H04L29/06
摘要:
Securing an endpoint against exposure to unsafe content includes encrypting files to prevent unauthorized access, and monitoring an exposure state of a process to potentially unsafe content by applying behavioral rules to determine whether the exposure state is either exposed or secure, where (1) the process is initially identified as secure, (2) the process is identified as exposed when the process opens a network connection to a URL that is not internal to an enterprise network of the endpoint and that has a poor reputation, (3) the process is identified as exposed when it opens a file identified as exposed, and (4) the process is identified as exposed when another exposed process opens a handle to the process. Access to the files may be restricted when the process is exposed by controlling access through a file system filter that conditionally decrypts files for the process according to its exposure state.
公开/授权文献
信息查询