Behavioral-based control of access to encrypted content by a process

    公开(公告)号:US10691824B2

    公开(公告)日:2020-06-23

    申请号:US16248417

    申请日:2019-01-15

    申请人: Sophos Limited

    IPC分类号: G06F21/62 G06F21/55 H04L29/06

    摘要: Securing an endpoint against exposure to unsafe content includes encrypting files to prevent unauthorized access, and monitoring an exposure state of a process to potentially unsafe content by applying behavioral rules to determine whether the exposure state is either exposed or secure, where (1) the process is initially identified as secure, (2) the process is identified as exposed when the process opens a network connection to a URL that is not internal to an enterprise network of the endpoint and that has a poor reputation, (3) the process is identified as exposed when it opens a file identified as exposed, and (4) the process is identified as exposed when another exposed process opens a handle to the process. Access to the files may be restricted when the process is exposed by controlling access through a file system filter that conditionally decrypts files for the process according to its exposure state.

    Process-level control of encrypted content

    公开(公告)号:US10650154B2

    公开(公告)日:2020-05-12

    申请号:US15042862

    申请日:2016-02-12

    申请人: Sophos Limited

    IPC分类号: H04L29/06 G06F21/62 G06F21/55

    摘要: Securing an endpoint against malicious activity includes encrypting a plurality of files on an endpoint to prevent unauthorized access to the plurality of files, receiving a request to access a file from a process executing on the endpoint, decrypting the file for the process, and monitoring a security state of the process. If the security state becomes a compromised state, a technique involves maintaining access to any open files (including the file decrypted for the process), prohibiting access to other files, and initiating a remediation of the process by facilitating a restart of the process. If the remediation is successful, access by the process to the plurality of files may be restored.

    BEHAVIORAL-BASED CONTROL OF ACCESS TO ENCRYPTED CONTENT BY A PROCESS

    公开(公告)号:US20190228172A1

    公开(公告)日:2019-07-25

    申请号:US16248417

    申请日:2019-01-15

    申请人: Sophos Limited

    IPC分类号: G06F21/62 G06F21/55 H04L29/06

    摘要: Securing an endpoint against exposure to unsafe content includes encrypting files to prevent unauthorized access, and monitoring an exposure state of a process to potentially unsafe content by applying behavioral rules to determine whether the exposure state is either exposed or secure, where (1) the process is initially identified as secure, (2) the process is identified as exposed when the process opens a network connection to a URL that is not internal to an enterprise network of the endpoint and that has a poor reputation, (3) the process is identified as exposed when it opens a file identified as exposed, and (4) the process is identified as exposed when another exposed process opens a handle to the process. Access to the files may be restricted when the process is exposed by controlling access through a file system filter that conditionally decrypts files for the process according to its exposure state.